IT如何準備資安稽核?

一個重視資安且內控制度完整的企業,一定會建立起完善內外稽核系統。

透過內外部資安稽核施作,可強化企業資安體質,且透過所建立PDCA機制,持續提升企業資安的有效性。我於2019年年底剛取得ISMS認證的工程師,透過年度外稽的實兵演練,分享首次接受稽核的準備工作及心得。

首次接觸ISMS制度

在我還沒受稽核訓練前,初次接觸資安稽核工作的時候,我是協助同仁準備資安稽核文件的角色,當中包括處理文件、歸納文件等等的工作內容,並也藉由全程參與外部稽核的機會,更近距離感受稽核當下的氣氛。會有產生一種ISMS只是文件整理的錯覺。

參與ISO 27001資訊安全管理制度主導稽核員訓練課程期間,導師教導資安稽核的觀念、解釋條文的內容、稽核的技巧等,並透過分組討論、模擬情境的方式實作並導正觀念。獲得資安稽核基礎認知後,工作上能夠處理得更適切、也越能夠了解其中的脈絡和意義。對於資產風險管控與分析以及活用PDCA的流程操作有了一番新的體驗。

ISMS過程中需關注多個面向

資訊安全規章辦法多以中性字眼呈現,但是在一些資產風險管理上就必需採取嚴謹的用詞才能確保風險分析的價值,目的是為了搭配不同的組織文化做相對應的措施,多閱讀企業內部文件並與規章辦法做連結,這種練習可以加深對條文的理解以及增加對內部文件的熟悉程度。歸納來說,ISMS相關的條例或辦法可以滿足各類企業管控所需,因為它有足夠的彈性去滿足在經費、人力、制度各方面的需求。 

準備資安稽核涵蓋的項目很多,資產清冊、風險評估、緊急應變措施、各式記錄、文件化資料等等,這些項目除了熟能生巧之外,應該要了解其中的來龍去脈、搭配檢討、調整。或許過程略為辛苦,但是對我來說就是一個制度訓練的基礎。

首次外稽給予的衝擊

當外稽進入公司大門開始,填寫訪客通知單、攜帶物品單、閱讀資安規定,年度外稽就已經開始,這也是公司資安制度的常態落實。

由於年度稽核是企業相當期待的一件事情,所以在開始會議前,公司的資安官、資安部門主管、文件管理員、內部稽核員以及相關負責同仁會提前就位,等待著外部稽核員的到來,此時的氣氛很正式。進行開始會議時,外部稽核員會向與會人員說明當次稽核的流程及重點,開始會議之後,就留下IT部門接受外部稽核員的檢視,稽核過程只能以誠惶誠恐作比喻,生怕有哪個小細節沒有做好。

首先外部稽核員會針對去年的次缺與建議事項和負責的同仁進行追蹤確認,接者參考「適用性說明書」,建立條文規章與內部文件的對應關係,這是稽核員後續驗證說、寫、做一致的階段性參考文件,也是稽核方及受稽方都會關注的一個重點。

由於外部稽核不像內稽熟悉內部運作細節,所以還會透過翻閱「內部稽核報告」的方式蒐集資訊、搭配稽核方法做抽樣驗證。資安稽核所羅列的資料十分繁雜,但稽核員必需在有限的時間內進行調查,所以也會以「文件流程的關聯性」作為判定符合規章辦法的依據。最後的外部稽核結束會議,宣告著此次稽核的完成,但不代表制度流程的句點,而必需持續改善。

良善的態度準備資安稽核

在準備資安稽核工作的時候,難免會與同仁互動、交流,由於過程可能會中斷同仁作業或造成多餘工作負擔的關係,容易導致同仁有排斥的情形發生,必需耐心地向同仁解釋並傳遞是基於協助的立場、沒有找碴的意思,建立互助合作的渠道有利於後續檢視並尋找、討論需要改善的地方。

稽核的當下,稽核方與受稽方在處於不對等的關係,雙方都應了解稽核的目的是在於發現問題並達到持續改善的作用,所以建議受稽方敞開心胸配合稽核人員的調查,倘若與稽核人員意見分歧的時候,也要沉澱思索、回歸到稽核的主軸判斷並與稽核人員溝通。

資安稽核不只是文件管理的工作,它是一個透過制度性的管控降低企業資安風險的最適制度,畢竟資安是人、資料、系統與公司文化的結合,要高層的支持,同仁的配合,才有辦法持續與完善。

 

 

關於Version 2 Limited

Version 2 Limited是亞洲最有活力的IT公司之一,公司發展及代理各種不同的互聯網、資訊科技、多媒體產品,其中包括通訊系統、安全、網絡、多媒體及消費市場產品。透過公司龐大的網絡、銷售點、分銷商及合作夥伴,Version 2 Limited 提供廣被市場讚賞的產品及服務。Version 2 Limited 的銷售網絡包括中國大陸、香港、澳門、臺灣、新加坡等地區,客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於精品科技

精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。

 

關於Version 2

Version 2 Digital 是立足亞洲的增值代理商及IT開發者。公司在網絡安全、雲端、數據保護、終端設備、基礎設施、系統監控、存儲、網絡管理、商業生產力和通信產品等各個領域代理發展各種 IT 產品。透過公司龐大的網絡、通路、銷售點、分銷商及合作夥伴,Version 2 提供廣被市場讚賞的產品及服務。Version 2 的銷售網絡包括台灣、香港、澳門、中國大陸、新加坡、馬來西亞等各亞太地區,客戶來自各行各業,包括全球 1000 大跨國企業、上市公司、公用事業、醫療、金融、教育機構、政府部門、無數成功的中小企及來自亞洲各城市的消費市場客戶。

關於精品科技
精品科技(FineArt Technology) 成立於1989年,由交大實驗室中,一群志同道合的學長學弟所組合而成的團隊,為一家專業的軟體研發公司。從國內第一套中文桌上排版系統開始,到投入手寫辨識領域,憑藉著程式最小、速度最快、辨識最準等優異特性,獲得許多國際大廠的合作與肯定。歷經二十個寒暑,精品科技所推出的產品,無不廣受客戶好評。

Airline leaked 9.4 million customers personal privacy,could face huge fines of $4 billion.

Recently, an airline issued an announcement on its website. It revealed that the personal data of about 9.4 million passengers were stolen. The incident began in March, confirmed in May, and announced in October. Personal information includes passenger name, nationality, telephone number, passport number, etc. In this incident,business not only faces with the crisis of brand image and customer confidence,it may face a huge fine of nearly $4 billion due to its failure to notify the incident in time under the EU's General Data Protection Regulations (GDPR). Let the business grow in the long term | Start with protecting assets At the network security level, the most common challenges for businesses are prevention, detection, and response to protect business endpoints, servers, networks, and sensitive data. Installing anti-virus software is the first step. However, in the face of today's endless network attacks, this step is relatively passive. The airline incident started with a system anomaly in March and confirmed the leakage of data in May. It was announced in October and the whole process lasted for more than six months. A company spokesperson said that it took so long to find out exactly what happened. The environment faced by businesses is complex and severe. Especially for airlines with large-scale business, many employees, and extremely valuable customer information stored, they will naturally become the target of hackers. Today, companies should use the widest range of potential sources to obtain anti-virus information in order to make predictive adjustments and adapt to an evolving security environment. Targeted attacks, advanced stubborn threats (APT), zero-day viruses, and botnet activity are hard to find for security engineers who only get relevant information from the company's internal network environment. On the contrary; using artificial intelligence and machine learning, early warning, and monitoring various threats from inside and outside of company, businesses can then respond in a timely manner and reduce losses. Preventing data leakage depends on professional software assistance X-FORT electronic data control system, integrated protection, without loopholes In planning control, many system authorisations of MIS and senior executives and managerswith the most information but not under supervision will be ignored. The employers’mindset is always different from that of the employees. The managers want convenience. Employees want to work smoothly.In order not to cause inconvenience to employees’ work, but also make the employers feel at ease,internal security control is indispensable. X-FORT allows MIS system setting, managers to check the information,senior executives to easily master reports and easily manage internal security. Main functions · Integrate AD to provide remote deployment ·Protection features include any channels that may write data · Does not change the user's operating experience, does not affect the user's computer operation ·Humanistic and intuitive UI management interface, zero learning costfor managers · Instant warning, regular delivery of operation reports, mastering the usage condition of employees' computers · Select functions according to the requirements of business security, and provide flexible space for future expansion

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About FineArt Technology Co., Ltd.
FineArt Technology Co., Ltd. was founded in September 1989 and made public offering on December 29, 2006. Fineart is engaged in the research, development, design and distribution of software and hardware. The company’s products include handwriting recognition and application software, which are applied in personal computers (PCs), electronic dictionaries, personal digital assistants (PDAs), smart phones, translators, label printers and car global positioning (GPS) navigators; universal serial bus (USB) external device applications, which are used in USB flash drives, USB fingerprint software and fingerprint software notebooks, and information security applications, which are used for electronic monitoring to prevent corporate data leaks, enterprise software and hardware management and monitoring and personal information systems. It distributes its products within the domestic market and to overseas markets.

Customer Satisfaction

Company Profile

Established in 1989, FineArt Technology Co., Ltd. began as a team of NCTU graduates that shared the same vision in professional software R&D.
The company has collaborated with international companies and is widely acclaimed for its compact, speedy, and accurate program features from the first local Desk Top Publishing (DTP) to Handwriting Recognition (HR). FineArt Technology’s product line has received positive feedback from its customers over the past 20 years.

In addition to substantial OEM/ODM market development, FineArt Technology also engages in information protection, computer asset management, and USB application software to provide professional Data Leak Protection (DLP) for enterprise and personal users and meet customers’ software product requirements. The company persists in stringent quality control and enthusiasm in providing customers with the most comprehensive and reliable products and services.

FineArt Technology holds great pride in its technology and R&D experiences. Other than numerous national awards and more than 110 patents locally and overseas, it has also excelled in domestic and overseas product sales. FineArt software is found in one of seven USB flash drives worldwide! It also successfully gained entry in the Japanese market with high-quality information security products used by many world-renowned customers. Its handwriting recognition software is also adopted by CASIO, the leading electronic dictionary manufacturer in Japan with over 3 million authorized sales annually. Not only has FineArt established reputable credibility amongst its clients, it has also proved its mature and reliable professionalism in software.

As its name implies, FineArt insists on developing the most innovative and functional products in pursuit of art and beauty. With years of R&D experience, FineArt aims to achieve innovative breakthroughs and expand overseas markets so that Taiwan can become one of the world leaders in software technology.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About FineArt Technology Co., Ltd.
FineArt Technology Co., Ltd. was founded in September 1989 and made public offering on December 29, 2006. Fineart is engaged in the research, development, design and distribution of software and hardware. The company’s products include handwriting recognition and application software, which are applied in personal computers (PCs), electronic dictionaries, personal digital assistants (PDAs), smart phones, translators, label printers and car global positioning (GPS) navigators; universal serial bus (USB) external device applications, which are used in USB flash drives, USB fingerprint software and fingerprint software notebooks, and information security applications, which are used for electronic monitoring to prevent corporate data leaks, enterprise software and hardware management and monitoring and personal information systems. It distributes its products within the domestic market and to overseas markets.