Jurnal Ilmiah Merpati (Menara Penelitian Akademika Teknologi Informasi)
Vol 9 No 3 (2021): Vol. 9, No. 3, December 2021

Information Security Risk Strategy at PT. X Using NIST SP 800-30

I Gusti Ngurah Made Putra Eryawan (Udayana University)
Gusti Made Arya Sasmita (Udayana University)
Anak Agung Ketut Agung Cahyawan Wiranatha (Udayana University)



Article Info

Publish Date
27 May 2021

Abstract

Information security is a vital aspect that must be considered in use of information technology devices by active users. PT. X runs a business that applies information technology related to distribution aspects through company resource planning. Information technology formed assets IT infrastructure, information systems, operating procedures, and network infrastructure. This asset has a potential threat that causes disruption resulting losses. This problem arises to cope through the response to the risk strategy. NIST SP 800-30 method has a flexible risk perspective for the organization and federation standards of American security. Research is divided into risk measurement as a risk, risk mitigation as risk planning, and risk evaluation embodied risk reports. Results of the research show the value of risk through the calculation of the likelihood and impact matrix of the highest threat is at a low level is 14, medium at 12, and high of 4 are categorized good enough. Keywords: Risk Strategy, Information Security, NIST SP 800-30, Risk

Copyrights © 2021






Journal Info

Abbrev

merpati

Publisher

Subject

Computer Science & IT

Description

The journal publishes work from all disciplinary, theoretical and methodological perspectives. It is designed to be read by researchers, scholars, teachers and advanced students in the fields of Information Systems and Information Science, as well as IT developers, consultants, software vendors, and ...