Aris Kusnandar
Program Studi Teknik Geodesi dan Geomatika, Institut Teknologi Bandung Jln. Ganesha 10, Bandung

Published : 4 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 2 Documents
Search
Journal : JURNAL SISTEM INFORMASI BISNIS

Pengukuran Tingkat Risiko dan Keamanan Informasi Menggunakan Metode FMEA Berbasis ISO/IEC 27001 pada Instansi XYZ untuk Keamanan Sistem Informasi Kusnandar, Aris; Rochim, Adian Fatchur; Gunawan, Vincensius
Jurnal Sistem Informasi Bisnis Vol 14, No 4 (2024): Volume 14 Nomor 4 Tahun 2024
Publisher : Diponegoro University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.21456/vol14iss4pp375-384

Abstract

The more information stored in an organization, the higher the risks that may arise, such as damage, loss, or the exposure of personal information to irresponsible parties. XYZ Institution faces information security threats from various sources, including data theft, damage, and computer hacking. It is essential for the organization to understand the level of information security risk to ensure information remains secure. Therefore, this study proposes measuring information security risk using the FMEA method and analyzing information security risks based on ISO/IEC 27001:2013. The aim of this study is to identify and assess the level of information security risk at XYZ Institution to provide recommendations for information security. The study's results revealed 4 high-risk information security threats, 9 medium-risk threats, and 16 low-risk threats. The findings demonstrate that the organization needs to pay more attention to information security to ensure its smooth operation in the future.
Evaluasi Keamanan Sistem Informasi Menggunakan Fuzzy FMEA Berbasis Framework ISO/IEC 27001:2013 untuk Meningkatkan Keamanan Informasi Kusnandar, Aris
Jurnal Sistem Informasi Bisnis Vol 14, No 2 (2024): Volume 14 Nomor 2 Tahun 2024
Publisher : Diponegoro University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.21456/vol14iss2pp181-190

Abstract

Very few organizations are not aware of the importance of information security, even though information security is important to the running of an organization. Dinas Kependudukan XYZ faces a number of information security threats from various sources. Every security threat such as information theft, fraud, vandalism, and computer hacking will affect the organization. This research uses the ISO/IEC 27001:2013 framework as a method for. analyze risks. The risk value calculation uses the FMEA method which is integrated with the fuzzy method to determine the risk level of information security threats based on ISO/IEC 27001:2013. The research results are in the form of a risk processing report containing a list of risk priorities and control plans according to the ISO/IEC 27001:2013 standard. The information security risk priorities obtained in this research were 13 very high priority and 10 high priority. This proves that the organization has not complied with standard security/information procedures so it needs to document security policies based on ISO/IEC 27001:2013 to provide a sense of security and increase trust in the public.