研究生: 舒君達
論文名稱: 具資安韌性之遠距工作框架
A Framework of Securing Cyber-Resilient Telework
指導教授: 吳宗成
Tzong-Chen Wu
口試委員: 吳宗成
Tzong-Chen Wu
Nai-Wei Lo
Chuan-Kai Yang
學位類別: 碩士
系所名稱: 管理學院 - 資訊管理系
Department of Information Management
論文出版年: 2021
畢業學年度: 109
語文別: 中文
論文頁數: 52
中文關鍵詞: 遠距工作資安韌性安全框架風險評估
外文關鍵詞: Telework, Cyber-resilience, Security Framework, Risk Assessment
After the outbreak of COVID-19 in the early 2020, the crisis has ubiquitously impacted the general public and disturbed the business continuity globally. The partially adopted and valued telework has now become prevalent in a different way, and due to the advancement of information and communication technology, it is conceivable that telework will become the New Normal, meaning telework will continue to be adopted even if the crisis has subsided. However, several new and advanced threats have arisen during the pandemic outbreak, for instance, the exploit of communication platform’s vulnerability and the unprecedented surge in internet traffic because of the digital transformation. All of these threats could potentially pose harm to the confidentiality, integrity and availability of teleworker’s information and organization’s outcome simultaneously. Therefore, it is imperative to develop a framework of securing cyber-resilient telework.
In this thesis, we refer to the enterprise telework security guide published by NIST, then interpret most of the security controls mentioned in the publication and revise the other, while integrating trending concepts such as “cyber resilience”, “infosec governance” and “risk assessment” into the proposed framework. Enabling enterprises to delivery their expected outcome, despite adverse conditions; and recognize their security postures and security requirements based on risk assessment results, then determine the corresponded security controls according to their security requirements and business scales, and implement the framework effectively by means of hierarchical collaboration; thus achieving telework security.

摘要 I ABSTRACT II 誌謝 III 目錄 IV 圖目錄 VI 表目錄 VII 第一章 緒論 1 1.1 研究背景與動機 1 1.2 研究目的 4 1.3 論文架構 6 第二章 文獻探討 7 2.1 資安韌性 7 2.2 風險評估方法 9 第三章 本研究提出之框架 11 3.1 遠端存取解決方案安全 12 3.1.1 遠端存取伺服器安全 12 3.1.2 遠端存取伺服器建置 13 3.1.3 遠端存取鑑別、授權及存取控制 16 3.1.4 遠端存取客戶端軟體安全 19 3.1.5 遠端存取解決方案關鍵指引總結 20 3.2 遠距工作客戶端裝置安全 21 3.2.1 確保遠距工作個人電腦安全 24 3.2.2 確保遠距工作行動裝置安全 26 3.2.3 保護遠距工作客戶 端裝置資料 27 3.2.4 遠距工作客戶端裝置關鍵指引總結 31 第四章 框架 部署 考量 32 4.1 遠端存取生命週期安全考量 32 4.1.1 初始階段 34 4.1.2 開發階段 37 4.1.3 實施階段實施階段 38 4.1.4 運作及維護階段運作及維護階段 40 4.1.5 汰除階段汰除階段 40 4.1.6 遠端存取生命週期關鍵指引總結遠端存取生命週期關鍵指引總結 41 4.2 資安韌性資安韌性 42 4.3 資安治理資安治理 43 4.4 風險評估風險評估 44 第五章 結論與未來研究方向結論與未來研究方向 47 5.1 結論結論 47 5.2 未來研究方向未來研究方向 49 參考文獻 50

