跳到主要內容區塊

資訊安全政策

壹、目的

元長鄉公所(以下簡稱本所)為強化本所資訊安全管理作業,除遵循上級機關及政府資訊安全管理業務機關(行政院資通安全處)相關資訊安全作業內容外,並採用國際標準資訊安全管理標準(ISO/IEC 27001),建立一套適合本所資訊安全防護機制,確保本所資訊安全作業符合相關法令要求外,達到機密性、完整性及可用性之作業要求,使本所資訊安全管理擁有可信賴之服務環境。

貳、依據

  1. 資通安全管理法
  2. 國家機密保護法
  3. 個人資料保護法
  4. 文書處理手冊
  5. ISO/IEC 27001 (Information technology — Security techniques — Information security management systems — Requirements)
  6. ISO/IEC 27002 (Information technology — Security techniques — Code of practice for information security management)
  7. ISO/IEC 27005(Information technology — Security techniques —Information Security Risk Management)
  8. ISO/IEC 27006 (Information technology — Security techniques – Requirements for bodies providing audit and certification of information security management systems)
  9. ISO/IEC 27007 (Information security, cybersecurity and privacy protection — Guidelines for information security management systems auditing)
  10. ISO/IEC TS 27008(Information technology — Security techniques — Guidelines for the assessment of information security controls)
  11. ISO/IEC 27009 (Information technology — Security techniques — Sector-specific application of ISO/IEC 27001 — Requirements)
  12. ISO/IEC 27010 (Information technology — Security techniques — Information security management for inter-sector and inter-organizational communications)
  13. ISO 31000 (Risk management — Guidelines)
  14. IEC 31010 (Risk management — Risk assessment techniques)