Claim Missing Document
Check
Articles

Found 1 Documents
Search

Information System Audit Based on ISO/IEC 27001: A Case Study of a Culinary Small and Medium Enterprise Mira Agustina; Andini Syahputri; Rizky Natasya; Neng Sri Wardhani
Proceedings of The International Conference on Computer Science, Engineering, Social Science, and Multi-Disciplinary Studies Vol. 1 (2025)
Publisher : CV Raskha Media Group

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.64803/cessmuds.v1.93

Abstract

Small and Medium Enterprises (SMEs) increasingly rely on information systems to support operational efficiency, customer management, and financial transactions. However, limited awareness and resources often cause SMEs to neglect information security governance, exposing them to data breaches and operational risks (ENISA, 2021). This study aims to evaluate the effectiveness of information security controls in a culinary SME using the ISO/IEC 27001 framework. A qualitative case study approach was employed, involving document analysis, interviews, and observation of information system practices within the organization (Yin, 2018). The audit results reveal several gaps in information security implementation, particularly in access control, risk assessment, and incident management. These findings indicate that although basic controls are in place, the SME has not yet aligned its practices with ISO/IEC 27001 requirements. This study contributes by providing a practical audit model for SMEs to improve information security governance in a cost-effective and structured manner (ISO, 2022).