This research examines the application of ISO 31000:2018 in IT risk management within the publishing system of PT. X, a book publishing company. ISO 31000:2018 is an international standard providing systematic guidance to identify, analyze, and manage risks, aiming to enhance operational efficiency and organizational sustainability. Using a qualitative approach, this study incorporates literature reviews and interviews with the publishing manager of PT. X to further understand risk management implementation and identify existing gaps. The identified risks include natural, human, and system-related factors, totaling 23 risks such as hacking attacks, data theft, and server damage. Risk analysis was conducted using likelihood and impact parameters to evaluate the frequency and consequences of risks on company operations. The findings reveal that implementing ISO 31000:2018 offers an effective framework for managing risks at PT. X, enhancing risk awareness, safeguarding company assets, and supporting decision-making processes. This study also provides strategic recommendations to improve risk management and strengthen operational resilience at PT. X.
Copyrights © 2024