The XYZ City Government has conducted an assessment using the KAMI Index, revealing that the governance aspect is weaker compared to other areas. Given this issue, a risk assessment was conducted to provide recommendations for the City of XYZ to improve its information security. The risk assessment was carried out using the NIST SP 800-30 framework, designed as a guideline for evaluating risk management. There are five risk categories: Very Low, Low, Moderate, High, and Very High. Based on the assessment using NIST 800-30, several critical areas for improvement were identified: Policy with a High level of risk, Data and Information with a Very High level of risk, Information Security Education with a Moderate level of risk, Accountability with a High level of risk, Implemented Programs with a High level of risk, Legal Aspects with a High level of risk, BCP and DRP Implementation with a High level of risk, Information Security Standards and Performance with a Moderate level of risk, and Information Security Management with a High level of risk.
Copyrights © 2024