This Author published in this journals
All Journal OPSI
I Wayan Agus Arimbawa
Informatics Department, Universitas Mataram, Nusa Tenggara Barat 83116, Indonesia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

From standards to practice: Applying ISO/IEC 27005:2022 for information security risk management in regional water company Andi Hary Akbar; Heri Wijayanto; I Wayan Agus Arimbawa; Riza Prapascatama Agusdin; Andika Rifai; Athaya Rizqia Fitriani
OPSI Vol 19 No 1 (2026): OPSI - June 2026
Publisher : Jurusan Teknik Industri, Fakultas Teknologi Industri UPN "Veteran" Yogyakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.31315/opsi.v19i1.15917

Abstract

Regional water companies have increasingly adopted information technology to support their operations. However, the absence of formalized information security risk management procedures can lead to substantial operational disruptions and financial losses. Therefore, this study aims to conduct a systematic risk assessment of a regional water company based on its IT assets, utilizing the ISO/IEC 27005:2022 standard. Data collection through semi-structured interviews and questionnaires with the company's IT department identified 31 assets, which were subsequently used for risk mapping and assessment. The assessment identified a total of 265 risk scenarios, categorized into 10 High (3.77%), 68 Medium (25.66%), and 187 Low (70.57%) level risks. Following the evaluation where all risks were deemed unacceptable, risk modification was recommended as treatment for all risk scenarios. Based on the results of the risk assessment, control recommendations were developed according to ISO/IEC 27001:2022 to assist the company in managing and mitigating risks. The implementation of the two ISO standards aligns to comprehensively map risks and provide a structured mitigation plan. These results are expected to assist the company in establishing formal risk management procedures and maintain business process continuity and effectiveness.