The One Data application at XYZ Agency is a strategic data portal that supports bureaucratic reform and civil service governance. The high strategic value of the managed data has implications for increasing information security risks. This study aims to design information security risk management in the One Data Application at XYZ Agency by referring to SNI ISO/IEC 27005:2022, prioritizing risk treatment, and validating the design through control alignment with the IKASANDI guidelines. The research methods include inventorying application-related assets, identifying threats and vulnerabilities, formulating risk scenarios, and analyzing and evaluating risks using consequence-likelihood criteria and a 5x5 risk matrix referring to PermenPANRB Number 43 of 2021. The design results produce a risk register covering 30 assets, 21 types of threats, and 61 risk scenarios, consisting of 33 risks requiring mitigation and 28 risks in the acceptable category. High-priority risks primarily relate to service availability, dependence on supporting infrastructure, and human factors, including potential insider threats and limited personnel availability. The risk treatment recommendations are mapped against SNI ISO/IEC 27002:2022 controls and aligned with IKASANDI controls; design validation is demonstrated by an increase in the IKASANDI score from 1,65 to 2,24. The proposed risk treatment plan also targets a decrease in the average risk score from 12,07 to 6,31, placing all scenarios in the acceptance category. The study concludes that the implementation of SNI ISO/IEC 27005:2022, validated through an increase in the IKASANDI score, results in a structured risk management design, and supports continuous monitoring and improvement of the information security management system in the XYZ Agency's One Data Application.