林毅力

高鼎精密材料股份有限公司 / 總經理室 副理

資歷:

  • 2 年政府標案 - 軟體工程師
  • 5 年 - 資訊系統工程師
  • 7 年 - 資訊部門主管
  • 2 年 - 集團經營管理、資訊、稽核、人資、安衛環 等單位主管。
  • 製造業 \ 中小企業專業幕僚,持有 CCSP \ CISSP \ CISM \ CISA \ CEH \ ITIL \ PMP \ ACP \ Associate C|CISO 等國際認證。
SPEECH
4/17 (Thu.) 14:30 - 15:00 4F Cyber Talent Cyber Talent Forum
From PDDRO to TTQS: Integrating ISO 27001 to Establish a Corporate Cybersecurity Training Framework and Enhance Training Investment Efficiency

People have always been the weakest link in cybersecurity. Incidents such as data breaches, social engineering attacks, and phishing campaigns often result in significant financial or reputational losses for organizations. Therefore, leveraging the TTQS and PDDRO models in conjunction with the cybersecurity management requirements of ISO 27001 has become a critical task for enterprises. By addressing the five stages of Planning, Design, Execution, Output, and Improvement, organizations can systematically design, implement, and evaluate cybersecurity training activities after identifying their security objectives.

ISO 27001 provides a systematic cybersecurity management framework. By using its risk assessment and control measures as the basis for training needs, organizations can enhance the relevance of training activities and ensure alignment with international standards.

Additionally, the principle of Continual Improvement resonates with the improvement stage of TTQS, facilitating the ongoing optimization of information security training quality.

Ultimately, integrating TTQS, PDDRO, and ISO 27001 can improve the efficiency of training investments, ensuring that every dollar spent is well-utilized. This approach also highlights the strategic value of IT personnel within an organization. These practical insights and outcomes are the focus of this sharing session.