2Viewes
Analisis Risiko Keamanan Informasi Berbasis ISO/IEC27001:2022 pada Pusat Kegiatan Belajar Masyarakat (PKBM) XYZ
Repository Analytics
Statistic Details
0Downloaded
2Accessed per month
1Countries
Loading...
Date
Authors
Fathimah, Nabilah
Journal Title
Journal ISSN
Volume Title
Publisher
Politeknik Negeri Batam
Abstract
PKBM XYZ utilizes various information technology assets to support its operational activities and educational services, including data, hardware, software, computer networks, and human resources. These resources face possible threats that could influence the confidentiality, integrity, and accessibility of data. Therefore, information security risk analysis is required as the basis for effective information security management. The aim of this research is to analyze the risks to information security at PKBM XYZ by utilizing the Risk Assessment approach aligned with the ISO/IEC 27001:2022 standard. The analysis was conducted through the identification of assets, threats, and vulnerabilities, followed by risk assessment and evaluation based on the likelihood of threats and their potential impact on the organization. Information was gathered via observations, interviews, and documentation to gain insights into the information technology resources and the present condition of information security related to this area of investigation. The results indicate that the administrator's laptop and router have the highest risk values, primarily due to inadequate physical protection and maintenance of hardware assets, while web hosting services and other network assets show relatively lower risk levels. Based on the risk evaluation results, information security control recommendations were developed in accordance with ISO/IEC 27001:2022 to support risk mitigation and enhance information security. The results from this research are anticipated to provide guidance for PKBM XYZ in enhancing its information security management in a more efficient manner.
Description
Penelitian ini menganalisis risiko keamanan informasi pada PKBM XYZ menggunakan pendekatan Risk Assessment berbasis ISO/IEC 27001:2022. Hasil penelitian berupa identifikasi aset, ancaman, kerentanan, tingkat risiko, serta rekomendasi kontrol keamanan untuk mendukung pengelolaan keamanan informasi yang lebih baik.
Citation
IEEE
