資安實務與規範
Information Security Practice and Regulation
| 節 | 週五 |
|---|---|
2 09:00–09:50 | 資安實務與規範 A305 3 節連堂 |
3 10:10–11:00 | |
4 11:10–12:00 |
* 根據陽明交大上課時間表所列
This course is designed to provide an in-depth introduction to Information Security Practice and Regulation. Its primary objective is to impart a comprehensive understanding of international standards of information security and the best practice for industry. Topics range from security or privacy-oriented standards such as ISO 27001/27002 (ISMS), 27701 (PIMS), 27014 (IS Governance) and 29134 (PIA) to standards for specific domains such as IEC 62443 (OT), ISO 28001 (SCM), 42001 (AIMS), 38505 (Data Governance), 23576 & 23244 (Blockchain and distributed ledger technologies). This course offers an extensive introduction to the practices and regulations of information security, designed to equip students with a thorough understanding of the international standards governing information security and industry best practices. Our primary goal is to ensure learners acquire a deep and comprehensive knowledge of how to maintain security and privacy in various organizational contexts, guided by globally recognized standards. Throughout the course, we will cover a broad spectrum of security and privacy-oriented standards, including: - ISO 27001/27002 for Information Security Management Systems (ISMS), - ISO 27701 for Privacy Information Management Systems (PIMS), - ISO 27014 for Information Security Governance, - ISO 29134 for Privacy Impact Assessment (PIA), - Other domain-specific standards such as IEC 62443 (OT), ISO 28001 (SCM), ISO 42001 (AIMS), ISO 38505 (Data Governance), and ISO 23576 & 23244 (Blockchain and distributed ledger technologies). This curriculum is carefully crafted to not only present theoretical knowledge but also to provide practical insights of these standards, preparing students for the real-world challenges they will face in the information security field.
NA
授課教師講授、個案討論
Homework 45% Final Project 25% Midterm Exam 20% Final Exam 20%
| 週次 | 主題 |
|---|---|
| 第 1 週 | Introduction to ISMS (資訊安全管理系統導論) |
| 第 2 週 | ISO 27001/27002 (資訊安全管理系統) |
| 第 3 週 | ISO 27001/27002 (資訊安全管理系統) |
| 第 4 週 | ISO 27001/27002 (資訊安全管理系統) |
| 第 5 週 | ISO 27701 (隱私管理系統) |
| 第 6 週 | ISO 27701 (隱私管理系統) |
| 第 7 週 | ISO 29134 (隱私衝擊分析) |
| 第 8 週 | Midterm Exam (期中考) |
| 第 9 週 | ISO 29134 (隱私衝擊分析) |
| 第 10 週 | ISO 27014 (資安治理管理規範) |
| 第 11 週 | IEC 62443 (工控安全管理規範) |
| 第 12 週 | ISO 28001 & ISO 27036 (供應鏈安全管理規範) |
| 第 13 週 | ISO 28001 & ISO 27036 (供應鏈安全管理規範) |
| 第 14 週 | Other Issues: ISO 42001, ISO 38505, ISO 23576 & 23244 (人工智慧管理系統、區塊鏈管理規範) |
| 第 15 週 | Final project (分組報告) |
| 第 16 週 | Final Exam (期末考) |
Self-Designed Teaching Material
- 地點
- 工六363室 (EF363)
- 時間
- 周五13:00 (請預約)
- 聯絡方式
- khyeh@nycu.edu.tw