Jurnal Pengembangan Teknologi Informasi dan Ilmu Komputer
Vol 4 No 9 (2020): September 2020

Analisis Manajemen Risiko Keamanan Sistem Informasi pada BKPSDM Kota Batu menggunakan Kerangka Kerja OCTAVE-S dan ISO 27001:2013 (Studi Kasus: Aplikasi E-Kinerja)

Dinda Riski Nurfadilah (Fakultas Ilmu Komputer, Universitas Brawijaya)
Widhy Hayuhardhika Nugraha Putra (Fakultas Ilmu Komputer, Universitas Brawijaya)
Aditya Rachmadi (Fakultas Ilmu Komputer, Universitas Brawijaya)



Article Info

Publish Date
07 Sep 2020

Abstract

Staffing Agency and Human Resources Development Batu City (BKPSDM) is an OPD (Regional Institute Organization) that uses information technology for the procurement and operational processes on the organization. E-Kinerja system is a system managed and created by BKPSDM to measure and assess the performance of Government Employees (ASN) periodically basis as a reference for providing performance benefits. The functional of system and information technology give good results because it helps on the internal operations organization, in other condition also have a bad impact and security issues that are not mitigated proceed correctlye. Problems that occur in BKPSDM Batu City never do an assesment focused on risk management and there are no regulations or policies related to information system security. This researcher supports to identification and provide information on BKPSDM Batu City related to weaknesses, challenges, system weaknesses, and provide mitigation recommendations. This study uses an OCTAVE-S work license to analyze risk and combined with standard ISO 27001: 2013 controls. The results of the study obtained 3 areas of security practices that have yellow traffic light status namely security management, physical access and management approval. As well as 3 areas of security practices that have red light status namely security regulations and policies, authentication and authorization, and security management. There are six areas of security practice were chosen as areas for mitigation. Control guidelines according to standard ISO 27001: 2013 so that they can be used as guidelines for the BKPSDM of Batu City in making improvements.

Copyrights © 2020






Journal Info

Abbrev

j-ptiik

Publisher

Subject

Computer Science & IT Control & Systems Engineering Education Electrical & Electronics Engineering Engineering

Description

Jurnal Pengembangan Teknlogi Informasi dan Ilmu Komputer (J-PTIIK) Universitas Brawijaya merupakan jurnal keilmuan dibidang komputer yang memuat tulisan ilmiah hasil dari penelitian mahasiswa-mahasiswa Fakultas Ilmu Komputer Universitas Brawijaya. Jurnal ini diharapkan dapat mengembangkan penelitian ...