Claim Missing Document
Check
Articles

Found 1 Documents
Search
Journal : Jurnal Computer Science and Information Technology (CoSciTech)

Penilaian risiko keamanan siber kampus menggunakan framework cybersecurity NIST 1.1 Handoyo, Eko; Izza Eka Nigrum
Computer Science and Information Technology Vol 4 No 3 (2023): Jurnal Computer Science and Information Technology (CoSciTech)
Publisher : Universitas Muhammadiyah Riau

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.37859/coscitech.v4i3.5628

Abstract

The Industrial Revolution 4.0 forced institutions and companies to start improving the implementation of information technology to be able to compete well.The campus is one of the most massive sectors in the development and implementation of information technology.Because there are so many services and business processes that exist in the campus system.Campus business systems that are complex and have a lot of data in the information certainly pose a threat in the information technology security sector.Technological security must of course guarantee its confidentiality, integrity and availability. Countermeasures related to cybersecurity threats can be carried out by conducting a cyber security risk assessment.Standards for conducting cyber security assessments include COBIT 5, NIST, and ISO 20071. Each standard has audit modules that aim to make the institution a good government.NIST Cybersecurity Framework 1.1 is a standard used to direct organizations to cybersecurity activities and consider cybersecurity risks as part of their management process. The purpose of this study is to produce an assessment of campus cybersecurity risks using the NIST cybersecurity framework 1.1 as a standard reference.The overall result of the research, which is to produce, is the ranking of campus cyber risk assessments.The assessment of campus cyber security risks resulted in a value of 1.20, placing the campus institution in a "Partially Implemented" cybersecurity condition.Where campuses only carry out control on the framework as necessary and have not been documented, and so it needs to be improved regarding proper control and documentation to improve better cyber security.