To enhance the university's performance in providing services, Ma Chung University utilizes IT infrastructure and information systems that support the continuity of its business processes. However, there are potential risks that could threaten these business processes. Currently, Ma Chung University has not yet implemented a standardized approach to IT risk management, leading to uncertainties, particularly in managing risks related to the university's assets. By adopting the standard recognized by the National Standardization Agency (BSN), namely ISO 31000, which is suitable for dynamic and flexible organizations, this standard can be utilized to assess risks and determine responses to those risks. The purpose of this thesis is to identify and analyze risks, as well as to mitigate the impact of IT-related risks at Ma Chung University, thereby contributing to the continuous improvement of the university's risk management mechanisms. Policies have been formulated to monitor and review risk management practice.
Copyrights © 2023