Aiti: Jurnal Teknologi Informasi
Vol 21 No 2 (2024)

Kematangan risiko keamanan informasi layanan TI menggunakan pendekatan NIST dan standar ISO 27001:2013 (Studi kasus: Bapenda Provinsi Jawa Tengah)

Aminudin, Agus (Unknown)
Supriyanto, Aji (Unknown)



Article Info

Publish Date
30 Sep 2024

Abstract

The application of Information Technology (IT) often poses risks, such as incorrect application processes, data theft and data corruption. With the increasing risk, greater control is needed. For this reason, it is necessary to see whether the running system is equipped with adequate control. The Regional Revenue Management Agency (BAPENDA) of Central Java Province has utilized IT in its activities. The absence of adequate information security standards impacts data or information that is less secure, both in terms of confidentiality, integrity, and availability. The aims and objectives of the research are to measure KAMI risk maturity, such as conducting an IT assessment managed by BAPENDA. For example, vehicle tax payment service application, Android (New Sakpole), and IT infrastructure. The results of KAMI Maturity Level at BAPENDA in security policy clauses were 0.76, organization KAMI 1.24, control asset classification 0.63, personnel security 1.12, incident management KAMI 1.21, business continuity management 0.51, physical and environmental security 1.61, system development and maintenance 2.94, access control 4.18, communications and operations management 4.58 and, compliance 2.07. Mapping asset identification with NIST-CSF obtained several assets: hardware, software, employee, and information/data. The results show that assets in BAPENDA have a high risk (High) Risk Avoidance, so they require mitigation using NIST controls and Annex ISO-IEC 27001:2013.

Copyrights © 2024






Journal Info

Abbrev

aiti

Publisher

Subject

Computer Science & IT

Description

AITI: Jurnal Teknologi Informasi is a peer-review journal focusing on information system and technology issues. AITI invites academics and researchers who do original research in information system and technology, including but not limited to: Cryptography Networking Internet of Things Big Data Data ...