Skip navigation

DSpace JSPUI

DSpace preserves and enables easy and open access to all types of digital content including text, images, moving images, mpegs and data sets

Learn More
DSpace logo
English
中文
  • Browse
    • Communities
      & Collections
    • Publication Year
    • Author
    • Title
    • Subject
    • Advisor
  • Search TDR
  • Rights Q&A
    • My Page
    • Receive email
      updates
    • Edit Profile
  1. NTU Theses and Dissertations Repository
  2. 社會科學院
  3. 國家發展研究所
Please use this identifier to cite or link to this item: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/101397
Title: 探討金融業面臨的資安風險及因應對策-以臺灣為例
Cybersecurity Risks and Countermeasures Faced by the Financial Industry: A Case Study of Taiwan
Authors: 周聖倫
Sheng-Lun Chou
Advisor: 鄧志松
Chih-Sung Teng
Keyword: 金融資安,ISO 27001NIST CSF資安治理DDoS 攻擊ATM 遭駭
Financial Cybersecurity,ISO 27001NIST Cybersecurity Framework(NIST CSF)Cybersecurity GovernanceDDoS AttacksATM Hacking
Publication Year : 2026
Degree: 碩士
Abstract: 隨著金融科技(FinTech)快速發展,資訊科技已成為金融業運作的基石,帶來便利與效率,但也引發日益嚴峻的資安挑戰。臺灣金融業近年屢次發生重大資安事件,包括 2016 年第一銀行 ATM 遭駭盜領案、2023 年上海商業儲蓄銀行客戶個資外洩案,以及 2024 年親俄駭客組織之大規模 DDoS 攻擊,顯示金融業不僅面臨外部駭客的組織化威脅,亦受限於內部治理失效、法規遵循流於形式及供應鏈安全管理缺失等結構性問題。
本研究採用文獻分析與個案比較法,系統性整理臺灣金融業資安事件之類型與成因,並建構「技術、制度、法律」之三維度分析架構。研究發現,當前防禦體系之失靈,核心原因在於機構往往陷入「形式合規」之誤區,過度倚重技術採購,而忽略了管理制度之實質執行度與法律聯防之自動化效能。
依據上述分析架構,本研究針對結構性成因提出五大核心因應策略:
技術面,推動「情資導向主動防禦」與「多層次防禦機制」,建議導入威脅情報平台(TIP)與 AI 智能偵防;制度面,落實「權限最小化分層管理」與「制度合規實質化」,主張全面導入零信任架構,並以資安長(CISO)職權實質化作為落實基礎,法律與協作向,建構「跨產業情資聯防與共享機制」,建議透過法制化之「免責保障條款」提升分享意願,實現自動化之生態系聯防。
未來展望應聚焦於新興科技之資安防護,藉由整合技術韌性、制度實效與法律保障,協助臺灣金融業建構具備「反脆弱」特質之防衛體系,從根本提升整體產業之韌性與國際競爭力。
The rapid growth of Financial Technology (FinTech) has made information technology essential to financial operations, but it has also intensified cybersecurity risks. Major incidents in Taiwan—such as the 2016 First Bank ATM heist, the 2023 Shanghai Bank data breach, and the 2024 large-scale DDoS attacks—highlight not only sophisticated external threats but also internal weaknesses, including governance failures, superficial regulatory compliance, and poor supply chain security.
This study analyzes these issues using a three-dimensional framework: Technology, Institution, and Law. The main finding is that many defense failures result from “formal compliance”—an overemphasis on acquiring technical solutions while neglecting effective management practices and automated legal collaboration.
To address these structural vulnerabilities, five core countermeasures are proposed:
Technical: Adopt intelligence-driven, proactive, and multi-layered defense mechanisms, leveraging Threat Intelligence Platforms (TIP) and AI-based detection.
Institutional: Implement hierarchical management with least privilege, strengthen real compliance through Zero Trust architecture, and empower Chief Information Security Officers (CISO).
Legal/Collaborative: Build cross-industry intelligence sharing and joint defense mechanisms, including Safe Harbor clauses to encourage information sharing.
Looking ahead, integrating technical resilience, effective governance, and legal safeguards is crucial for Taiwan’s financial industry to build an “anti-fragile” defense system, enhancing both resilience and international competitiveness.
URI: http://tdr.lib.ntu.edu.tw/jspui/handle/123456789/101397
DOI: 10.6342/NTU202600152
Fulltext Rights: 未授權
metadata.dc.date.embargo-lift: N/A
Appears in Collections:國家發展研究所

Files in This Item:
File SizeFormat 
ntu-114-1.pdf
  Restricted Access
1.38 MBAdobe PDF
Show full item record


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

社群連結
聯絡資訊
10617臺北市大安區羅斯福路四段1號
No.1 Sec.4, Roosevelt Rd., Taipei, Taiwan, R.O.C. 106
Tel: (02)33662353
Email: ntuetds@ntu.edu.tw
意見箱
相關連結
館藏目錄
國內圖書館整合查詢 MetaCat
臺大學術典藏 NTU Scholars
臺大圖書館數位典藏館
本站聲明
© NTU Library All Rights Reserved