Ayunda Della Ariesta
Fakultas Ilmu Komputer, Universitas Brawijaya

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Evaluasi Tata Kelola dan Manajemen Risiko Teknologi Informasi pada PT. MyECO Teknologi Nusantara menggunakan Framework COBIT 2019 Proses EDM03 dan APO12 Ayunda Della Ariesta; Suprapto Suprapto; Andi Reza Perdanakusuma
Jurnal Pengembangan Teknologi Informasi dan Ilmu Komputer Vol 6 No 12 (2022): Desember 2022
Publisher : Fakultas Ilmu Komputer (FILKOM), Universitas Brawijaya

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

PT. MyECO Teknologi Nusantara is a startup company that focuses on electricity-saving smarthome technology solutions. It has a product, namely an IoT-based automatic electricity-saving device. In supporting the quality of the company's products, MyECO has a smarthome application, namely the "myECO" application which functions to control electrical devices in the house from anywhere and at any time. The "myECO" application is expected to support the company's business processes. However, IT implementation is not always in accordance with the expected conditions because it can create risks. Regarding IT risk management, PT. MyECO Teknologi Nusantara has not implemented a specific mechanism to deal with IT risks that will arise when these risks have not been managed properly, it is necessary to conduct an assessment of IT risk management at PT. MyECO Teknologi Nusantara uses the COBIT 2019 framework. The framework used focuses on the EDM03 and APO12 processes. The research aims to assess the level of capability, gaps, and provide recommendations for the company. Data collection was obtained through interviews, questionnaire assessment sheets and observation. Respondents in this study were CEOs and CTOs who were determined using the RACI Chart. The results of the assessment show the capability level achieved by PT. MyECO Teknologi Nusantara is level 1 for EDM03 and APO12 processes. The recommendations focus on preparing documents that contain risk profiles, risk appetite, risk tolerance, corrective steps, risk grouping and the implementation of regular IT risk management evaluation activities in the company.