International Journal of Electrical, Computer, and Biomedical Engineering (IJECBE)
Vol. 2 No. 3 (2024)

Design and Analysis of Information Security Risk Management Based on ISO 27005: Case Study on Audit Management System (AMS) XYZ Internal Audit Department

Hidayatullah, Diar Eka Risqi (Unknown)
Kunthi, Raisiffah (Unknown)
Harwahyu, Ruki (Unknown)



Article Info

Publish Date
30 Sep 2024

Abstract

Information security is an important aspect and supported by a report issued by the Internal Audit Foundation entitled Risk in Focus 2024 Global Summary. Biggest risk that will be faced in 2024 is Cybersecurity and Data Security with a score of 73% for the global average. Based on a report issued by International Business Machine (IBM) entitled Cost of a Data Breach Report 2023, takes an average of 204 days to find out about a data leak by an affected agency or organization, and takes 73 days to overcome the data leak. To realize this digitalization, an Audit Management System (AMS) system was implemented which can accommodate the audit process starting from the Planning, Execution and Reporting stages as well as follow-up process for recommendations process. Using AMS is not without risks, access to AMS can be done without a Virtual Private Network (VPN). In this research, a risk assessment was carried out based on the ISO/IEC 27005:2022 standard by proposing a method for calculating consequences based on the classification of data in the system and a method for calculating possibilities based on business processes that have an impact on system vulnerabilities and risks that need to be mitigated. ISO/IEC 27002:2022 will be used to anticipate risks. Results of the risk examination revealed that there were 24 risks with 1 very high-level risk, 3 high level risks, 8 medium level risks, 11 low level risks, and 1 very low-level risk in the XYZ internal audit department.

Copyrights © 2024






Journal Info

Abbrev

go

Publisher

Subject

Computer Science & IT Electrical & Electronics Engineering Materials Science & Nanotechnology Medicine & Pharmacology

Description

The International Journal of Electrical, Computer, and Biomedical Engineering (IJECBE) is an international journal that is the bridge for publishing research results in electrical, computer, and biomedical engineering. The journal is published bi-annually by the Electrical Engineering Department, ...