跳到主要內容

簡易檢索 / 詳目顯示

研究生: 吳泳霖
Ng Wing Lam
論文名稱: 台灣保險業資訊安全風險治理之探討
A Study on Information Security Risk Governance in Taiwan’s Insurance Industry
指導教授: 蔡政憲
Tsai, Cheng-Hsien
口試委員: 湯美玲
Tang, Mei-Ling
黃孝慈
Huang, Hsiao-Tzu
學位類別: 碩士
Master
系所名稱: 商學院 - 風險管理與保險學系
Department of Risk Management and Insurance
論文出版年: 2026
畢業學年度: 114
語文別: 中文
論文頁數: 98
中文關鍵詞: 資訊安全風險治理保險業風險治理第三方風險國際監理比較
外文關鍵詞: information security risk governance, insurance industry, risk governance, third-party risk, international regulatory comparison
相關次數: 點閱:9下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 隨著數位轉型與保險科技逐漸普及,資訊安全風險已不再只是技術部門需要處理的問題,而是逐漸成為牽動公司治理、營運穩定與企業聲譽的重要議題。本研究從風險治理的角度出發,檢視我國保險業資訊安全制度中可能存在的治理缺口,並透過國際比較,提出可供參考的改進方向。
    本研究採用文獻分析法與比較研究法,先整理國際風險治理委員會 (IRGC)風險治理框架與經濟合作暨發展組織(OECD)公司治理原則,歸納出資訊安全風險治理應具備的五項核心要素,包括明確的職責分工、全面的風險辨識、明確的風險胃納、持續性的監督,以及完整的溝通與揭露機制。其後,本文以公司治理、技術控制、委外管理、事件通報與懲戒四大構面,比較美國、英國、新加坡、歐盟與香港的保險業資安監理制度,並與我國現況進行對照。
    研究發現,我國雖已逐步建立多層次的資安治理架構,但在高階主管個人問責、資安風險胃納、董事會資安能力要求、第四方與關鍵第三方集中度風險管理,以及懲戒制度等方面,仍有進一步強化的空間。
    因此,本研究建議我國可逐步強化高階主管個人問責,要求董事會核定可量化的資安風險胃納,提升核心技術控制要求的法規位階,建立風險分級的威脅導向測試制度,並深化第四方與第三方集中度風險管理。對業者而言,亦應更主動將資安納入董事會治理議程,使資訊安全管理不只是為了符合規定,而能真正成為公司日常治理的一部分。


    With the growth of digital transformation and InsurTech, information security risk (cybersecurity) is no longer only a technical issue for the IT department. It has gradually become an important governance issue that may affect corporate governance, business stability, and company reputation. This study looks at the information security system of Taiwan’s insurance industry from the perspective of risk governance. It aims to identify possible governance gaps and, through international comparison, suggest directions for improvement.
    This study uses literature analysis and comparative research. First, it reviews the Internation Risk Governance Council (IRGC) risk governance framework and the Organization for Economic Co-operation and Development (OECD)’s corporate governance principles. Based on these ideas, this study summarizes five key elements of information security risk governance: clear division of responsibilities, clear risk appetite, comprehensive risk identification, continuous supervision, and complete communication and disclosure mechanisms. Then, this study compares the cybersecurity regulatory systems for the insurance industry in the United States, the United Kingdom, Singapore, the European Union, and Hong Kong. The comparison is made through four aspects: corporate governance, technical controls, outsourcing management, and incident reporting and penalties.
    The research finds that Taiwan has gradually built a multi-level information security governance framework. However, there is still room for improvement in several areas, including personal accountability of senior managers, cybersecurity risk appetite, cybersecurity knowledge requirements for board members, fourth-party risk and key third-party concentration risk management, and penalty mechanisms.
    Therefore, this study suggests that Taiwan may gradually strengthen the personal accountability of senior managers, require the board of directors to approve measurable risk appetite, raise the legal level of key technical control requirements, build a risk-based threat-led testing system, and improve the management of fourth-party risk and third-party concentration risk. For insurance companies, they should also take a more active role in including information security in board-level governance. In this way, information security management will not only be a matter of compliance, but can become part of the company’s daily governance.

    第一章 緒論 7
    第一節 研究背景 7
    第二節 研究目的與動機 7
    第三節 研究方法 8

    第二章 資訊安全風險治理 10
    第一節 資訊安全風險 10
    第二節 資訊安全風險治理之理論基礎 15
    第三節 資安治理理論的體現 20
    第四節 國內保險業資訊安全相關研究 23

    第三章 台灣保險業資訊安全現狀 27
    第一節 台灣資訊安全監理現況 27
    第二節 我國保險業資訊安全監管架構 29
    第三節 台灣保險業主要實務資安缺失 36
    第四節 治理缺口歸納 39

    第四章 各國保險業資訊安全監管框架比較分析 42
    第一節 美國 42
    第二節 英國 50
    第三節 新加坡 56
    第四節 歐盟 63
    第五節 香港 68
    第六節 各國治理設計對照 73

    第五章 建議 80
    第一節 監理層面建議 80
    第二節 業者層面建議 86

    第六章 結論 88

    參考資料 92
    附錄一、保險業近六年的主要資安缺失 96

    中文部分:
    王綱(2021),銀行業與保險業運用雲端服務與個人資料保護之合規研究,國立政治大學法學院碩士在職專班學位論文,1-158。
    李珍穎(2019),淺談資安風險與網路保險之發展。中華民國產物保險商業同業公會,《保險大道》,78,48-55。
    安侯建業(2020),2020年臺灣保險業報告,https://shorturl.at/dY4NV。
    金管會(2022),金融資安行動方案2.0。金融監督管理委員會。https://reurl.cc/Wbm6nk
    金管會(2025),金融資安行動方案2.0重要措施及成效。金融監督管理委員會。https://reurl.cc/Z2kK6g。
    陳鑫如(2005),BS7799 基礎下資訊安全架構之探討-以人壽保險業為例,中原大學資訊管理學系學位論文,1-128。
    黃柏強(2018),我國資訊安全保險市場之研究,逢甲大學風險管理與保險學系
    碩士學位論文,1-93。
    謝正彬 (2012),保險業因應新版個資法之資安管理研究-以S公司為例,國立政治大學經營管理碩士學位論文,1-66。
    檢查局(2026),金融機構最近六年度主要檢查缺失,https://www.feb.gov.tw/ch/home.jsp?id=300&parentpath=0,5,297
    OneDegree (2024),臺灣保險業的資安曝險調查報告,
    https://shorturl.at/ahzIO

    英文部分:
    APRA. (2023). Cyber security stocktake exposes gaps. https://www.apra.gov.au/news-and-publications/cyber-security-stocktake-exposes-gaps?utm_source=chatgpt.com
    Bank of England. (2024). Outsourcing and Third Party Risk Management. https://www.bankofengland.co.uk/-/media/boe/files/prudential-regulation/supervisory-statement/2024/ss221-november-2024-update.pdf
    Bank of England. (2025). Critical Third Parties(CTPs).
    93
    https://www.bankofengland.co.uk/financial-stability/financial-market-infrastructure-supervision/fmi-rulebook/critical-third-parties
    Debevoise & Plimpton. (2020). Cybersecurity Requirements for Insurance Companies -The NYDFS Rules as the Emerging Standard. https://shorturl.at/sPPd1.
    EIOPA. (2025). European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act. https://www.eiopa.europa.eu/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital-2025-11-18_en
    European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). http://data.europa.eu/eli/reg/2016/679/oj
    European Union. (2022). Regulation (EU) 2022/2554 (Digital Operational Resilience Act). http://data.europa.eu/eli/reg/2022/2554/oj
    FCA. (2026). Senior Management Arrangements, Systems and Controls. https://handbook.fca.org.uk/handbook?entityId=sysc
    FSA. (2024). Results of the Cybersecurity Self Assessment for Insurance Companies(FY2023). https://www.fsa.go.jp/en/news/2024/20241224/cssa_en.html
    Financial Conduct Authority. (2026). FCA handbook: Senior management arrangements, systems and controls (SYSC). https://www.handbook.fca.org.uk/handbook/SYSC/
    IA. (2017). Guideline on Outsourcing. https://www.ia.org.hk/en/legislative_framework/files/GL14.pdf
    IA. (2024). Guideline on Cybersecurity. https://www.ia.org.hk/en/legislative_framework/files/GL20_Eng.pdf
    ISO. (2022). Information security, cybersecurity and privacy protection-Information security management systems-Requirements (ISO/IEC 27001:2022). https://www.iso.org/standard/82875.html
    Insurance Authority. (2024). Guideline on cybersecurity (GL20). https://www.ia.org.hk/en/legislative_framework/files/GL20_Eng.pdf
    Insurance Authority. (2017). Guideline on outsourcing (GL14). https://www.ia.org.hk/en/legislative_framework/files/GL14.pdf
    IRGC. (2017). Introduction to the IRGC risk governance framework. EPFL
    94
    International Risk Governance Center. https://shorturl.at/ynE3K
    Monetary Authority of Singapore. (2021). Technology risk management guidelines. https://www.mas.gov.sg/regulation/guidelines/technology-risk-management-guidelines
    Monetary Authority of Singapore. (2022). Notice FSM-N04 cyber hygiene. https://www.mas.gov.sg/regulation/notices/notice-fsm-n04
    Monetary Authority of Singapore. (2024). Notice FSM-N03 Technology Risk Management. https://www.mas.gov.sg/regulation/notices/notice-fsm-n03
    Monetary Authority of Singapore. (2025). Guidelines on Outsourcing (Financial Institutions other than Banks). https://www.mas.gov.sg/regulation/guidelines/guidelines-on-outsourcing-financial-institutions-other-than-banks
    NAIC. (2017). Insurance data security model law (Model Law 668). https://content.naic.org/sites/default/files/model-law-668.pdf
    NAIC. (2025). State legislative brief of the NAIC insurance data security model law. https://content.naic.org/sites/default/files/government-affairs-brief-data-security-model-law.pdf
    NIST. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
    NYDFS. (2023). Cybersecurity requirements for financial services companies (23 NYCRR Part 500). https://reurl.cc/L2Oyo7
    OECD. (2023). G20/OECD principles of corporate governance 2023. https://reurl.cc/9WkeAx
    ORX. (2023). Insights into material risks 2023. https://orx.org/resource/insights-into-material-risks-2023
    Plante Moran. (2020). Cybersecurity and the insurance industry: Challenges, opportunities, and strategies. https://reurl.cc/X281Ya
    Prudential Regulation Authority. (2021). Outsourcing and third party risk management (Supervisory Statement SS2/21). Bank of England. https://shorturl.at/SHr9B
    Prudential Regulation Authority. (2025). Insurance supervision: 2025 priorities. https://reurl.cc/yO8d86
    Renn, O. (2017). Risk governance: coping with uncertainty in a complex world.
    95
    Routledge.
    Singh, A., & Akhilesh, K. B. (2020). The insurance industry-Cyber security in the hyper-connected age. In Smart technologies: Scope and applications (pp. 201-219).
    Verizon. (2025). 2025 data breach investigations report. https://www.verizon.com/business/resources/reports/2025-dbir-data-breach-investigations-report.pdf
    Wilson, C., Gaidosch, T., Adelmann, F., & Morozova, A. (2019). Cybersecurity risk supervision. International Monetary Fund.
    World Economic Forum. (2026). Global risks report 2026. https://reports.weforum.org/docs/WEF_Global_Risks_Report_2026.pdf

    無法下載圖示 全文公開日期 2031/08/19
    QR CODE
    :::