標題: 台灣某一公司的整合性資訊安全管理之研究
The Study of Integrated Information Security for A Company in Taiwan
作者: 施弘彦
Shih, Hung-Yen
關鍵字: 整合性的資訊安全
Enterprise Architecture (EA)
Integrating information security
Identity and Access Management (IAM)
Information and Communication Technologies (ICT)
出版社: 高階經理人碩士在職專班
摘要: 藉由資訊科技的協助,企業能提供更方便及容易的資訊存取,但在此的同時,延伸出包含隱私權及資訊安全等問題。本研究展示整合性的資訊安全管理藍圖,包含以下四個觀點:系統、平台、基礎建設及安全政策。企業方格架構(Enterprise Architecture,EA)提供了企業在不同階層中如何運用身份驗證管理(IAM)進行整合性及相互協調的資訊通訊技術 (ICT) 系統管理及規劃。本研究係採用深度個案研究,A輪胎製造廠為主要研究對象,以企業方格架構來探討資訊安全架構規劃的整合性藍圖建立。
Nowadays, with the help of technologies, organizations are able to provide easy access to information across its boundaries. Along the road, the questions are merged in the prospective of privacy and information security. The study demonstrated a roadmap for integrating information security management solutions within a business setting approaching from four aspects: system, Platforms, infrastructures and security policies. The application of Enterprise Architecture (EA) is practiced for comprehensive and coordinated planning and management of organizational Information and Communication Technologies (ICT) and the security infrastructure in different levels of the business structure. An in-depth case study within a leading tire manufacture is conducted based on EA framework. Security architecture planning includes Identity and Access Management (IAM) and security policy are structured to deliver an integrated security management roadmap.
