Claim Missing Document
Check
Articles

Found 1 Documents
Search

Perencanaan Pengelolaan Keamanan Informasi Berbasis ISO 27001 menggunakan Indeks KAMI Studi Kasus: Dinas Komunikasi dan Informatika Kabupaten Rembang Anindhita Firdani; Suprapto Suprapto; Andi Reza Perdanakusuma
Jurnal Pengembangan Teknologi Informasi dan Ilmu Komputer Vol 3 No 6 (2019): Juni 2019
Publisher : Fakultas Ilmu Komputer (FILKOM), Universitas Brawijaya

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (338.443 KB)

Abstract

Dinas Komunikasi dan Informatika (Kominfo) Kabupaten Rembang is a government service that implements IT in carrying out business processes and daily activities. Dinas Kominfo use various IT services and have the responsibility to manage some of services technically. Based on the interviews that have been done, the more services managed by Dinas Kominfo, the more appropriate safeguards are needed to avoid the risks that might occur. According the existing conditions and referring to Peraturan Menteri Komunikasi dan Informatika Republik Indonesia Nomor 4 Tahun 2016, Dinas Kominfo need to plan for managing information security. Therefore, the purpose of this research is to provide a information security management plan based on risk analysis in Dinas Kominfo Kabupaten Rembang. Planning for information security management that conduct through steps includes assessments using Information Security (KAMI) Index, asset and risk identification, risk analysis using FMEA, risk priorities, make appropriate recomendations to ISO 27001 controls, cost and benefit analysis to determine risk mitigation priorities, and arrange ISO 27001 mandatory document. From the Indeks KAMI assessmen result, the completeness levels score is 161 and the average maturity level of each information security areas is Level I to Level I+. Then, there are 15 top IT risk with the highest RPN value 126. Risk mitigation recommendations can be applied by doing 13 ISO 27001 controls based on risk analysis.