Cilacap Regional General Hospital has been using the SIMRS system since 2006 to the present day. however, its use has encountered several challenges, such as human error, lengthy data synchronisation processes and time-consuming application maintenance. Previous studies have analyzed risk assessments regarding application usage, yet there is a gap in the implementation of risk mitigation. The aim of the research is to carry out a risk assessment of the SIMRS using the OCTAVE Allegro method and to propose risk mitigation measures in accordance with ISO/IEC 27001. The novelty of this research lies in the combination of methods used to conduct risk assessment and mitigation utilising the ISO/IEC 27001:2022 control standards. Results of research identify the areas of impact, reputation, finance and productivity. The areas of concern are human error, hardware management and software management. Scenarios were developed based on these areas of concern; according to the calculations, the score for human error was 31, for hardware management 24 and for software management 18. Mitigation, as set out in ISO/IEC 27001:2022, focuses on organisational controls in clauses 5.1, 5.15, 5.24, 5.26, 5.28, 5.33, 5.37. People controls in clauses 6.2, 6.3, 6.5, 6.8. Physical controls in clauses 7.5, 7.7, 7.10, 7.12, 7.13. Technological controls in clauses 8.2, 8.5, 8.7, 8.12, 8.13, 8.20, 8.22, 8.32. The scientific contribution lies in the integration of the OCTAVE Allegro and ISO/IEC 27001:2022 approaches to produce a risk assessment process that is not only capable of identifying and prioritising risks, but also directly provides relevant security controls.