Claim Missing Document
Check
Articles

Found 1 Documents
Search

Analisis Manajemen Risiko Teknologi Informasi pada Dinas Kominfo Sumatera Selatan Berdasarkan Iso 31000:2018 Aloisius Egi Sanjaya; Muhammad Raka Nur Habibi; Sri Andayani
Jurnal Pendidikan, Sains Dan Teknologi Vol. 5 No. 3 (2026): Juli-September
Publisher : CV. ITTC INDONESIA

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47233/jpst.v5i3.4873

Abstract

This study evaluates the potential risks of information systems and technology at the Office of Communication and Informatics (KOMINFO) of South Sumatra Province. The primary issues faced by the agency include power supply disruptions causing server downtime, unstable internet connections, high data loss risks due to system updates without adequate backups, and cybersecurity threats in the form of regional government (OPD) website defacement leading to online gambling content. This study aims to systematically map IS/IT risks, conduct risk assessments, and provide comprehensive mitigation recommendations tailored to the local government's operational conditions.The method used is a descriptive approach with a mixed-methods design, involving direct observation, in-depth interviews with IT staff, and questionnaires. The data analysis technique is fully based on the ISO 31000:2018 framework, which includes risk identification, risk analysis by measuring the likelihood and impact using a 1-5 Likert scale, and risk evaluation through a 5x5 risk matrix. The results identified 11 primary risks in the categories of physical environment, system infrastructure, cybersecurity, and human aspects. All risks were proven to be at the medium level, with the highest handling priorities on power outages (R01), internet disruptions (R03), and inconsistent changes in leadership requirements (R09). No high-level risks were found. Mitigation recommendations are focused on strengthening backup power (UPS/generators), optimizing redundant internet, implementing daily backup procedures, and standardizing the change control mechanism.