Skip to content

Commit 2aa585e

Browse files
committed
Update and re-org contents
Signed-off-by: Shield of Self-Defense (ocf.tw) <ssd@ocf.tw>
1 parent edbd5a3 commit 2aa585e

54 files changed

Lines changed: 808 additions & 1747 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

docs/assessment/index.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,10 +12,9 @@ title: 進度追蹤
1212
<figcaption><small>「進度追蹤」階段</small></figcaption>
1313
</figure>
1414

15-
您目前在「[進度追蹤]」,服務導入團隊將定期關懷,並協助提供在專案推進與問題協助。(完整流程:「[課程主題]{target="_blank"}」、「[操作指南]{target="_blank"}」、「[制定資安政策]{target="_blank"}」、「[進度追蹤]{target="_blank"}」、「[疑問諮詢]{target="_blank"}」)
15+
您目前在「[進度追蹤]」,服務導入團隊將定期關懷,並協助提供在專案推進與問題協助。(完整流程:「[課程主題]{target="_blank"}」、「[制定資安政策]{target="_blank"}」、「[進度追蹤]{target="_blank"}」、「[疑問諮詢]{target="_blank"}」)
1616

1717
[課程主題]: ../chapter/index.md
18-
[操作指南]: ../user_guide/index.md
1918
[制定資安政策]: ../policy/index.md
2019
[進度追蹤]: ../assessment/index.md
2120
[疑問諮詢]: ../support/index.md

docs/chapter/abroad/index.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ title: 海外出差
3535

3636
!!! info "完成順序"
3737

38-
- 「設備加密」相關的操作可以參考「[操作指南:裝置安全](../user_guide/devices/index.md){target="_blank"}」。
38+
- 「設備加密」相關的操作可以參考「[操作指南:裝置安全](../../user_guide/devices/index.md){target="_blank"}」。
3939
- 「設備更新」的步驟或許會在「設備加密」之前,但不影響「設備加密」的問題,只需要都有完成即可。
4040

4141
### 備份、加密資料
@@ -47,8 +47,8 @@ title: 海外出差
4747

4848
!!! info "「備份」、「檔案加密」參考章節"
4949

50-
- 備份相關的介紹可以參考「[資料管理與備份](./files_management/index.md){target="_blank"}」。
51-
- 檔案加密的操作需要了解其原理與限制,可以參考「[加密通訊](./e2ee/index.md){target="_blank"}」章節的介紹。
50+
- 備份相關的介紹可以參考「[資料管理與備份](../files_management/index.md){target="_blank"}」。
51+
- 檔案加密的操作需要了解其原理與限制,可以參考「[加密通訊](../e2ee/index.md){target="_blank"}」章節的介紹。
5252

5353
### 通訊安全
5454

@@ -72,7 +72,7 @@ title: 海外出差
7272

7373
!!! note "關於「通訊安全」相關的章節"
7474

75-
可參考「[VPN](./network/vpn.md){target="_blank"}」、「[網路與 Wi-Fi](./network/wifi.md){target="_blank"}」、「[加密通訊](./e2ee/index.md){target="_blank"}」內容補充更多細節。
75+
可參考「[VPN](../network/vpn.md){target="_blank"}」、「[網路與 Wi-Fi](../network/wifi.md){target="_blank"}」、「[加密通訊](../e2ee/index.md){target="_blank"}」內容補充更多細節。
7676

7777
#### 緊急聯絡與應變
7878

docs/chapter/abroad/policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
icon: material/book-check
2+
icon: material/airplane
33
title: 海外出差政策規範
44
---
55

docs/chapter/account/management.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
---
2-
title: 帳號權限管理與追蹤
2+
title: 帳號管理原則
33
---
44

5-
# :material-account-key: 帳號權限管理與追蹤
5+
# :material-account-key: 帳號管理原則
66

77
目前以 Google Workspace 和 Microsoft 365 這兩個常見的線上協作工具作為範例。
88

docs/chapter/account/policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
icon: material/book-check
2+
icon: material/account-box
33
title: 帳號管理政策規範
44
---
55

docs/chapter/devices/index.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ title: 裝置安全
3535

3636
與裝置安全相關的操作指南,請參考此章節。
3737

38-
[:material-arrow-right-bold: 操作指南:裝置安全](../user_guide/devices/index.md){ .md-button .md-button--primary }
38+
[:material-arrow-right-bold: 操作指南:裝置安全](../../user_guide/devices/index.md){ .md-button .md-button--primary }
3939

4040
3. 裝置安全的在職培訓與教育
4141

@@ -51,4 +51,4 @@ title: 裝置安全
5151

5252
與裝置安全相關的制定政策範本,請參考此章節。
5353

54-
[:material-arrow-right-bold: 制定政策:裝置安全](../policy/devices.md){ .md-button .md-button--primary }
54+
[:material-arrow-right-bold: 制定政策:裝置安全](../devices/policy.md){ .md-button .md-button--primary }

docs/chapter/devices/policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
icon: material/book-check
2+
icon: octicons/devices-24
33
title: 裝置安全政策規範
44
---
55

docs/chapter/e2ee/policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
icon: material/book-check
2+
icon: material/shield-lock
33
title: 加密通訊政策規範
44
---
55

docs/chapter/files_management/files_access.md

Lines changed: 42 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -120,34 +120,70 @@ title: 檔案存取權限
120120
- 只有極少數授權人可以存取。
121121
- 需加密存儲和傳輸。
122122

123+
!!! example "範例:涉密的策略計畫、成員個資、捐款者名單等"
124+
125+
- **存取限制**:僅限極少數授權人員存取,如高層管理者和關鍵專案負責人。
126+
- **保護措施**:
127+
- 儲存:所有機密資料需加密儲存,且存放在安全的伺服器或加密硬碟中。
128+
- 傳輸:使用[加密通訊軟體](../../chapter/e2ee/im.md){target="_blank"}傳輸,如 Signal 或 PGP 加密的電子郵件。
129+
123130
#### 內部機密資料(Confidential)
124131

125132
- 涉及機敏或關鍵業務資料。
126133
- 僅限於特定內部人員存取。
127134
- 需加密存儲。
128135

136+
!!! example "範例:未公開的內部報告、專案規劃文件等"
137+
138+
- **存取限制**:僅限相關專案或業務的內部人員存取。
139+
- **保護措施**:
140+
- 儲存:使用加密硬碟或伺服器存儲。
141+
- 傳輸:確保資料在傳輸過程中經過加密,如利用 SSH 或 SSL 等通道。
142+
129143
#### 內部資料(Internal Use Only)
130144

131145
- 涉及內部運作的資料。
132146
- 內部員工可存取,但不可對外分享。
133147

148+
!!! example "範例:組織運作手冊、內部通訊等"
149+
150+
- **存取限制**:內部所有員工可存取,但不可對外分享。
151+
- **保護措施**:明確標示「僅供內部使用」,提醒員工勿對外泄露。
152+
134153
#### 公開資料(Public Use)
135154

136155
- 可以公開於網路或其他公開管道分享。
137156
- 該類資料不需特別的保護措施,但需確保資料準確性和完整性。
138157

158+
!!! example "範例:公開的宣傳材料、網站內容、新聞稿等"
159+
160+
- **存取限制**:可對外公開分享,不需特別存取限制。
161+
- **保護措施**:需確保資料的準確性和完整性,避免誤導或錯誤信息。
162+
139163
### 存取控制
140164

141165
#### 最小權限原則(Principle of Least Privilege)
142166

143167
- 任何使用者僅能存取其工作所需的最少部分資料。
144168
- 定期審查和更新使用者的存取權限。
145169

170+
!!! note "實施方法"
171+
172+
- 為每位使用者設定最小的存取權限,即僅能存取其工作必需的資料。
173+
- 使用權限管理工具(如 LDAP 或 IAM 系統)追蹤和管理使用者的存取權限。
174+
- 定期(建議每季一次)審查和更新使用者的存取權限,取消不需要的權限。
175+
146176
#### 分離職能(Segregation of Duties)
147177

148178
- 確保不同人員負責不同職能,以降低風險。
149179
- 避免單一人員擁有過多的權限。
150180

181+
!!! note "實施方法"
182+
183+
- 定義和區隔不同職能的責任,例如:資金管理與審核職能由不同人員負責。
184+
- 避免單一員工擁有多重機敏權限,減少內部風險。
185+
- 實施定期內部稽核,確保分離職能的落實。
186+
151187
#### 資料壽命周期(Data Lifecycle Management)
152188

153189
1. **建立(Creation)**:資料的產生或收集。
@@ -163,6 +199,12 @@ title: 檔案存取權限
163199
- 所有資料應依照其機密等級進行標記。
164200
- 範例:「機密」、「內部」、「公開」。
165201

202+
!!! note "實施方法"
203+
204+
- 依照上述機密等級為所有資料進行標記。
205+
- 例:「機密」資料標註「Top Secret」,「內部」資料標註「Internal Use Only」。
206+
- 每次新產生資料時,應即時進行分類和標記,保證資料在整個生命週期內得到適當的保護。
207+
166208
### 加強政策和教育
167209

168210
#### 制定資安政策(Policy Development)

docs/chapter/files_management/policy.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
---
2-
icon: material/book-check
2+
icon: material/folder-open
33
title: 資料管理與備份政策規範
44
---
55

0 commit comments

Comments
 (0)