Implementing e-government in Indonesia, one example of technology adoption in the government sector is the digitalization of business processes within government agencies. SiREV application is an information system used by auditor XYZ Agency in carrying out business processes in the field of supervision. In developing this application, the agile method was chosen to accommodate several reasons starting from requirements that could not be determined at the beginning of the work implementation and changes to the application in the future that needed to be made to adapt to needs. Several obstacles are encountered in its implementation which are the familiarity of using agile methods and the security of the information while developing it. To conduct this research, we use ISO 31000:2018 and ISO 27005:2018 framework to assess the risks. This study aims to assess risk in agile project with ISO 31000 and ISO 27005 so that XYZ Agency has a design of risk management related to agile implementation in project development and information security. The results of this research showed that 24 risks were identified, consisting of 11 risks related to agile implementation and 13 risks related to information security. After doing risk evaluation from these 24 risks, 13 risks need to be handled because they are outside the organization's risk appetite, while the other 11 risks do not need to be handled because they are within the organization's risk appetite