Firza Zukhriadna Afriliandra
Fakultas Ilmu Komputer, Universitas Brawijaya

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Evaluasi Tata Kelola Manajemen Risiko Teknologi Informasi pada PT XYZ menggunakan Kerangka Kerja COBIT 2019 Firza Zukhriadna Afriliandra; Suprapto Suprapto; Andi Reza Perdanakusuma
Jurnal Pengembangan Teknologi Informasi dan Ilmu Komputer Vol 6 No 12 (2022): Desember 2022
Publisher : Fakultas Ilmu Komputer (FILKOM), Universitas Brawijaya

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

PT XYZ is an IT-based company in Malang City that provides services as a solution to client problems. As a service provider, companies need to manage IT risk management well because there is a possibility of IT risk occurring from the client's system being developed. To maintain service quality, the company implements the Sentry.io service to assist developers in monitoring the system so that errors that occur can be corrected immediately. But sometimes there are still problems or obstacles in its application. Currently the company has not documented identified IT risks, this needs to be done in order to determine IT risk scenarios to prevent the risk from reoccurring. The tight performance of activities within the company means that IT risk management activities need to be optimized so as not to affect the running of business processes. This study aims to identify the capability level related to the condition of managing IT risk management in companies. After evaluation, recommendations for improvement based on gap analysis were obtained. The research focused on the EDM03 and APO12 processes of the 2019 COBIT framework. The data used in the study were collected through interviews, distributing questionnaires, and observation. Based on the results of data analysis, the capability level achieved by PT XYZ is at level 1 in the EDM03 and APO12 processes. Provision of recommendations focuses on activities that can help improve the implementation of information technology risk management at PT XYZ.