Claim Missing Document
Check
Articles

Found 35 Documents
Search

PERBANDINGAN APRIORI DAN FP-GROWTH DALAM PEMBUATAN ATURAN ASOSIASI PEMBELIAN PRODUK BAKERY BERBASIS CRISP-DM Vivian Vivian; Jek Siang Jong; Halim Budi Santoso
INTECOMS: Journal of Information Technology and Computer Science Vol. 9 No. 2 (2026): INTECOMS: Journal of Information Technology and Computer Science
Publisher : Institut Penelitian Matematika, Komputer, Keperawatan, Pendidikan dan Ekonomi (IPM2KPE)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.31539/qdvqa169

Abstract

Penelitian ini membandingkan performa algoritma Apriori dan FP-Growth dalam mengekstraksi aturan asosiasi dari dataset transaksi penjualan bakery dari Kaggle yang terdiri atas 2.654 transaksi dan 23 jenis produk. Perbandingan meliputi jumlah frequent itemset, jumlah aturan asosiasi, nilai rata-rata support, confidence, dan lift, serta waktu eksekusi algoritma. Seluruh proses analisis dilakukan menggunakan perangkat lunak Python dengan pustaka pandas dan mlxtend pada lingkungan komputasi yang identik. Data diproses menggunakan one-hot encoding dan dianalisis dengan parameter minimum support sebesar 5% dan minimum confidence sebesar 50%. Hasil percobaan menunjukkan bahwa kedua algoritma menghasilkan 43 frequent itemset dan 18 aturan asosiasi yang identik, dengan rata-rata support sebesar 0.1319, rata-rata confidence sebesar 0.7454, dan rata-rata lift sebesar 1.0876. Waktu eksekusi Apriori tercatat sekitar 0.00379 detik, sedangkan FP-Growth sekitar 0.00397 detik. Temuan ini menunjukkan bahwa pada dataset yang dianalisis, kedua algoritma memiliki kinerja yang setara dalam kualitas aturan asosiasi, dengan perbedaan waktu eksekusi yang relatif kecil Kata Kunci: CRISP-DM, Market Basket Analysis, Apriori, FP-Growth, Aturan Asosiasi, Bakery
PERANCANGAN APPLIKASI BERGERAK TRASHSURE DENGAN DESIGN THINKING SEBAGAI SOLUSI PERMASALAHAN SAMPAH BERBASIS KOMUNITAS Halim Budi Santoso; Jong Jek Siang; Josephine Vania Soerjanto
Jurnal Pendidikan Teknologi Informasi (JUKANTI) Vol 7 No 2 (2024): JURNAL PENDIDIKAN TEKNOLOGI INFORMASI (JUKANTI) EDISI NOPEMBER 2024
Publisher : Universitas Citra Bangsa

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.37792/jukanti.v7i2.1373

Abstract

Waste from meetings and gatherings is often just thrown away and collected by garbage collectors. This garbage has economic value for the surrounding community as an additional income. However, collecting this kind of garbage requires communication media that can help to connect the owners and the garbage collectors. To understand the underlying mechanisms in creating good communication media, this study utilizes a design thinking method to design TrashSure, a community-based mobile application without financial transactions and less profit-oriented. The TrashSure application was designed by analyzing the interview data of 10 people for each actor type: garbage collector and garbage owner. We received some feature recommendations to advance the communication channels, such as trash ownership and supporting data, such as time, type, volume, and location. In addition, the rating feature is essential to understand the credibility of the garbage collectors. Then, we evaluate the usability using the System Usability Scale (SUS) with ten respondents. The result shows a fairly good predicate with a score of 75.25.
Internal Compliance Audit of the Information Security Management System in a Cybersecurity Company based on ISO/IEC 27001 Sterevania Rambu Muna; Halim Budi Santoso; Jong Jek Siang
SISTEMASI Vol 15, No 6 (2026): Sistemasi: Jurnal Sistem Informasi
Publisher : Universitas Islam Indragiri

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.32520/stmsi.v15i6.6471

Abstract

Information Security Management Systems (ISMSs) require periodic evaluation to assess their level of compliance with established standards and frameworks. This study evaluates the implementation of an Information Security Management System in an Indonesian cybersecurity services company, with a particular focus on the Compliance Division and the Security Operations Center (SOC). The case study was selected because the organization's ISMS had not been implemented consistently, particularly regarding the regular updating of security policies and operational procedures. As a cybersecurity service provider, the company is expected to conduct periodic compliance assessments to ensure alignment with recognized information security management standards, such as ISO/IEC 27001:2022. The study employed a Gap Analysis approach that combined qualitative and quantitative data. Data were collected through direct observation and a review of internal documentation after obtaining the company's authorization. The results indicate an overall compliance level of 77.5%. Three control areas achieved full compliance: the timely execution of internal audits, incident documentation, and log management. Based on the identified gaps, a set of improvement recommendations was developed to assist the organization in achieving greater compliance with the requirements of ISO/IEC 27001:2022. This study provides practical contributions by demonstrating the application of the ISO/IEC 27001:2022 framework for conducting internal compliance audits of Information Security Management Systems and offering actionable recommendations for strengthening organizational information security governance.
Analisis Kepatuhan ISO 27001 Annex A pada Perusahaan Keamanan Siber Adelia Cristyana Dewanti; Halim Budi Santoso; Jong Jek Siang
Jutisi : Jurnal Ilmiah Teknik Informatika dan Sistem Informasi Vol 15, No 3 (2026): Juni 2026
Publisher : STMIK Banjarbaru

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.35889/jutisi.v15i3.3696

Abstract

Information Security Management System  is an important aspect for cybersecurity companies in maintaining the confidentiality, integrity, and availability of information. This study evaluates the implementation of ISO 27001:2022 Annex A controls in the Compliance and IT Security divisions of a cybersecurity company using the Gap Analysis method. The evaluation covered 12 controls clusters, including security policies, compliance audits, access management, incident handling, and third party management through observation, semi structured interviews, and document analysis. Assessment results showed an actual score of 33 out of 48, indicating a compliance level of 68.75% categorized as compliant. Technical controls had generally been implemented well. However, gaps remained in compliance audits, third party management, security documentation, and employee security awareness. Recommendations include documentation standardization, stronger compliance monitoring, periodic evaluations, and formal incident handling procedures to improve ISMS implementation continuously.Keywords: ISO 27001:2022; Annex A; Gap Analysis; Compliance; Information Security. AbstrakSistem Manajemen Keamanan Informasi menjadi aspek penting bagi perusahaan keamanan siber dalam menjaga kerahasiaan, integritas, dan ketersediaan informasi. Penelitian ini mengevaluasi implementasi kontrol ISO 27001:2022 Annex A pada divisi Compliance dan IT Security menggunakan metode Gap Analysis. Evaluasi dilakukan terhadap 12 cluster kontrol keamanan informasi melalui observasi, wawancara semi terstruktur, dan analisis dokumen perusahaan. Hasil penilaian menunjukkan skor aktual sebesar 33 dari skor maksimal 48 dengan tingkat kepatuhan 68,75% yang termasuk kategori patuh. Implementasi kontrol pada aspek teknis telah berjalan cukup baik, namun masih ditemukan kesenjangan pada audit kepatuhan, pengelolaan pihak ketiga, dokumentasi keamanan informasi, dan kesadaran keamanan SDM. Rekomendasi yang diusulkan meliputi standarisasi dokumentasi, penguatan pemantauan kepatuhan, evaluasi berkala, dan penyusunan prosedur formal penanganan insiden guna meningkatkan implementasi SMKI secara berkelanjutan. 
Integrating the NIST 800-30 Risk Management Framework with Penetration Testing: A Case Study of Web-Based Training Information Systems in a Cybersecurity Company Yohanes Dewantara Marpaung; Halim Budi Santoso; Erick Kurniawan; Gabriel Indra Widi Tamtama; Abdul Karim
Indonesian Journal of Information Systems Vol. 9 No. 1 (2026): August 2026
Publisher : Program Studi Sistem Informasi Universitas Atma Jaya Yogyakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24002/ijis.v9i1.14877

Abstract

Web application security has become a paramount concern due to the escalating frequency of cyber threats targeting internet-based information systems. Web developers must prioritize risk management, with a particular emphasis on integrating risk identification within the information security management system. Companies specializing in information security management must exercise caution when deploying web-based applications, as information security is a critical issue that can substantially affect a company's reputation. However, previous research has frequently failed to address this issue comprehensively. Consequently, this study seeks to investigate the integration of a risk management framework with penetration testing. The amalgamation of penetration testing with NIST SP 800-30 is expected to provide a comprehensive risk assessment. The penetration testing was conducted using a grey-box testing methodology, guided by OWASP WSTG v4.2 and augmented by CVSS v3.1 for severity measurement. Subsequently, NIST SP 800-30 was employed as the risk management framework. The grey-box testing was performed on a recently deployed web-based training management system. As a result, four vulnerabilities were identified and verified through Proof of Concept: SQL Injection (High), Blind Stores XSS (Critical), Unrestricted file upload enabling remote code execution (Critical), and Brute Force Attack (High). A comprehensive risk identification and mitigation process was then conducted for these vulnerabilities. This study also provides improvement suggestions to aid in mitigating the identified vulnerabilities. This research introduces a novel approach by integrating penetration testing with risk management frameworks to enhance the effectiveness of risk management in web-based applications