Claim Missing Document
Check
Articles

Found 1 Documents
Search

Evaluasi Keamanan Informasi pada Dinas Komunikasi dan Informatika Kabupaten Sidoarjo menggunakan Indeks Keamanan Informasi (KAMI) Nofry Arman; Widhy Hayuhardhika Nugraha Putra; Aditya Rachmadi
Jurnal Pengembangan Teknologi Informasi dan Ilmu Komputer Vol 3 No 6 (2019): Juni 2019
Publisher : Fakultas Ilmu Komputer (FILKOM), Universitas Brawijaya

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (398.373 KB)

Abstract

The Communication and Information Agency (KOMINFO) of Sidoarjo Regency is a government service located in Sidoarjo Regency, which is engaged in communication and informatics and provides public services by utilizing information technology. Related to the importance of information security, the Ministry of Communication and Information issued the Republic of Indonesia Minister of Communication and Information Minister Regulation Number 4 of 2016 concerning Information Security Management System to support the implementation of information security management systems in government agencies, therefore as a service that provides information and uses information technology in its services, an evaluation of the level of information security is needed. In this study the evaluation was conducted with a questionnaire instrument based on Indeks Keamanan Informasi (KAMI) to determine the level of completeness and maturity of information security in five areas, governance, risk management, frameworks, asset management, and technology. From the results of the evaluation it can be seen that at the completeness level get a score of 334 and the average level of information security maturity is at level II. From this, it can be stated that the Sidoarjo Regency Communication and Information Agency needs improvement to carry out ISO27001 certification. These results form the basis of making recommendations obtained from the results of a comparison between Indeks KAMI and ISO27001 controls. One recommendation given is the risk management procedure for non-compliance corrective actions based on control A.18.2.