IJISCS (International Journal of Information System and Computer Science)
Vol 7, No 3 (2023): IJISCS (International Journal of Information System and Computer Science)

OPTIMIZING RISK MANAGEMENT IN THE INSURANCE SECTOR: LEVERAGING THE COBIT 5 FRAMEWORK

Pratama, Kenny (Unknown)
Fianty, Melissa Indah (Unknown)



Article Info

Publish Date
14 Nov 2023

Abstract

A vehicle insurance company is grappling with a critical issue amid its efforts to integrate information technology into its operations. The problem revolves around the absence of documented procedures related to IT service management and infrastructure resources, impacting various operational facets, including business processes, staff management, applications, infrastructure, facilities, and vendor relationships. To address these concerns, the company has taken measures, including identification, analysis, control, and mitigation of IT-related risks. However, these measures have proven insufficient for optimal risk management, prompting the need for a comprehensive evaluation of their IT risk management capabilities. This assessment focuses on evaluating the implementation of IT risk management using a qualitative approach within the COBIT 5 framework. Specifically, it assesses the company's performance in two closely related processes: APO 12 (Manage Risk) for identifying IT-related risks and DSS 05 (Manage Security Services) for understanding the role of information security and monitoring security aspects. The assessment results indicate that the company's IT risk management capability is at level 3 (Established) for both processes. However, the company aspires to reach level 4 (Predictable) and improve their risk management. Furthermore, a critical discovery is the absence of Standard Operating Procedures (SOPs) related to data encryption, which is vital for information security. While some monitoring methods for information security service design have been effective, there is a need for enhanced data security through the development of encryption-related SOPs. The company plans to implement improvements based on COBIT 5 framework recommendations to achieve a higher level of risk management capability. These enhancements aim to better align IT-related risk management with the company's business objectives and improve the overall effectiveness of the processes.

Copyrights © 2023






Journal Info

Abbrev

ijiscs

Publisher

Subject

Computer Science & IT Control & Systems Engineering Electrical & Electronics Engineering

Description

The IJISCS (International Journal of Information System and Computer Science) is a publication for researchers and developers to share ideas and results of software engineering and technologies. These journal publish some types of papers such as research papers reporting original research results, ...