RADEN FATAHRADEN FATAH

TADWIN: Jurnal Ilmu Perpustakaan dan InformasiTADWIN: Jurnal Ilmu Perpustakaan dan Informasi

As the utilization of digital systems continues to grow, libraries must strengthen their information management systems to protect against threats such as cyberattacks and data breaches. This study employed a descriptive qualitative approach using observation, interviews, and documentation. The findings indicate that several ISO/IEC 27001 based controls have been implemented, including firewalls, encryption, and regular audits. However, security gaps remain, such as weak credentials, the absence of multi-factor authentication, and limited real-time monitoring and data backup. Major risks include malware, network attacks, and system failures. Although the National University (UNAS) Cyber Library has developed a Disaster Recovery Plan (DRP), formal documentation and user digital literacy are still needed. These findings serve as a strategic evaluation basis for enhancing the effectiveness of information security governance in academic library environments.

The UNAS Library has implemented several ISO/IEC 27001-based controls to enhance information security, but a comprehensive governance structure is still lacking.Strengthening information security requires formalizing policies, establishing a dedicated information security unit, and integrating risk assessments into strategic planning.Continuous improvement through regular audits, staff training, and user awareness programs is crucial for maintaining a resilient and secure information ecosystem.

Berdasarkan hasil penelitian, terdapat beberapa saran penelitian lanjutan yang dapat dilakukan untuk memperdalam pemahaman mengenai implementasi dan efektivitas manajemen keamanan informasi di perpustakaan. Pertama, penelitian dapat difokuskan pada pengembangan model pengukuran maturitas keamanan informasi yang spesifik untuk konteks perpustakaan akademik di Indonesia, mempertimbangkan tantangan unik yang dihadapi oleh perpustakaan dalam mengelola aset informasi digital dan fisik. Kedua, studi komparatif dapat dilakukan dengan membandingkan implementasi ISO/IEC 27001 di beberapa perpustakaan universitas di Indonesia untuk mengidentifikasi praktik terbaik dan hambatan umum yang dihadapi. Ketiga, penelitian dapat mengeksplorasi efektivitas berbagai metode pelatihan dan peningkatan kesadaran keamanan informasi bagi pengguna perpustakaan, termasuk penggunaan simulasi serangan phishing dan lokakarya interaktif, untuk meningkatkan perilaku keamanan pengguna dan mengurangi risiko pelanggaran data. Penelitian-penelitian ini diharapkan dapat memberikan kontribusi signifikan dalam meningkatkan keamanan informasi dan melindungi aset berharga yang dikelola oleh perpustakaan di lingkungan akademik.

  1. Evaluation of Information Security Management Based on ISO/IEC 27001 at Universitas Nasional Library... jurnal.radenfatah.ac.id/index.php/tadwin/article/view/29814Evaluation of Information Security Management Based on ISO IEC 27001 at Universitas Nasional Library jurnal radenfatah ac index php tadwin article view 29814
  2. 0. pdf obj endstream endobj stu lmm uf tvbp h8j ach us pg s4 journals.sagepub.com/doi/pdf/10.1177/096100062211270270 pdf obj endstream endobj stu lmm uf tvbp h8j ach us pg s4 journals sagepub doi pdf 10 1177 09610006221127027
  3. 0. pdf obj endstream endobj stu lmm uf tvbp h8j ach us pg s4 onlinelibrary.wiley.com/doi/pdfdirect/10.1002/joom.12150 pdf obj endstream endobj stu lmm uf tvbp h8j ach us pg s4 onlinelibrary wiley doi pdfdirect 10 1002 joom 1215
Read online
File size871.98 KB
Pages13
DMCAReport

Related /

ads-block-test