Kurniawan, Andys Sandra
Unknown Affiliation

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Security Risk Management Assessment in Information Technology Services using Information Technology Infrastructure Library (ITIL) V4 Kurniawan, Andys Sandra; Widodo, Aris Puji; Wibowo, Adi
Jurnal Sistem Informasi Bisnis Vol 15, No 4 (2025): Volume 15 Number 4 Year 2025 (In Press)
Publisher : Diponegoro University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.14710/vol15iss4pp469-472

Abstract

Information Technology (IT) is currently implemented in various fields of life, including in higher education. Some common IT-based service problems such as server down, slow systems, poor integration, and data security are important concerns for education managers. IT Service Management or Information Technology Service Management (ITSM) is a strategic approach to designing, providing, managing, and improving the way IT is used in an organization. ITIL is one of the most popular ITSM frameworks and includes a framework for evaluation and assessment. This study proposes the use of ITIL V4 to assess the level of maturity of security risk management in the higher education sector, which has not been widely explored. This study aims to measure and analyze the level of capability and assess the maturity of IT services, especially in risk management practices and information security management and analyze the level of gap between actual conditions that occur and expected standards. The results of the study indicate that the assessment of the level of maturity of higher education in managing IT service security risks, especially in both management practices, is at level 3 (Defined). These results indicate that universities have begun to realize the importance of IT security risk management, where practices are well defined, processes and activities are documented and standardized. To achieve continuous improvement according to the ITIL V4 standard, it is necessary to increase the capacity of the technology used, consistency in evaluation, and build an organizational culture that supports continuous risk management.