1,726,879 research outputs found

    DIKN wujud 7799 peluang pekerjaan sejak 2010

    Get PDF
    SINTOK- Sebanyak 7799 peluang pekerjaan dan RM6748 juta hasil pelaburan diperoleh melalui program yang dilaksana di bawah Dasar Industri Kreatif Negara (DIKN) sejak 2010 sehingga tahun lepas

    Novosti, ki jih prinašajo spremembe standarda BS 7799

    Get PDF
    In the paper, the information security standard BS 7799 is described. A short history of the standard is presented. Benefits of standard implementation into an organization are highlighted. Modifications in the latest versions of the standard (BS ISO/IEC 17799:2005 and BS ISO/IEC 27001:2005) are described in detail. The authors also discuss possible impact of these modifications on the organizations that have developed their information security management systems (ISMS) on the basis of the previous versions of the standard. Besides, the article describes what the organizations can expect in the field of the information security standardization in the near future. Keywords: information security, BS 7799 standard, new edition, modifications, impact on the organizations, future of the standardČlanek opisuje lastnosti standarda za informacijsko varnost BS 7799 in navaja koristi njegove uvedbe v organizacijo. Podana je kratka zgodovina standarda. Podrobno so opredeljene spremembe, ki jih prinašata najnovejši izdaji standarda, in sicer BS ISO/IEC 17799:2005 in BS ISO/IEC 27001:2005. Avtorici obravnavata možne vplive teh sprememb na organizacije, ki so svoje sisteme za upravljanje informacijske varnosti (SUIV) oblikovale na osnovi prejšnjih verzij standarda BS 7799. Opisano je tudi, katere standarde s področja zagotavljanja informacijske varnosti lahko organizacije pričakujejo v naslednjih letih. Ključne besede: informacijska varnost, standard BS 7799, nova izdaja, spremembe, vpliv na organizacije, prihodnost standard

    A Study Of Information Security Misgivings About BS 7799 Standard

    No full text
    資訊科技的發達與普及為我們帶來了生活上的方便,然而,相對的也帶來了許多資訊安全問題,由於資訊危安事件所造成的影響層面更逐漸擴大,這些問題已逐漸成為眾人最關心的問題之一,因此便有些企業組織想透過認證的方式來保障自身資訊系統的安全,但是有越來越多的事件顯示資訊安全問題的發生並非系統的問題而是人員有意或無意的行為所造成。 本篇論文以「人」為考量主體,從「道德」的角度來探討資訊安全的影響並對目前政府積極推行的資訊安全認證,BS 7799標準做相關的安全性探討。我們提出四個主要論點: 一、BS 7799對於新的網路犯罪手法不易抵抗; 二、BS 7799對組織內部的文化及人員的道德操守不易規範; 三、BS 7799對社會工程的防範能力仍薄弱; 四、資安認證成本偏高、部分規定過於繁瑣使得企業多不願投資。 我們也藉由相關的個案討論,說明BS 7799安全規範並無法涵蓋整個資訊安全範圍也不易對人員道德提出有效的規範,即使符合BS 7799認證並不表示就能獲得資訊安全上的保障或從此避開資訊安全的威脅。要做好資訊安全的工作除了從系統軟硬體的安全措施著手外,更需要從企業、組織內部做好人員的管理並加強有關人員的道德教育,如此企業、組織才能真正落實並有效提升整體的資訊安全。As with the convenience that the information technology has brought to our life, there also comes the information security problems. And with the impact of the information security events getting stronger and stronger, there is growing concern over the information security. Some enterprises might consider way of information security certificate to insure the safety of information systems. However, more and more events indicate that why the information security problem happened comes from people’s improper behavior whether intentionally or not, instead of the information system itself. In this thesis, we take ‘human’ as the major object in the thinking of information security. We exploit the impact of the information security from the morality point of view. The safety of the information security certificate, BS 7799 which the government is trying to carry out is also been discussed. We propose four major issues as follows: 1. It is not easy for BS 7799 to against the new technique of information attacks. 2. It is not easy for BS 7799 to rule the organization culture and the human morality. 3. BS 7799 could hardly attack the cheating by social engineering. 4. Most of organizations are unwilling to invest in BS 7799 certificates of registration because of the high cost of certificate registration and the tedious rules as well. We also claim that BS 7799 neither covers the whole scope of the information security nor makes efficient specifications on human normality through the case study. Even if the organization had been awarded a BS 7799 certificate of registration for the information security management system, it does not promise that their information system is under safe state or could keep away from any security threat. Besides enhancing the hardware/software of the information system, one of the critical disciplines needed for thorough security work is to establishing sound internal controls and enhancing the moral education for staffs, so that the organization can fulfill and improve the whole information security properly effectively.誌謝……………………………………………………………………………………i 摘要……………………………………………………………………………………ii ABS TRACT…………………………………………………………………………iii 目錄…………………………………………………………………………………iv 圖目錄………………………………………………………………………………vi 表目錄………………………………………………………………………………vi 第一章 緒論…………………………………………………………………………1 第一節 研究動機………………………………………………………………1 第二節 研究目的………………………………………………………………3 第三節 論文結構………………………………………………………………3 第二章 BS 7799標準與吳子兵法觀念簡介………………………………………5 第一節 BS 7799內容簡介……………………………………………………5 2.1.1 BS 7799第一部份:最佳實務準則……………………………5 2.1.2 BS 7799第二部分:資訊安全管理系統………………………6 第二節 目前國內對BS 7799認證的接受程度之概況………………………9 第三節 吳子兵法簡介及其與資訊安全的關係……………………………10 第三章 BS 7799的資訊安全虞慮………………………………………………11 第一節 BS 7799對於新的網路犯罪手法不易抵抗…………………………11 第二節 BS 7799對組織內部的文化及人員的道德操守不易規範…………13 3.2.1 BS 7799不易對組織內部的文化做規範……………………13 3.2.2 人員的道德操守規範不易……………………………………13 第三節 BS 7799對社會工程(Social Engineering)詐騙的防範能力薄弱……16 第四節 資安認證成本過高、部分規定過於繁瑣,企業主不願投資………19 第四章 資訊危安事件之案例探討………………………………………………20 第一節 疑似中共「網軍」的駭客入侵事件………………………………20 4.1.1 前言……………………………………………………………20 4.1.2 大陸駭客入侵事件的始末……………………………………21 4.1.3 駭客入侵的途徑及相關的木馬程式簡介……………………22 4.1.4 對大陸駭客入侵事件新聞的分析……………………………24 4.1.5 結語……………………………………………………………27 第二節 公鑰基礎建設(PKI)及其所帶來的資安虞慮………………………28 4.2.1 前言……………………………………………………………28 4.2.2 公鑰基礎建設簡介及其在國內應用現況……………………28 4.2.3 公鑰基礎建設的一些風險及資訊危安實例…………………31 4.2.4 結語……………………………………………………………41 第三節 無法兼顧人性且成效不佳的安全電子交易(SET) ………………42 4.3.1 前言……………………………………………………………42 4.3.2 SET簡介………………………………………………………42 4.3.3 成效不佳的原因………………………………………………47 4.3.4 結語……………………………………………………………49 第四節 積極取得國際認證卻仍傳出重大資安事件的財金資訊公司……51 4.4.1 前言……………………………………………………………51 4.4.2 財金資訊公司的相關資料……………………………………51 4.4.3 財金公司的重大資訊危安事件探討…………………………52 4.4.4 結語……………………………………………………………55 第五節 電子簽章與老千…………………………………………………56 4.5.1 前言……………………………………………………………56 4.5.2 電子簽章及其優缺點…………………………………………56 4.5.3 可能行騙的方法………………………………………………57 4.5.4 結語……………………………………………………………58 第六節 從明長城的角度看網路資訊安全…………………………………59 4.6.1 前言……………………………………………………………59 4.6.2 電腦網路中的長城——防火牆………………………………60 4.6.3 重要網路資訊安全事件回顧…………………………………61 4.6.4 借鑑吳子兵法…………………………………………………63 4.6.5 結語……………………………………………………………64 第七節 金融卡盜領事件……………………………………………………66 4.7.1 前言……………………………………………………………66 4.7.2 盜領案紀事……………………………………………………67 4.7.3 事件分析與討論………………………………………………70 4.7.4 結語……………………………………………………………73 第八節 內賊難防——台積電員工洩密案…………………………………75 4.8.1 前言……………………………………………………………75 4.8.2 事件回顧………………………………………………………75 4.8.3 事件分析………………………………………………………76 4.8.4 結語……………………………………………………………78 第五章 結論………………………………………………………………………79 參考文獻……………………………………………………………………………8

    Critical Success Factors of BS 7799 Certification Acquirement

    No full text
    [[abstract]]隨著資訊科技的蓬勃發展,企業必須依賴網際網路來掌握即時的商業資訊,同時也因為大量使用網路資訊,導致駭客入侵、電腦病毒的肆虐及重大人為或天然災害等資安事件層出不窮。輕則,個人資料被竊取,造成個人隱私外洩;重則,企業機敏性資訊外洩導致營運衝擊或業務損失等..。因此,企業界逐漸重視資訊安全,並朝向資訊技術的架構規劃與安全意識等種種資安行為加強。 然而,過去有關資訊安全議題之研究,大部份著重於資訊安全技術之應用,較少從資訊安全管理的角度來探討。因此,本研究依據全球所提倡的BS 7799 資訊安全實施標準(BS 7799 Code of Practice for Information Security),它是由英國國家標準協會(The British Standards Institute,Bsi)所制定之資訊安全管理標準,此項標準涵蓋了所有的安全議題,並且提供組織作為保護其資訊資產之機密性(Confidentiality)、完整性(Integrity)及可用性(Availability)管控方法。本研究主要係探討企業導入BS 7799 資訊安全管理系統的整個過程中,可能遭遇的推動上之難題或影響因素,並且企圖找出主要的關鍵因素及其重要程度,希望能協助企業順利取得BS 7799 認證及降低組織的資訊風險。 本研究首先收集有關資訊安全管理、導入ISO 9000 系列及BS 7799 認證之相關研究,找出相關導入BS 7799 資訊安全管理系統之關鍵成功因素,並將這些因素分成管理構面、人員構面、技術構面、外在環境構面等四個構面,又可分為15個關鍵因素,推導出「導入BS 7799 關鍵成功因素」之整體性評估模式,再透過分析層級程序法(Analyical Hierachy Process,AHP)深入分析組織在推動資訊安全管理系統時,必須優先考量之關鍵成功因素及其影響程度。本研究結果發現,透過AHP 找出導入BS 7799 關鍵成功因素,前三名依序為「高階主管的全力支持與承諾」、「選擇合適的資訊安全輔導顧問」、「不斷稽核與矯正」。本研究並透過取得BS 7799 或ISO 27001 認證組織及BS 7799 輔導顧問的觀點,來分析與比較其影響程度的不同之處。[[abstract]]subsequent actions. This process is called the model of motivatio

    Is BS 7799 worth the effort?

    Get PDF
    NORSK: Denne masteroppgaven fokuserer på hvorvidt organisasjoner som har sertifisert sitt styringssystem for informasjonssikkerhet etter BS 7799, oppnår en bedre evne til å forebygge, detektere og reagere på sikkerhetsbrudd slik at konsekvensene ved sikkerhetsbrudd reduseres. Masteroppgaven vil også utforske om det er en forskjell på organisasjoner som benytter BS 7799 på en uformell måte kontra organisasjoner som ikke benytter standarden. I disse dager er det en utfordring for informasjonssamfunnet at informasjonssikkerhet et styrt og håndtert på mange forskjellige måter. I dag, og i fremtiden, kan det være vitalt å kunne håndtere informasjonssikkerheten iht. et felles sett med prinsipper, uavhengig av organisasjon. Vi har gjennomført en undersøkelse i form av en spørreundersøkelse. Spørreundersøkelsen ble distribuert til sikkerhetssjefer eller stabspersonell innen informasjonssikkerhet i 40 norsk virksomheter hvor vi forventet at et styringssystem for informasjonssikkerhet var implementert. Åtte av virksomhetene var sertifisert etter BS 7799-2. Vi hadde også klare forventninger til at informasjonssikkerhet var et viktig tema i de andre virksomhetene. I spørreundersøkelsen spurte vi organisasjonene om følgende: -konsekvensene som har rammet organisasjonen fra 1999 til 2004, estimert som økonomiske tap - hvordan brudd på informasjonssikkerhet er håndtert i organisasjonen og mulighetene for oss til å få tilgang til de statistiske data angående brudd på sikkerheten - hvilke deler av styringssystemer som er implementert og hvordan det er implementert Angående spørsmålet om styringssystem for informasjonssikkerhet spurte vi om de vitale delene som burde vært implementert i alle virksomheter med et visst behov for å beskytte organisasjonens verdier. Svarene angående konsekvenser og statistiske data angående brudd på sikkerheten var for få til å sammenligne sertifiserte organisasjoner, organisasjoner som benytter standarden uformelt og de organisasjoner som ikke benytter en standard. Resten av spørreskjemaet fokuserte på de vitale delene av et styringssystem for informasjonssikkerhet. Svarene på disse spørsmålene gjorde det mulig å estimere modenhetsnivået på organisasjonens styringssystem for informasjonssikkerhet. Modenhetsnivået på styringssystemet for informasjonssikkerhet kan ansees som et speilbilde av nivået på informasjonssikkerheten i organisasjonene. Konklusjonene i denne masteroppgaven er at sertifiserte organisasjoner har et høyere modenhetsnivå enn organisasjoner som har valgt å benytte standarden til å implementere et uformelt styringssystem for informasjonssikkerhet. De organisasjoner som har implementert et uformelt styringssystem har et høyere modenhetsnivå enn de organisasjonene som ikke har implementert noen form for styringssystem.ENGELSK: This thesis will focus on whether organisations which have certified their ISMS according to BS 7799 achieve a better capability for preventing, detecting, and reacting to security breaches, so that the consequences of security breaches may be reduced. The thesis will also explore if there is any difference between organisations which use the BS 7799 informally versus organisations which do not use the standard at all. In these days, it is a challenge for the information community that IS is managed in many different ways. Today, and in the future, it may be vital that IS is handled according to a set of common principles independent of the organisation. We conducted a survey in the form of a questionnaire. The questionnaire was distributed to IS manager or IS staff in 40 Norwegian organisations which we expected to have implemented a type of ISMS. Eight of the organisations were certified according to BS 7799-2 and we had a clear expectation that a focus on IS was an important issue in the remaining organisations. In the questionnaire we asked the organisations for the following: - the consequences of security breaches which have hit the organisations from 1999 to 2004, estimated as financial loss - how security breaches are handled in the organisation and the possibilities for us to get access to statistical data regarding security breaches - which parts of the ISMS are implemented and how they are implemented In regard to the questions about ISMS, we asked about the vital parts which should have been implemented in all organisations which have a certain need for protecting their assets. The replies regarding the consequences of and the statistical data on security breaches were too few to compare certified organisations, organisations using the standard informal and organisations not using a standard at all. The rest of the questionnaire focused on the vital parts of the ISMS. The replies to these questions made it possible to estimate the maturity level of the ISMS within the organisations. The ISMS maturity level may be regarded as a reflection of the IS status of the organisations. The conclusions in this thesis are that organisations certified according to BS 7799-2 have a higher maturity level versus organisations which have chosen to implement an ISMS informally. Those organisations which have implemented an informal ISMS have higher maturity than those organisations which have not implemented an ISMS at all

    Is BS 7799 worth the effort?

    No full text
    NORSK: Denne masteroppgaven fokuserer på hvorvidt organisasjoner som har sertifisert sitt styringssystem for informasjonssikkerhet etter BS 7799, oppnår en bedre evne til å forebygge, detektere og reagere på sikkerhetsbrudd slik at konsekvensene ved sikkerhetsbrudd reduseres. Masteroppgaven vil også utforske om det er en forskjell på organisasjoner som benytter BS 7799 på en uformell måte kontra organisasjoner som ikke benytter standarden. I disse dager er det en utfordring for informasjonssamfunnet at informasjonssikkerhet et styrt og håndtert på mange forskjellige måter. I dag, og i fremtiden, kan det være vitalt å kunne håndtere informasjonssikkerheten iht. et felles sett med prinsipper, uavhengig av organisasjon. Vi har gjennomført en undersøkelse i form av en spørreundersøkelse. Spørreundersøkelsen ble distribuert til sikkerhetssjefer eller stabspersonell innen informasjonssikkerhet i 40 norsk virksomheter hvor vi forventet at et styringssystem for informasjonssikkerhet var implementert. Åtte av virksomhetene var sertifisert etter BS 7799-2. Vi hadde også klare forventninger til at informasjonssikkerhet var et viktig tema i de andre virksomhetene. I spørreundersøkelsen spurte vi organisasjonene om følgende: -konsekvensene som har rammet organisasjonen fra 1999 til 2004, estimert som økonomiske tap - hvordan brudd på informasjonssikkerhet er håndtert i organisasjonen og mulighetene for oss til å få tilgang til de statistiske data angående brudd på sikkerheten - hvilke deler av styringssystemer som er implementert og hvordan det er implementert Angående spørsmålet om styringssystem for informasjonssikkerhet spurte vi om de vitale delene som burde vært implementert i alle virksomheter med et visst behov for å beskytte organisasjonens verdier. Svarene angående konsekvenser og statistiske data angående brudd på sikkerheten var for få til å sammenligne sertifiserte organisasjoner, organisasjoner som benytter standarden uformelt og de organisasjoner som ikke benytter en standard. Resten av spørreskjemaet fokuserte på de vitale delene av et styringssystem for informasjonssikkerhet. Svarene på disse spørsmålene gjorde det mulig å estimere modenhetsnivået på organisasjonens styringssystem for informasjonssikkerhet. Modenhetsnivået på styringssystemet for informasjonssikkerhet kan ansees som et speilbilde av nivået på informasjonssikkerheten i organisasjonene. Konklusjonene i denne masteroppgaven er at sertifiserte organisasjoner har et høyere modenhetsnivå enn organisasjoner som har valgt å benytte standarden til å implementere et uformelt styringssystem for informasjonssikkerhet. De organisasjoner som har implementert et uformelt styringssystem har et høyere modenhetsnivå enn de organisasjonene som ikke har implementert noen form for styringssystem.ENGELSK: This thesis will focus on whether organisations which have certified their ISMS according to BS 7799 achieve a better capability for preventing, detecting, and reacting to security breaches, so that the consequences of security breaches may be reduced. The thesis will also explore if there is any difference between organisations which use the BS 7799 informally versus organisations which do not use the standard at all. In these days, it is a challenge for the information community that IS is managed in many different ways. Today, and in the future, it may be vital that IS is handled according to a set of common principles independent of the organisation. We conducted a survey in the form of a questionnaire. The questionnaire was distributed to IS manager or IS staff in 40 Norwegian organisations which we expected to have implemented a type of ISMS. Eight of the organisations were certified according to BS 7799-2 and we had a clear expectation that a focus on IS was an important issue in the remaining organisations. In the questionnaire we asked the organisations for the following: - the consequences of security breaches which have hit the organisations from 1999 to 2004, estimated as financial loss - how security breaches are handled in the organisation and the possibilities for us to get access to statistical data regarding security breaches - which parts of the ISMS are implemented and how they are implemented In regard to the questions about ISMS, we asked about the vital parts which should have been implemented in all organisations which have a certain need for protecting their assets. The replies regarding the consequences of and the statistical data on security breaches were too few to compare certified organisations, organisations using the standard informal and organisations not using a standard at all. The rest of the questionnaire focused on the vital parts of the ISMS. The replies to these questions made it possible to estimate the maturity level of the ISMS within the organisations. The ISMS maturity level may be regarded as a reflection of the IS status of the organisations. The conclusions in this thesis are that organisations certified according to BS 7799-2 have a higher maturity level versus organisations which have chosen to implement an ISMS informally. Those organisations which have implemented an informal ISMS have higher maturity than those organisations which have not implemented an ISMS at all

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Is BS 7799 worth the effort?

    No full text
    NORSK: Denne masteroppgaven fokuserer på hvorvidt organisasjoner som har sertifisert sitt styringssystem for informasjonssikkerhet etter BS 7799, oppnår en bedre evne til å forebygge, detektere og reagere på sikkerhetsbrudd slik at konsekvensene ved sikkerhetsbrudd reduseres. Masteroppgaven vil også utforske om det er en forskjell på organisasjoner som benytter BS 7799 på en uformell måte kontra organisasjoner som ikke benytter standarden. I disse dager er det en utfordring for informasjonssamfunnet at informasjonssikkerhet et styrt og håndtert på mange forskjellige måter. I dag, og i fremtiden, kan det være vitalt å kunne håndtere informasjonssikkerheten iht. et felles sett med prinsipper, uavhengig av organisasjon. Vi har gjennomført en undersøkelse i form av en spørreundersøkelse. Spørreundersøkelsen ble distribuert til sikkerhetssjefer eller stabspersonell innen informasjonssikkerhet i 40 norsk virksomheter hvor vi forventet at et styringssystem for informasjonssikkerhet var implementert. Åtte av virksomhetene var sertifisert etter BS 7799-2. Vi hadde også klare forventninger til at informasjonssikkerhet var et viktig tema i de andre virksomhetene. I spørreundersøkelsen spurte vi organisasjonene om følgende: -konsekvensene som har rammet organisasjonen fra 1999 til 2004, estimert som økonomiske tap - hvordan brudd på informasjonssikkerhet er håndtert i organisasjonen og mulighetene for oss til å få tilgang til de statistiske data angående brudd på sikkerheten - hvilke deler av styringssystemer som er implementert og hvordan det er implementert Angående spørsmålet om styringssystem for informasjonssikkerhet spurte vi om de vitale delene som burde vært implementert i alle virksomheter med et visst behov for å beskytte organisasjonens verdier. Svarene angående konsekvenser og statistiske data angående brudd på sikkerheten var for få til å sammenligne sertifiserte organisasjoner, organisasjoner som benytter standarden uformelt og de organisasjoner som ikke benytter en standard. Resten av spørreskjemaet fokuserte på de vitale delene av et styringssystem for informasjonssikkerhet. Svarene på disse spørsmålene gjorde det mulig å estimere modenhetsnivået på organisasjonens styringssystem for informasjonssikkerhet. Modenhetsnivået på styringssystemet for informasjonssikkerhet kan ansees som et speilbilde av nivået på informasjonssikkerheten i organisasjonene. Konklusjonene i denne masteroppgaven er at sertifiserte organisasjoner har et høyere modenhetsnivå enn organisasjoner som har valgt å benytte standarden til å implementere et uformelt styringssystem for informasjonssikkerhet. De organisasjoner som har implementert et uformelt styringssystem har et høyere modenhetsnivå enn de organisasjonene som ikke har implementert noen form for styringssystem

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship
    corecore