論文名稱 個資法施行後對組織之衝擊與因應-以S大學為例
(Organization Impact of the Personal Information Protection Act and a Proposed Solution – the Case of University “S”)
摘要(中) 《個人資料保護法》正式公告實施後,讓台灣個人資料保護邁入新的里程碑。近來頻頻發生資訊安全外洩事件及侵害個人隱私資料事件,因而喚起社會大眾對個人資料保護意識。在此環境下若無完善之資訊安全防護機制及個人資料保護的措施,很容易造成個人資料外洩的問題,尤其個資法實施後,一旦發生個資外洩事件,不僅衝擊組織的形象,更可能面臨法律責任及鉅額賠償的問題。

個案學校雖然每年透過第三方取得資訊安全管理標準ISO 27001 驗證,已提供完善的資訊安全的防護基礎,但是校方在面對個資法的衝擊及教育部要求之下,需以保護個人資料的角度來審視現行的資訊安全制度,以降低校方所面臨的法律衝擊及加強保護個人資料的安全措施。


針對衝擊及問題,在符合個資法及配合校方已實施資訊安全管理系統 (ISMS) 的條件下,採用 BS 10012 個人資料保護系統 (PIMS) 及PDCA管理循環的作法,本研究提出因應個資法衝擊之改善方案,並規劃個人資料保護系統的實施步驟,利用由上而下的改善方式,透過擴大校方原有的資訊安全制度,來完善個人資料保護的深度及廣度,降低校方誤觸個資法的風險,進而達到保障個人資料之目的。
摘要(英) The official announcement and implementation of the “Personal Information Protection Act” has propelled the privacy protection issue in Taiwan into a new era. Recently, frequent occurrence of information security leaks and data privacy violation events has awakened public awareness concerning this issue. Personal information leakage is likely to happen under circumstances without comprehensive information security protection mechanisms and personal information protection measures in place. Especially after the implementation of the “Personal Information Protection Act,” personal information leakage incidents will not only impact the image of the organization but also result in legal liabilities and severe damage compensation.

Having already acquired information security management ISO 27001 annual certification through a third party, University “S” is covered with a comprehensive information security protection base. However, the university is still faced with the impact of “Personal Information Protection Act” and the related requests from the Ministry of Education. It must further examine the existing information security system from the viewpoint of personal information protection to reduce the legal impact and strengthen security measures to protect personal information.

This study aims to provide a solution for the university facing such a problem. First, a review of relevant literature concerning the “Personal information Protection Act,” information security, and protection of personal information is conducted. Second, it seeks to understand the current status of the university through examining the information security measures and information assets. Third, it analyzes the legal impact and issues faced by the university in accordance with the “Personal Information Protection Act,” Personal Information Protection Act Enforcement Rules, and the use of personal information life cycle.

Finally, based on the Personal Information Protection Act and Information Security Management System (ISMS) implemented by the school, this study also adopts the BS 10012 Personal Information Management System (PIMS) and PDCA viewpoints, it proposes a set of actions in response to the impact of the Personal Information Protection Act. Detail implementation steps are also outlined. We adopt the top-down improvement method to improve personal information protection in depth and breadth, reduce the risk of violating Personal Information Protection Act, and achieve the purpose of protecting personal information by expanding the existing security system of the university.
關鍵字(中) ★ 個人資料保護法
★ 個人資訊管理制度
★ ISO 27001
★ BS 10012
關鍵字(英) ★ Personal Information Protection Act
★ ISO 27001
★ BS 10012
論文目次 摘要 v
Abstract vi
誌謝 vii
目錄 viii
圖目錄 x
表目錄 xi
第一章 緒論 1
1.1 研究背景 1
1.2 研究動機 1
1.3 研究目的 2
1.4 論文架構 3
第二章 文獻探討 4
2.1 個人資料保護法 4
2.2 資訊安全管理系統 (ISMS) 11
2.3 個人資料保護系統 (PIMS) 16
2.4 ISMS、PIMS與個資法相關比較 20
2.5 個資法之因應研究整理 24
第三章 個案衝擊與問題 27
3.1 個案背景介紹 27
3.2 個案學校簡介 28
3.3 資訊系統與資訊安全管理現況盤點 29
3.4 個案衝擊及問題 33
第四章 個案改善方案 43
4.1 個資保護管理制度的建立 43
4.2 個資保護管理制度的具體改善方案及步驟 48
4.3 可行性分析 60
4.4 小結 62
第五章 結論與建議 69
5.1 研究結論 69
5.2 對管理之建議 70
5.3 未來研究方向 71
參考文獻 72
指導教授 范錚強(Cheng-Kiang Farn) 審核日期 2014-7-14
