PT ABC is a property developer that relies heavily on the utilization of information technology in its operations. This dependency creates system vulnerabilities that could potentially disrupt business continuity. This study aims to analyze and evaluate information systems risk management at the company by applying the ISO 31000:2018 framework. The research stages include defining the scope, identifying assets and risks, analyzing likelihood and impact, evaluating risk levels, and determining treatment strategies. The results mapped 21 possible risk threats originating from hardware, software, data, and user factors. The risk matrix evaluation indicates that the most critical threats are at a very high level, such as power outages, cyberattacks, and data backup failures. To address these vulnerabilities, risk treatments are formulated with a dominance of mitigation actions, followed by risk avoidance, acceptance, and sharing. This research contributes as a strategic recommendation guide for company leaders to minimize risks and enhance the security of their information asset governance.
Copyrights © 2026