»s³y·~
  °]¸g¬É
  ¸ê°T¬É
  ¾Ç³N¬É
  ¬F©²¬É
  ´CÅé¬É
  IT²£·~
  ¤å¤Æ³q¸ô·~
  ©Ð«Î¥ò¤¶·~
  ¹ØÀI·~
  ¨ä¥L·~§O

 

 

 

¾Ç³N¬É¦W¤H±M³X
»¡©ú
¥ø·~ÅéÀË ¡U ºô¯¸¾ÉÄý ¡U ·|­û±M°Ï

ªôºa½÷
ÂǥѼзǡA¥ø·~¯à§ó¤F¸Ñ¦Û¨­¡A³z¹LºÞ²z¥i¦b¦w¥þ»P®Ä²v¤¤¨ú±o¥­¿Å

¥ø·~­n¹ê¬ICNS 17799¤§¸ê°T¦w¥þºÞ²z³W½d¡AÀ³´x´¤ PDCA (Plan-Do-Check-Act)¤§­ì«h¡A«ùÄò¸g¥Ñ³W¹º¡]Plan¡^¡B°õ¦æ¡]Do¡^¡BÀˮ֡]Check¡^¡B¦æ°Ê¡]Act¡^¼Ò¦¡¡A´`Àô§ïµ½¤½¥q¤§¸ê°T¦w¥þºÞ²z¡C
                                                  ¡Ðªø©°¤j¾Ç¹q¾÷¤uµ{¾Ç¨t°Æ±Ð±Â

³o´X¦~¸ê°T¦w¥þ¨Æ¥ó¼h¥X¤£½a¡AÄ´¦p¡G¤¤°êºô­x¤J«I°Ñ»Pº~¥úºt²ß¤§±Ð©x©Ò¨Ï¥Îªº¹q¸£¡A´Ó¤J¤ì°¨µ{¦¡¯f¬r¡A¦Ó¨Ïºt²ß¸ê®Æ¥~¬ª¡FµL½u°Ï°ìºô¸ô¤§WEP¥[±K¾÷¨î³Q¯}¸Ñ¡A¦Ó¨Ï¥HµL½u¤¬¶Ç¤§¸ê®Æ³QÅѨú¡F»È¦æ´£´Ú¥d³Q°¼¿ýµs«þ¡A¦Ó¨Ï±b¤á¤º¤§¦s´Ú³Qµs»â¡F¥xÅKºô¸ô­q²¼¨t²Î¾D¨ü·m²¼µ{¦¡§ðÀ»¡A¦Ó¨Ï­q²¼¨t²ÎÅõºÈ¡F¹q¸£¸ê°T¤½¥q¤§¤£ªk¾­ûµs¨ú¨Ã³c°â«È¤á¤§«H¥Î¥d¥d¸¹¡B¹q¸Ü¦í§}µ¥¸ê®Æ¡A¦Ó¨ÏÅU«È¾D¨ü·l¥¢¡C³o¨Ç¸ê°T¦w¥þ¨Æ¥óµo¥Íªº­ì¦]¡A¦³ªº¬O¦]¹q¸£ªº¨t²Î¦³¦w¥þº|¬}¦Ó³Q¤J«I§ðÀ»¡A¦³ªº¬O¦]©Ò¨Ï¥Î¤§±K½Xºtºâªk¦³®zÂI¦Ó¨ü³Q¯}¸Ñ¡A¦³ªº¬O¦]¸ê®ÆÀx¦s¸Ë¸mµL¨­¤ÀŲ§O»P¦s¨ú±±¨î¦Ó³Q°¼¿ýµs«þ¡A¦³ªº¬O¦]µ{¦¡³]­p¯Ê¥¢¦Ó¨üªýµ´ªA°È(Denial of Service, DoS)§ðÀ»¡A¦³ªº¬O¦]¸ê°T¨t²Î©Î¤½¥q¤§¸ê¦wºÞ²z¨î«×¤§¤£°·¥þ¦Ó¸ê®Æ³Q¬ª±K©Îµs°â¡C¥Ñ©óªÀ·|ªº¹q¤l¤Æ¡A¤é±`¤u§@»P¥Í¬¡·U¨Ó·U¨Ì¿à¸ê³q°T¨t²Î¡A¦]¦¹¸ê°T¦w¥þ¨Æ¥óªºµo¥Í¡A¦b¦b¼vÅT¨ì¤@¯ë¤H¥Í¬¡¡A¥H¤Î«Â¯Ù¥ø·~ªº¥¿±`Àç¹B¡C



ºô¸ô±a°Ê¥ø·~¤Î¬F©²§Ö³te¤Æ¡A¨Ï±o¸ê¦w°ÝÃD¤£Â_µo¿N¤¤
¸Û¦p¤W­z¡A¸ê¦w¨Æ¥óµo¥Íªº­ì¦]«Ü¦h¡A¦ý·í¥ø·~Åå¶Ç¸ê®Æ¥~¬ª¨Æ¥ó®É¡A¥Ø«e¤j³¡¤À°ÝÃD¤´¬O¦b©ó¡A¹ï¤º³¡¤H­û¤§¸ê¦wºÞ理­±¤W¥X²{漏洞¡CÀHµÛ¥ø·~¸ê°T¤Æµ{«×ªº´£¤É¡A¥ø·~Àç¹B©Òô¤§¹q¸£ºô¸ô¨t²Î¤]·U¨Ó·UÃeÂø¡A³o¤]¤è«K¥~³¡¯f¬r©ÎÀb«È¤§¤J«I¡B¤º³¡¤£¨v­û¤u¤§´c·d¡C¦b¼u«ü¶¡¡A¤½¥q¤§¸ê°T¨t²Î¦³¥i¯à¾D¨ü¹q¸£¯f¬r§ðÀ»¦ÓÅõºÈ¡A©Î¤½¥q¤§°Ó·~¯µ±K¸ê®Æ¦³¥i¯à¾D¨üÅѨú¦Ó¸g¥Ñºô¸ô©Î¹q¶l(email)¥~¬ª¡C³oÅý¥ø·~ĵı¨ì¡A¸ê¦w¨Æ¥ó¤§¼vÅT¥i¯à«Ü¤j«Ü²`»·¡A¬Æ¦Ü¥i¯à°Ê·n¨ì¥ø·~¤§¥Í¦s¡C³o¤]¦]¦¹±a°Ê¥ø·~ªº¸ê¦w»Ý¨D¡AÅý¥ø·~¶}©l­«µø¸ê¦wºÞ²z¡B­·ÀIµûŲ¡B©M«æÃøÀ³ÅÜ¡C


¥ø·~¦b³oºØ¸ê¦w¨Æ¥óÀW¶Ç¤§Àô¹Ò¤¤¡A­n¦p¦ó¦]À³¡Hªø©°¤j¾Ç¹q¾÷¤uµ{¾Ç¨t°Æ±Ð±Âªôºa½÷«ØÄ³¡G¥ø·~­º¥ýÀ³µû¦ô¤F¸Ñ¨Ã­q©w¡A¤½¥q¤§¸ê°T¦w¥þ¬Fµ¦¡A¥H«Å¥Ü¤½¥q¹ï¦UÃþ¸ê²£¤§¦w¥þ±±ºÞ­ì«h¡F¦A¨Ì¦¹¸ê°T¦w¥þ¬Fµ¦¡AÀ˰QÀÀ­q¹q¸£ºô¸ô¨t²Î»P¦UºØ¤½¥q§@·~¤Î¸ê®Æªº¸ê°T¦w¥þ»Ý¨D¡F±µµÛ¡A¨Ì¦¹¦w¥þ»Ý¨DÀÀ©w¤½¥q¤§¸ê°T¦w¥þºÞ²z¨î«×¤Î¨ä§@·~³W½d¡Cªôºa½÷ªí¥Ü¡A¥ø·~¦b³W¹º«Ø¸m¤½¥q¤§¸ê³q°T¨t²Î»P¸ê°T¦w¥þºÞ²z¨î«×®É¡A¥i°Ñ¦Ò¤¤µØ¥Á°ê°ê®a¼Ð·Ç CNS 17799¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T¦w¥þºÞ²z¤§§@·~³W½d »P CNS 27001¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T¦w¥þºÞ²z¨t²Î¡Ð­n¨D¨Æ¶µ¡C³o¨â­Ó¼Ð·Ç¬O´£¨Ñ¥ø·~¤@®M§¹¾ãªº¸ê°T¦w¥þªººÞ²z¾÷¨î¡AÅý¥ø·~¦b¾É¤J«á¡A¥i¶i¤@¨B­°§C¦]¤º¥~¦b«Â¯Ù¦Ó³y¦¨ªº¸ê¦w­·ÀI»P¤½¥q·l¥¢¡A¥H¨¾½d¥¼µM¡C³z¹L«Ø¸m¦¹®M¸ê°T¦w¥þºÞ²z¨î«×¡A¥i´£¤É¥ø·~­«­n¸ê·½»P¸ê®Æªº¥i¥Î©Ê¡B§¹¾ã©Ê»P¾÷±K©Ê¡C



CNS 17799¡BCNS 17800´N¬O¤@®M¸ê¦w°ê»Ú»{ÃҼзÇ
CNS 17799 ¬O°ê»Ú¸ê°T¦w¥þºÞ²z¼Ð·ÇBS 7799 »PISO 17799 ¤§¤¤¤å¤Æ¼Ð·Ç¡CBS 7799¬O­^°ê¼Ð·Ç¨ó·|(British Standards Institution, BSI)¤§¸ê°T¦w¥þºÞ²z¼Ð·Ç¡A³QISO (International Organization for Standardization) ±µ¯Ç¦¨¬°°ê»Ú¤§¸ê°T¦w¥þºÞ²z¼Ð·Ç¡CBS7799 Part1³QÂà½s¬° ISO 17799¡GInformation technology - Security techniques - Code of practice for information security management¡ABS7799 Part2³QÂà½s¬° ISO 27001¡G Information technology - Security techniques - Information security management systems - Requirements¡C¸gÀÙ³¡¼Ð·ÇÀËÅç§½°Ñ¦ÒISO17799 ¨î©wCNS 17799¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T¦w¥þºÞ²z¤§§@·~³W½d¼Ð·Ç¡F°Ñ¦ÒISO 27001 ¨î©wCNS 27001¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T¦w¥þºÞ²z¨t²Î¡Ð­n¨D¨Æ¶µ¼Ð·Ç¡CCNS 17799¬O¸ê°T¦w¥þºÞ²z¤§°Ñ¦Ò³W½d¡A¤º®e¥]§t11¤jºÞ±±¶µ¥Ø¡]¥]¬A¡G¦w¥þ¬Fµ¦¡B¦w¥þ²Õ´¡B¸ê²£¤ÀÃþ»P±±¨î¡B¤H¤O¸ê·½¦w¥þ¡B¹êÅé»PÀô¹Ò¦w¥þ¡B³q°T»P§@·~ºÞ²z¡B¦s¨ú±±¨î¡B¸ê°T¨t²Î¤§Àò±oµo®i»PºûÅ@¡B¸ê¦w¨Æ¬GºÞ²z¡BÀç¹B«ùÄòºÞ²z¡B¿í´`»P½]®Ö¡^¡B39­ÓºÞ±±¥Ø¼Ð¡B133­ÓºÞ±±±¹¬I¡CCNS 27001¬O¸ê°T¦w¥þºÞ²z¤§ÅçÃÒ³W½d¡A¨Ì­Ó§O¥ø·~¤§¤£¦P»Ý¨D¡A½Õ¾ã¨ä©Ò»Ý¤§ºÞ±±±¹¬I¡A¨Ã¾Ú¥H¼f¬dÅçÃÒ¸Ó¥ø·~¬O§_²Å¦XCNS 17799¤§¸ê°T¦w¥þºÞ²z³W½d¡C



ÂǥѼзǡA¥ø·~¯à§ó¤F¸Ñ¦Û¨­¡A³z¹LºÞ²z¥i¦b¦w¥þ»P®Ä²v¤¤¨ú±o¥­¿Å
ªôºa½÷°Æ±Ð±Â«ØÄ³¡G¥ø·~­n¹ê¬ICNS 17799¤§¸ê°T¦w¥þºÞ²z³W½d¡AÀ³´x´¤ PDCA (Plan-Do-Check-Act)¤§­ì«h¡A«ùÄò¸g¥Ñ³W¹º¡]Plan¡^¡B°õ¦æ¡]Do¡^¡BÀˮ֡]Check¡^¡B¦æ°Ê¡]Act¡^¼Ò¦¡¡A´`Àô§ïµ½¤½¥q¤§¸ê°T¦w¥þºÞ²z¡Cªô±Ð±Â¤]´£¿ô¡A¦w¥þ¬O¥þ­±©Ê¤§°ÝÃD¡CÄ´¦p¡A¤½¥q¤§°Ó·~¾÷±K¸ê®Æ¬O¨Ï¥Î³Ì°ª¦w¥þµ¥¯Å¤§±K½Xºtºâªk«OÅ@¡A¦ý­Y¨ä¥[¸Ñ±K¤§Æ_°Í¥¼«OºÞ¦n¡A«h¤]ªPµM¡C¦]¬°¸ê°T¦w¥þ»Ý¥þ­±©Ê¤§ºÞ²z¡A¥ô¦ó¤@­ÓÀô¸`¥X²{°ÝÃD¡A¸ê¦w§ðÀ»¥i¯à·|ÀH¤§¦Ó¦Ü¡C¦Ó­n¸ê°T¦w¥þºÞ²z¯à­±­±­ÝÅU¡A¥B­n«ùÄò§ïµ½¡A½T¹ê¬O»Ý­n§ë¤J¬Û·í¦h¤§¤ß¤O¡Cªô±Ð±Â¤]ªí¥Ü¡A¸ê°T¨t²Î¤§¦w¥þ¨¾Å@¬O¬Û¹ïªº¡A¥ø·~»Ýµû¶qªº¬O¡A©Ò­n«OÅ@¤§¸ê·½ªº»ù­È©Ê¦h°ª¡A¦p¦¹¤~¯à¿Å¶q»Ý­n¦w¥þµ¥¯Å¦h°ª¤§¸ê¦w¨t²Î¨Ó¨¾Å@»PºÞ²z¡C¦P®É¡A¤]»Ý¦Ò¶q¸ê³q°T¨t²Î¤§¦w¥þ¨¾Å@©Ê»P¨Ï¥Î®Ä²v©Ê¬O¬Û¤¬½Ä¬ðªº¡A¨t²Î¦w¥þ­n¨D¶VÄY¡A¨ä®Ä²v»P«K§Q©Ê´N¶V§C¡C³o¹ï­«µø®Ä²v¤§¥ø·~¦Ó¨¥¡A³o¬O¨âÃøªº¨ú±Ë¡C


¦p¦ó­ÝÅU¸ê³q°T¨t²Î¤§¦w¥þ©Ê»P®Ä²v©Ê¡Hªôºa½÷±Ð±Â«ØÄ³¡G¥ø·~©y°w¹ï©Ò¦³¤§¸ê²£¡Aµû¦ô¨ä­«­n©Ê¤Î¨ä¬Û¹ï¤§¦w¥þ»Ý¨D¡C¦b¦Ò¶q©Ò»Ý¤§¦w¥þ©Ê»P®Ä²v©Ê¤U¡A³W¹º¨ä¬Û¹ïÀ³¤§¸ê¦wºÞ²z³W½d¡C¬°¤FÀ±¸É¦]¤½¥q¹B§@®Ä²v¤§»Ý¨D¦ÓÄ묹¤§¦w¥þ©Ê¡A¦]¤£¥i¯à­±­±­ÝÅU©Ò²£¥Í¤§¸ê¦w¯Ê¥¢¡A¥H¤ÎµLªk¹w´Á¤§¨t²Î¼ç¦bº|¬}©Î·N¥~¸ê¦w¨Æ¬G¡A¸ê¦wºÞ²z¨t²ÎÀ³¦³­·ÀIµûŲºÞ²z¡B¥H¤Î¦M¾÷À³ÅܳB²z¤§³W¹º³]­p¡A§Y©w´Á¤ÀªRµû¦ô¸ê³q°T¨t²Îªº¥i¯à¯Ü®zÂI»P¨ä«Â¯Ù¡A«Ø¥ß¸ê°T¦w¥þ­·ÀI¶µ¥Ø»P¨äµûµ¥¡A³W¹º»P¸¨¹ê­°§C­·ÀI¤§ºÞ±±±¹¬I¡Cªôºa½÷»{¬°¡A¸g¥Ñ¾A·í¤§­·ÀIµûŲºÞ²z¡A¥iÅý¸ê³q°T¨t²Î¡A¦b©Ò³]­p¤§¦w¥þ©Ê»Ý¨D¤U¡A¤£¦ý¥i´£¨Ñ¥ø·~©Ò»Ý¤§¨t²Î®Ä²v¡A¤]¯à±N¸ê¦w­·ÀI­°§C¨ì¥i±µ¨üªº½d³ò¤º¡C


CNS 17799 ¸ê°T¦w¥þºÞ²z¨t²ÎÁöµM²[»\¤§¸ê¦wijÃD¼sªx¡A¦ý¥D­n¬OµÛ­«©óºÞ²z­±ªº¸ê¦w»Ý¨D¡A¦Ó¤£µÛ­«¦b§Þ³N­±ªº±M·~ª¾ÃÑ¡C³o¬O§_·|¼vÅT©ÒºÞ²z¤§¸ê³q°T¨t²Î¤§¦w¥þ©Ê¡H-ªôºa½÷°Æ±Ð±Âªí¥Ü¡ACNS 17799 Áö¥uµÛ­«©óºÞ²z­±¡A¦ý³o¨Ã¤£·|¼vÅT©Ò³W¹º«Ø¸m¤§¸ê°T¨t²Îªº¦w¥þ©Ê¡C¦n¤ñ¡A¤½¥q¨Ì·~°ÈºÞ²z»Ý¨D¤§¤£¦P¡A±ÄÁʤ£¦Pµ¥¯Å¤§¨T¨®¡B¾÷¨®¨Ñ­û¤u¨Ï¥Î¡CÁöµM¤½¥q­û¤u¨ÃµL»s§@¨T¾÷¨®¤§±M·~§Þ³N¡A¦ý¦b¾A·í¤§ºûÅ@ºÞ²z¾÷¨î¤U¡A¸Óµ¥¨T¾÷¨®À³¯àµo´§¨äÀ³¦³¤§¥\¯à¡C¦P²z¡A¦b CNS 17799¸ê°T¦w¥þºÞ²z¨t²Î¤§ºÞ±±¤U¡AµwÅé³]³Æ¤§«Ø¸m¡B³nÅéµ{¦¡¤§¶}µo¡A¬Ò¥i©e¥~³B²z¡Cªôºa½÷»¡¡A¨Ì´`CNS 17799³W½d¡A©w´Á¶i¦æ¸ê¦w¨t²Î¤§³W¹ºÅ禬¡B±±¨î±¹¬I¤§¬yµ{ºÞ²z¡B«ùÄò¹B§@¤§½]®Ö§ïµ½¡A¤½¥q¤§¸ê°T¨t²ÎÀ³¯à¹F¨ì©Ò³W¹º¤§¦w¥þµ¥¯Å»P¥i±µ¨ü¤§­·ÀI¥Ø¼Ð¡C



CNS¦³Ãö¸ê¦w¼Ð·Ç¤§µo¥¬¬Û·í§Ö³t¡A¥B¤º®e§¹¾ã¤SÂ×´I
ªôºa½÷°Æ±Ð±Â³¯­z¡A§Ú°ê¤§¸ê³q¦w¥þ¼Ð·Ç¡A­ì«h¤W¬O°Ñ·ÓISO°ê»Ú¼Ð·Ç¦Ó¨î©w¡C¥Ø«eISO¥¿­pµe¥é·ÓISO 9000«~½èºÞ²z¨t¦C¼Ð·Ç¡A±N©Ò¦³¸ê°T¦w¥þºÞ²z¨t²Îªº¨t¦C¼Ð·Ç³W¹º¦p¤U¡G
ƒ{ ISO 27000 Principles and vocabulary
ƒ{ ISO 27001 ISMS Requirements
ƒ{ ISO 27002 (§Y¥Ø«e¤§ISO 17799:2005)
ƒ{ ISO 27003 ISMS Risk management
ƒ{ ISO 27004 ISMS Metrics and measurement
ƒ{ ISO 27005 ISMS Implementation guidelines
ƒ{ ISO 27006-27010(«O¯d¥¼¨Óµo®i¥Î)
¥¼¨Ó¡A¼ÐÀ˧½À³·|¤ñ·Ó«ùÄò¨î©w CNS 27000-27005¤§¸ê°T¦w¥þºÞ²z¨t¦C¼Ð·Ç¡C¥Ñ¦¹¥iª¾¡A¬F©²©Î¥ø·~¦b¸ê°T¦w¥þºÞ²z¤è­±¡A¿í´`¨Ã¾É¤JCNS27000¨t¦C¼Ð·Ç¡AÀ³¯àÀò±o»ô¥þ»P§¹µ½¸ê°T¦w¥þºÞ²z³W½d¡C¬G¥ø·~¾É¤JCNS 27000¤§¸ê°T¦w¥þºÞ²z¨t¦C¼Ð·Ç³W½d¡AÀ³¯à´£¨Ñªº¥²­n©Ê¡A


ªôºa½÷°Æ±Ð±Â±j½Õ¡AÁöµM¤W­z¤º®e¥uµÛ­«©ó¤¶²ÐCNS 17799»PCNS27001¸ê°T¦w¥þºÞ²z¼Ð·Ç¡A¦ýCNS¦³Ãö¸ê°T¦w¥þ¤§¼Ð·ÇÁ٫ܦh¡CÄ´¦p¡A
¦³ÃöŲ§O(Authentication)¤§¼Ð·Ç
CNS 13789¸ê°T§Þ³N¢w¦w¥þ§Þ³N¢w¹êÅéŲ§O¾÷¨î
¦³Ãö¼Æ¦ìñ³¹(Digital Signature)¤§¼Ð·Ç
CNS-14105¸ê°T§Þ³N¡V¦w¥þ§Þ³N¡VÂø´ê¨ç¼Æ
CNS-14510¸ê°T§Þ³N-¦w¥þ§Þ³N-¤£¥i§_»{©Ê
CNS-14563¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¨ã°T®§¦^´_ªº¼Æ¦ìñ³¹¤è®×
CNS-14629¸ê°T§Þ³N¢w¦w¥þ§Þ³N¢w¨ãªþ¥ó¤§¼Æ¦ìñ³¹
¦³Ãöºô¸ô¦w¥þ(Network Security)¤§¼Ð·Ç
CNS-14992¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T§Þ³N¤J«I°»´ú®Ø¬[
¦³Ãöª÷Æ_ºÞ²z(Key Management)¤§¼Ð·Ç
CNS-14379»È¦æ·~¡Ð¨Ï¥Î«D¹ïºÙºtºâªkªºª÷Æ_ºÞ²z
CNS-14380»È¦æ·~¡Ð¹s°â¦¡ª÷Æ_ºÞ²z
CNS-14381¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ðª÷Æ_ºÞ²z
¦³Ãöª÷¿Ä¦w¥þ(Financial Security)¤§¼Ð·Ç
CNS-13798»È¦æ·~¡V­Ó¤HÃѧO½XºÞ²z»P¦w¥þ
CNS-13936ª÷¿Ä¥æ©ö¥d¡V¨Ï¥Î¢×¢Ñ¥dªºª÷¿Ä¥æ©ö¨t²Î¤Uªº¦w¥þ¬[ºc
CNS-14644»È¦æ¤Î¬ÛÃöª÷¿ÄªA°È·~¢w¸ê°T¦w¥þ«ü¤Þ
CNS-14770»È¦æ·~¡Ð¹s°â¦¡¦w¥þ±K½X¸Ë¸m
¦³Ãö¸ê¦wºÞ²z(Information Security Management)¤§¼Ð·Ç
CNS-14731¸ê°T¦w¥þºÞ²z¨t²ÎÅçÃÒ/µn¿ý¾÷ºc¤§»{ÃÒ«ü¤Þ
CNS-14929¸ê°T§Þ³N¡Ð¸ê°T§Þ³N¦w¥þºÞ²z«ü¾Éºõ­n
CNS-17799¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T¦w¥þºÞ²z¤§§@·~³W½d
CNS-27001¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T¦w¥þºÞ²z¨t²Î¡Ð­n¨D¨Æ¶µ
¦³Ãö¦w¥þÀË´ú(Security Evaluation)¤§¼Ð·Ç
CNS-15408¸ê°T§Þ³N¡Ð¦w¥þ§Þ³N¡Ð¸ê°T§Þ³N¦w¥þµû¦ô·Ç«h



CNS¤§¦r¦r·r°u¡Aºë·Ç«×¬Æ¥i­â¾r¨ä¥L°ê»Ú¸ê¦w¼Ð·Ç
¦]¬°ªôºa½÷°Æ±Ð±Â¬O¼ÐÀ˧½¸ê³q°T°ê®a¼Ð·Ç¼f¬d©e­û¤§¤@¡A°ò©ó¦h¦~¨Ó°Ñ»P¸ê³q°T¼Ð·Ç¤§¼f¬d¸gÅç¡A¥Lªí¥Ü¡ACNSªº¼Ð·Ç¤j³£¬°ISO¡BITUµ¥°ê»Ú¼Ð·Ç¤§¤¤¤å¼Ð·Ç¡A¦Ó¼ÐÀ˧½¦b­q©wCNSªº¼Ð·Ç¹Lµ{¤¤¡A¹ï¤º®e¤§¥¿½T»P¹F·N¡A­n¨D«D±`°ª¡A¥i»¡¬O¥Î¡y¦r¦r·r°u¡zªº¤è¦¡¨Ó¨î©w¼Ð·Ç¤º®e¡C¯S§O¬Oªñ¦~¨Ó³\¦h¼Ð·Ç¤å¥óªºÂ½Ä¶¡A¬O¥Ñ¨ã¦³±M·~­I´º¤§²£©x¾Ç¬É¤H¤h¾á·í¡A¦bCNSªº¼Ð·Ç¨î­q¹Lµ{¤¤¡A¯àµo²{¨Ã§ó¥¿­ì¤å¼Ð·Ç¤§¤º®e¿ù»~¡A³oÅýCNSªº¼Ð·Ç§ó¯à­È±o¤j®a¤§«H¥ô¡C


¸ê°T¦w¥þ¼Ð·Ç»P¨ä¥L¼Ð·Ç¤@¼Ë¡A¨ÃµL±j¨î©Ê¡A¦ý³o¬O¥ø·~­n«Øºc¨ä¸ê³q°T²Î¤ÎºÞ²z¦¹¨t²Î¤§°Ñ¦Ò¨Ì¾Ú¡A¤]¬O¥ø·~¦b¸ê°T¦w¥þºÞ²z¤Î¨ä²£«~¤W¤§«~½è«ü¼Ð¡C¥ø·~¾É¤JCNSªº°ê®a¼Ð·Ç³W½d¡A¥i¨ã¦³¦Pµ¥©ó²Å¦X°ê»Ú¼Ð·Ç¤§«~½è¼Ð¥Ü¡Cªôºa½÷°Æ±Ð±Âªí¥Ü¡AÁöµM¹ê°È¤W¨ÃµLµ´¹ï¦w¥þ¤§¼Ð·Ç³W½d¡A¦ý¥ø·~­Y¯à¿í´`CNSªº¸ê°T¦w¥þ¬ÛÃö¼Ð·Ç³W½d¡A³z¹L¼Ð·Ç¨î«×»P±±¨î±¹¬Iªº¨ó§U¡AÀ³¥iÁ×§K³\¦h¤£¥i¹w´Áªº¸ê¦w¨Æ¥óµo¥Í¡A¥i­°§C­û¤u¥¢»~¬ªº|¡BÀb«È¤J«I©Î¯f¬r§ðÀ»¤§·l¥¢»P­·ÀI¡AÅý¥ø·~ªº¸ê°T¦w¥þ¨¾Å@§ó¥[§¹µ½¡C¤£½×¥ø·~©Î­Ó¤H¡A­Y¯à¿í´`CNS 27001¤§PDCA (Plan-Do-Check-Act)«ùÄò§ïµ½¤§¤èªk¡A¨­Åé¤O¦æ¡A«h¥¼¨Ó±N¨ü¥Î¤£ºÉ¡C

 

      

 

²£«~ªA°È | À³¥Î¹ê¨Ò | Ãö©óHiB2B | ªA°È¹Î¶¤ | FAQ | »P§ÚÁpµ¸ | ºô¯¸¾ÉÄý | ·|­û±M°Ï
HiB2B¤¤µØ¹q«H¥ø·~¹q¤l°Ó°ÈAll Rights Reserved. ª©Åv©Ò¦³¡Eµs¥Î¥²¨s ¡UÁô¨pÅvÁn©ú¡U