Jurnal Sistem Informasi Universitas Dinamika
Vol 5, No 10 (2016)

Security Audit Parahita Information System Based ISO 27002:2005 At Parahita Diagnostic Center Surabaya

Diah, Meita Eny Kusumaning (Unknown)
Tanuwijaya, Haryanto (Unknown)
Sutomo, Erwin (Unknown)



Article Info

Publish Date
10 Mar 2017

Abstract

Parahita Diagnostic Center (PDC) is a company engaged in the field of public health service, particularly in the field of laboratory. PDC using technology that is integrated and centralized called Parahita Information System (PARIS) for running and supporting existing business processes. Implementation of the (PARIS) has some problems: frequent occurrence of malicious code attacks, misuse by unauthorized parties, and lack of maintenance on the system. Existing obstacles which lead to some risk of data loss, misuse of data and information, failures in data processing and the performance of the system becomes impaired. In order to determine the cause of problems that may occur, PDC need to conduct a Information System Security Audit using the standard ISO 27002: 2005 as the best security. This audit process using ISACA developed stage and calculations of maturity model using CMMI. The scope used is clause 10, clause 12, clause 13, clause 14 and clause 15 which is adapted to the problem. The results obtained from the information system security audit is the level of maturity of 3,11 that is defined. It shows that most of the information systems security process already have rules and conducted on a regular basis. This research also produced recommendations which are used to improve the process of information systems owned by the PDC.

Copyrights © 2016






Journal Info

Abbrev

jsika

Publisher

Subject

Humanities Computer Science & IT Economics, Econometrics & Finance Education Engineering

Description

Jurnal JSIKA adalah jurnal yang menampung publikasi tentang sistem perangkat lunak dan perangkat keras yang mendukung aplikasi khususnya sistem informasi. Jurnal JSIKA menerbitkan artikel mengenai desain dan implementasi, data model, process model, algoritma, perangkat lunak dan perangkat keras ...