The development of information technology has driven digitalization in various sectors, including government procurement of goods and services through the E-purchasing system. Toko Amertha Sanjiwani is one of the businesses that utilizes the e-Catalog and Mbizmarket platforms to process transactions with government agencies. However, in its implementation, the information system used also creates various operational risks that can disrupt business continuity. This study aims to analyze the information system risk management implemented by Toko Amertha Sanjiwani using the ISO 31000:2018 framework. The method used is a descriptive qualitative approach with data collection techniques in the form of interviews, observation, and documentation. The results show that there are ten main risks identified, including internet connection disruptions, application inaccessibility, and delays in product data updates and delivery of goods. These risks are then analyzed based on their likelihood and impact, so that mitigation priorities are obtained. Control measures are carried out through strategies such as increasing staff training, providing backup networks, and implementing dual authentication and data backup SOPs. By conducting regular evaluation and monitoring, the implementation of ISO 31000-based risk management has proven effective in helping Toko Amertha Sanjiwani identify, analyze, and control information system risks systematically and sustainably.
Copyrights © 2026