17
2009/12/21 專專專專 專專專 專專專專 專專專 專專專 專專專 專專專 專專專 專專專 專專專 專專專 專專專

企業資訊安全政策施行架構 -以電信業為例

  • Upload
    lorene

  • View
    40

  • Download
    5

Embed Size (px)

DESCRIPTION

商務科技管理系 實務專題報告. 企業資訊安全政策施行架構 -以電信業為例. 專題成員:蔡嘉容 、 李育玫 、 陳璟瑩 、 劉蕙慈 、 謝佩勳. 2009/12/21. 大綱. 一、研究背景與動機 二、研究範圍與目標 三、研究結果 四、 SMAC 方法論 五、資訊安全控管流程 六、資訊安全系統架構. 七、系統特色 八、實際效益 九、結論 十、後續研究方向 十一、參考文獻. 一、研究背景與動機.   中華電信由於在美國的證卷交易委員會登記註冊,必須受美國沙氏法案的約束,因此有符規 (compliance) 的需求。 - PowerPoint PPT Presentation

Citation preview

  • 2009/12/21

  • SMAC

  • (compliance) KPMG20083.6%1

  • NGOSS

    IBM2

  • PDSE

    3

  • SMAC 4-PDSE

  • (1/2)-PDSE5

  • (2/2)6-PDSE

  • (1/2)-PDSE7

  • (2/2)8

  • 9

    Chen, Kuo Bradley, Josang Sengupta et alCoyle et al 2009200420052007 /

  • 61%18% 10

  • PDSEPDSEPDSEPDSE

    11

  • PDSE12

  • (1/2)(2001)(2005)BS7799(2007)(2004) (2009)WiMAX http://www.exam.gov.tw/ http://my.so-net.net.tw/joe21799/l/l3.htm http://www.trendmicro.com.tw/micro/TMLP/TMLP_microsite_index.html http://www.gss.com.tw/tw/eispage/vol56/eispage5606.htm13

  • (2/2)A. Zuccato, Holistic Security Management Framework Applied in Electronic Commerce, Computers & Security, Vol 26 (3), p256-265, 2007.J. C. Sipior, B. T. Ward, A Framework for Information Security Management based on Guid Standards: A United States Perspective, Issues in Informing Science and Information Technology Vol 5, p52-60, 2008Policy Enforcement Framework for Web Services and Grid OperationalAnton Chuvakin, Gunnar Peterson, "Logging in the Age of Web Services," IEEE Security & Privacy, Vol. 7 (3) , pp. 82-85, May/June, 2009.K.J. Knapp, R.F. Morris Jr., T.E. Marshall, T. Anthony, Information Security Policy: An Organizational-Level Process Model, Computer & Security, Volume 28 (7), p493-508, 2009.S.C. Shih, H.J. Wen, E-enterprise Security Management Life Cycle, Information Management & Computer Security, Vol 13 (2), p121-134, 2005.D. Bradley, A. Josang, Mesmerize An Open Framework for Enterprise Security Management, ACM International Conference Proceeding Series; Vol. 54, Proceedings of the second workshop on Australasian information security, Data Mining and Web Intelligence, and Software Internationalisation - Volume 32, Dunedin, New Zealand, p37-42, 2004A. Sengupta, A. Mukhopadhyay, K.Ray, A.G. Roy, D. Aich, M.S. Barik, C. Mazumdar, A Web Enabled Enterprise Security Management Framework based on a Unified Model of Enterprise Information System Security, Lecture Notes in Computer Science, Vol 3803, p328-331, 2005.J. Colye, J. Demerest, R. McAllister, A Proposed Security Management Framework for the Global Information Security, 6th Workshop on Enabling Technologies Infrastructure for Collaborative Enterprises (WET-ICE 97), p200-206, 1997.14

  • *