An organization can prevent a risk from occurring by taking planning or mitigation steps that must be taken if an error occurs so that it does not have a negative impact on the organization's activities. The data center is the heart of the information technology infrastructure owned by XYZ University because there needs to be risk management in place if a threat occurs whether from within or from outside. Three security factors that must be protected in an information security system are confidentiality, integrity and availability. The absence of a risk analysis made by XYZ University has resulted in the absence of mitigation steps that must be taken if a threat or failure occurs in the Data Center. Based on the results of risk management research using OCTAVE Allegro carried out at XYZ University, 9 important information assets were produced, of which 5 assets must be mitigated, namely errors during network maintenance in the server room, service interruption due to power failure, internet connection disruption, damage to server hardware, Natural disasters that result in damage to related devices, and 4 information assets must be postponed, namely leaking of access rights such as administrator username and password, server space being accessed by unauthorized parties, bugs/errors during system updates, exploitation of system security gaps in the server from outside parties. and in the.
Copyrights © 2024