Abstract - The development of digital information systems brings an increased risk of cybersecurity threats that impact data integrity, individual privacy, and public trust (Febiola, 2023). This study aims to examine risk management practices and security policy frameworks applied to securing digital information systems (Saputra, 2025). The study utilized a literature review by analyzing journals, books, government regulations, and information security standards such as ISO/IEC 27001 and NIST SP 800-30 (Arifnur, 2023). The findings indicate that digital security relies on three main aspects: risk identification and assessment, implementation of preventive and mitigating controls, and structured policy governance (Harefa & Hartomo, 2022). Public data leaks and public disinformation are high-probability risks that require mitigation through encryption, dual authentication, and media monitoring (BSSN, 2022). Risk management and information security policies are essential foundations for maintaining data integrity and public trust (Zulfitra, 2023). Further research is recommended to use an empirical case study approach (Nadiya et al., 2024).
Copyrights © 2026