KRESNA MEDIAKRESNA MEDIA

Jurnal Riset InformatikaJurnal Riset Informatika

The advancement of information technology (IT) provides significant benefits for organizational operations, including the Department of Communication and Informatics (Diskominfo) of Tabanan Regency. However, IT implementation also brings security risks, such as hacking and cyberattacks, which can threaten the continuity of public services. This study aims to implement risk management based on ISO/IEC 27005:2022 to protect the IT assets owned by Diskominfo Tabanan Regency. The stages carried out include context establishment, risk identification, risk analysis, risk evaluation, and recommendations. In the risk identification stage, 28 IT assets, 57 threats, existing controls for each asset, vulnerabilities of these controls, and potential consequences were identified. In the risk analysis stage, eight respondents were asked to complete a questionnaire to assess the impact of threats and the likelihood of their occurrence, with the average impact and likelihood scores being 3 and 4, respectively. Based on the questionnaire results, the study will proceed with risk level assessment to determine risk levels based on the previous analysis. Subsequently, a risk evaluation will be conducted to provide recommendations for effective mitigation measures. This IT risk analysis study resulted in mitigation recommendations for threats that could potentially impact Diskominfo Tabanan Regency IT assets. The recommendations were developed based on the severity level of each risk after analysis, referring to common practices in both public and private sectors, as well as sources such as research journals, relevant literature, and the ISO/IEC 27005 standard.

2022 at Diskominfo Tabanan revealed numerous risks to the organizations critical IT assets.Risk levels ranged from moderate to very high, especially for threats related to infrastructure failures and cyberattacks.Despite the presence of some controls, many assets were still vulnerable due to outdated systems or insufficient policies.The study identified the most significant risks and provided tailored recommendations to improve resilience, particularly for server operations, infrastructure, and human resource readiness.

Based on the findings, future research could focus on expanding the scope of risk analysis to include more assets, divisions, or activities within Diskominfo Tabanan. Integrating other frameworks like NIST SP 800-30 or OCTAVE could enhance the depth and breadth of future risk analyses. Additionally, ongoing risk reviews, threat awareness, and training for staff should be conducted to strengthen collective responsibility for IT asset security. These recommendations can serve as a basis for assessing the effectiveness of ISO 27005-based risk management in future studies.

  1. Implementasi Teknologi Biometrical Identification untuk Login Hotspot | Jurnal Pustaka Robot Sister (Jurnal... doi.org/10.55382/jurnalpustakarobotsister.v1i1.358Implementasi Teknologi Biometrical Identification untuk Login Hotspot Jurnal Pustaka Robot Sister Jurnal doi 10 55382 jurnalpustakarobotsister v1i1 358
  2. ANALISIS MANAJEMEN RISIKO INFORMASI MENGGUNAKAN ISO/IEC 27005:2018 (STUDI KASUS: PT.XYZ) | Hikam | JIPI... jurnal.stkippgritulungagung.ac.id/index.php/jipi/article/view/4709ANALISIS MANAJEMEN RISIKO INFORMASI MENGGUNAKAN ISO IEC 27005 2018 STUDI KASUS PT XYZ Hikam JIPI jurnal stkippgritulungagung ac index php jipi article view 4709
  3. Information Technology Risk Analysis Using ISO 27005:2022 At Diskominfo Tabanan Regency | Jurnal Riset... ejournal.kresnamediapublisher.com/index.php/jri/article/view/394Information Technology Risk Analysis Using ISO 27005 2022 At Diskominfo Tabanan Regency Jurnal Riset ejournal kresnamediapublisher index php jri article view 394
Read online
File size382.9 KB
Pages10
DMCAReport

Related /

ads-block-test