Kevin Alexander Yech
Universitas Katolik Musi Charitas

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Analisis Manajemen Risiko Sistem Informasi Menggunakan Standar ISO 31000:2018 pada PT WleoWleo Michael Imanuel; Kevin Alexander Yech; Sri Andayani
Jurnal Tata Kelola dan Kerangka Kerja Teknologi Informasi Vol. 12 No. 2 (2026): Agustus 2026
Publisher : Universitas Komputer Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.34010/jtk3ti.v12i2.20269

Abstract

PT ABC is a property developer that relies heavily on the utilization of information technology in its operations. This dependency creates system vulnerabilities that could potentially disrupt business continuity. This study aims to analyze and evaluate information systems risk management at the company by applying the ISO 31000:2018 framework. The research stages include defining the scope, identifying assets and risks, analyzing likelihood and impact, evaluating risk levels, and determining treatment strategies. The results mapped 21 possible risk threats originating from hardware, software, data, and user factors. The risk matrix evaluation indicates that the most critical threats are at a very high level, such as power outages, cyberattacks, and data backup failures. To address these vulnerabilities, risk treatments are formulated with a dominance of mitigation actions, followed by risk avoidance, acceptance, and sharing. This research contributes as a strategic recommendation guide for company leaders to minimize risks and enhance the security of their information asset governance.