Filter By Year

1945 2024


Found 1,293 documents
Search KEAMANAN INFORMASI

PENILAIAN RESIKO TEKNOIOGI INFORMASI & KEAMANAN SISTEM INFORMASI DENGAN MENGGUNAKAN FRAMEWORK COBIT 4.1 DAN GUIDELINES NIST SP 800-30 ( Studi Kasus : Rumah Sakit Umum Dr Slamet Garut ) Yana aditia gerhana; Erdiansyah Erdiansyah Erdiansyah; Undang Syarifudin
JURNAL ISTEK Vol 5, No 1-2 (2011): ISTEK
Publisher : JURNAL ISTEK

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

Every organization have a goal. In the digital era, organization use automated information technology to process their information for better support for their goals, and risk management plays and important role to protect information assets of organization and for that purpose can be accomplished. An effective risk management process is an important component of the success of information technology security program. The principle objectives of an organization’s risk management should be protect organization and the ability to perform their purpose is not to protect information technology assets only. For this risk management process should not be treated purely as a function but the technique is the basis of the management functions of the organization.
Analisis Resiko Keamanan Sistem Informasi Menggunakan Metode OCTAVE-S (Studi Kasus : Sistem Informasi Akademik STMIK AKBA Makassar) Syaharullah Disa
Inspiration: Jurnal Teknologi Informasi dan Komunikasi Vol 1, No 1 (2011): Jurnal Inspiration Volume 1 Issue 1
Publisher : STMIK AKBA

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.35585/inspir.v1i1.3

Abstract

Penelitian ini bertujuan untuk menganalisis keamanan sistem informasi pada STMIK AKBA Makassar. Metode yang digunakan dalam menganalsis yakni metode OCTAVE-S (Operationally Critical Threat, Asset, and Vulnerability Evaluation). Penelitian diwali dengan melakukan identifikasi aset sistem informasi beserta resiko ancaman yang mungkin terjadi. Selanjutnya dilakukan perhitungan kemungkinan tingkat kerugian yang ditimbulkan apabila resiko tersebut terjadi. Hasil Penelitian menunjukkan bahwa Persentase total resiko (dengan klasifikasi) sebesar 44,8. Sedangkan Persentase total resiko (tanpa klasifikasi) sebesar 67,3. Dengan hasil persentasi tersebut, maka dapat dikatakan bahwa tingkat keamanan sistem informasi pada STMIK AKBA makassar tergolong sedang.
Perencanaan Keamanan Informasi Berdasarkan Analisis Risiko Teknologi Informasi Menggunakan Metode OCTAVE dan ISO 27001 (Studi Kasus Bidang IT Kepolisian Daerah Banten) Fadzri Ahdi Anshori; Suprapto Suprapto; Andi Reza Perdanakusuma
Jurnal Pengembangan Teknologi Informasi dan Ilmu Komputer Vol 3 No 2 (2019): Februari 2019
Publisher : Fakultas Ilmu Komputer (FILKOM), Universitas Brawijaya

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (232.405 KB)

Abstract

Banten Regional Police is a public service provided by the government to secure and enforce the law in force in Indonesia, especially in urban areas. Operational activities at the Banten Regional Police have been supported by information technology, but the application of information technology in Banten Regional Police has not had a policy regarding information security and risk management. The purpose of this study is to provide a risk mitigation plan that is appropriate for the Banten Regional Police. Provisions on risk mitigation plans can be obtained by identifying and assessing the risks in the Banten Regional Police based on the OCTAVE method. Risk mitigation recommendations are provided in accordance with ISO 27001 standards and prioritized based on the costs and benefits of each recommendation action. The final results of this study, there are 28 risks that may occur in Banten Regional Police with the highest RPN value 240 to the lowest RPN value 18. Risk mitigation recommendations can be made with 11 controls contained in ISO27001.
TATA KELOLA KEAMANAN TEKNOLOGI INFORMASI MENGGUNAKAN COBIT 5 (STUDI KASUS PADA DINAS KOMUNIKASI DAN INFORMASI KOTA SUKABUMI) ., lelah; Suharto, Toto
JURNAL GAUNG INFORMATIKA Vol 12 No 1 (2019): Jurnal Gaung Informatika Vol.12 No 1 Januari 2019
Publisher : JURNAL GAUNG INFORMATIKA

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (213.114 KB)

Abstract

DISKOMINFO Sukabumi city is Office that has the task of implementing regional authority in field of management of Information and Communication Technology. The consequence of application of Information and Communication Technology (ICT) is with emergence of security risks. As happened in Sukabumi City Government Information System, hacking occurs by unauthorized parties. There are  several ways to maintain information security, by applying information security to information technology layer technically or by doing governance. The implementation of this governance is a necessity and has become a necessity and a demand. One of them is using COBIT 5 framework with the COBIT for information security section, which focuses on information security and provides more complete guidelines and practices for information security professionals and other related parties at each interprise level. In a study at DISKOMINFO Kota Sukabumi, the selection of the COBIT 5 framework domain, was taken by mapping the organization's objectives with EG COBIT and ITRG goals. From the election was taken the enabler of EDM01, APO01, APO02, APO03, BAI02, DSS03, DSS05. The results show that Information Technology security management in DISKOMINFO is still at level 1.
Penilaian Risiko Keamanan Informasi Menggunakan Metode NIST 800-30 (Studi Kasus: Sistem Informasi Akademik Universitas XYZ) Wenni Syafitri
Jurnal CoreIT: Jurnal Hasil Penelitian Ilmu Komputer dan Teknologi Informasi Vol 2, No 2 (2016): Desember 2016
Publisher : Fakultas Sains dan Teknologi, Universitas Islam Negeri Sultan Syarif Kasim Riau

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (782.18 KB) | DOI: 10.24014/coreit.v2i2.2356

Abstract

Sistem informasi akademik Universitas XYZ merupakan terobosan terbaru dibidang pelayanan akademik. Sistem ini menyediakan berbagai informasi yang dibutuhkan oleh civitas akademika. Sehingga kebutuhan akan keberlangsungan sistem ini semakin penting. Permasalahan yang pernah ada di SI Akademik Universitas XYZ seperti berkaitan dengan celah kerawanan keamanan informasi. Jika permasalahan ini tidak dapat diperbaiki secara berkelanjutan, alhasil akan memberikan dampak ataupun risiko kepada keberlangsungan sistem ini, khusunya civitas akademika. Penelitian ini menggunakan NIST SP 800-30 sebagai metode yang digunakan untuk menyelesaikan permasalahan tersebut. Maka berdasarkan hasil penelitian yang telah dilakukan, Universitas xyz memiliki 1 tingkat risiko tinggi, 5 tingkat risiko sedang dan 52 tingkat risiko rendah.
AUDIT KEAMANAN SISTEM INFORMASI AKADEMIK DENGAN KERANGKA KERJA ISO 27001 DI PROGRAM STUDI SISTEM INFORMASI UNIKOM Winanti, Marliana Budhiningtias; Dzulhan, Ismail
Majalah Ilmiah UNIKOM Vol. 16 No. 2 (2018): Majalah Ilmiah Unikom
Publisher : Universitas Komputer Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (659.913 KB) | DOI: 10.34010/miu.v16i2.1355

Abstract

Academic Information Systems Prodi UNIKOM Information System is the primary system used in the Information Systems Prodi process data and information about lectures and students. But in this system still found a lack of control of physical and logical security. To find out how your system security in organizations, information systems need security audit to determine whether security information is in accordance with the security procedures of management. Standardization used here is ISO 27001, this standards have been an international standards organization that is structured on the management of information security systems. Implementation of academic information system security audit is done by using the Audit Checklist ISO 27001: 2005. Audit results found security controls are still less well as the roles and responsibilities of employee safety, physical protection from disasters and power failures, data validation, and data backup are less regular. So the academic information system security controls is still need to be repairs in accordance with the recommendation.
PEMBUATAN RENCANA KEAMANAN INFORMASI BERDASARKAN ANALISIS DAN MITIGASI RISIKO TEKNOLOGI INFORMASI AlBone, Aan
Jurnal Informatika Vol 10, No 1 (2009): MAY 2009
Publisher : Institute of Research and Community Outreach - Petra Christian University

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (305.503 KB) | DOI: 10.9744/informatika.10.1.44-52

Abstract

An information security plan consists of strategies and shared responsibility, the main aim is to reduce the risk of a potential threat to the company's operations. If the security plan is not based on the results of risk analysis, can cause weakness in the strategy to anticipate the threat of disruption and attacks on corporate assets. Weak strategy, caused by the process of identifying weaknesses and vulnerabilities of information technology is not done properly. Instead of the security plan should be based on the results of analysis and information technology risk mitigation, so that the security of the proposed strategy can effectively reduce the risks identified through risk analysis and mitigation. The process of risk analysis in addition to producing the identification of risk, also providing recommendations appropriate security controls with the risk would be reduced. The recommended security controls on risk analysis, will then be evaluated from the aspects of effectiveness and efficiency in reducing any risk, the risk mitigation process, so that this process will provide a strong foundation in information security plan to determine an overall, effective and efficient, since it is based with the impelementasinya priority. Sebuah rencana keamanan informasi terdiri atas strategi dan pembagian tanggungjawab, yang bertujuan utama untuk menurunkan risiko yang berpotensi menjadi ancaman terhadap operasional perusahaan. Jika penyusunan rencana keamanan tidak berdasarkan hasil analisis risiko, akan dapat menyebabkan lemahnya strategi dalam mengantisipasi ancaman gangguan dan serangan terhadap aset perusahaan. Lemahnya strategi tersebut, disebabkan oleh proses identifikasi kelemahan dan kerawanan teknologi informasi yang tidak dilakukan dengan baik. Sebaliknya dalam penyusunan rencana keamanan seharusnya didasari oleh hasil analisis dan mitigasi risiko teknologi informasi, agar strategi keamanan yang diusulkan dapat secara efektif menurunkan risiko yang telah diidentifikasi melalui analisis dan mitigasi risiko. Proses analisis risiko selain menghasilkan identifikasi risiko, juga memberikan rekomendasi kontrol keamanan yang sesuai dengan risiko yang akan diturunkan. Kontrol keamanan yang direkomendasikan pada analisis risiko, selanjutnya akan dinilai kembali dari aspek efektivitas dan efisiensi dalam menurunkan setiap risiko, pada proses mitigasi risiko, sehingga proses ini akan memberikan dasar yang kuat dalam menentukan rencana keamanan informasi yang menyeluruh, efektif dan efisien, karena didasarkan dengan prioritas implementasinya. Kata kunci: Analisis risiko, Mitigasi risiko, Rencana Keamanan Informasi
Analisis Sistem Manajemen Keamanan Informasi Menggunakan ISO/IEC 27001 : 2013 Serta Rekomendasi Model Sistem Menggunakan Data Flow Diagram pada Direktorat Sistem Informasi Perguruan Tinggi Yuze, Yuni Cintia; Priyadi, Yudi; Candiwan, Candiwan
JSINBIS (Jurnal Sistem Informasi Bisnis) Vol 6, No 1 (2016): Volume 6 Nomor 1 Tahun 2016
Publisher : Universitas Diponegoro

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (725.713 KB) | DOI: 10.21456/vol6iss1pp38-45

Abstract

The importance of information and the possible risk of disruption, therefore the universities need to designed and implemented of the information security.  One of the standards that can be used to analyze the level of information security in the organization is ISO/IEC 27001 : 2013 and this standard has been prepared to provide requirements for establishing, implementing, maintaining and continually improving an information security management system. The objective of this research is to measure the level of information security based on standard ISO/IEC 27001: 2013 and modeling systems for information security management. This research uses descriptive qualitative approach, data collection and validation techniques with tringulasi (interview, observation and documentation). Data was analyzed using gap analysis and to measure the level of maturity this research uses SSE-CMM (Systems Security Engineering Capability Maturity Model). Based on the research results, Maturity level clause Information Security Policy reaches level 1 (Performed-Informally), clause Asset Management reaches level 3 (Well-Defined), clause Access Control reaches level 3 (Well-Defined), clause Physical and Environmental Security reaches level 3 (Well-Defined), clause Operational Security reaches level 3 (Well-Defined), Communication Security clause reaches the level 2 (Planned and Tracked). Based on the results of maturity level discovery of some weakness in asset management in implementing the policy. Therefore, the modeling system using the flow map and CD / DFD focused on Asset Management System.
PERENCANAAN STRATEGIS SISTEM INFORMASI PADA PUSAT PENANGANAN INSIDEN KEAMANAN INFORMASI SEKTOR PEMERINTAH Setiawan, Ahmad Budi
Masyarakat Telematika Dan Informasi : Jurnal Penelitian Teknologi Informasi dan Komunikasi Vol 5, No 1 (2014): Masyarakat Telematika Dan Informasi : Jurnal Penelitian Teknologi Informasi dan
Publisher : Kementerian Komunikasi dan Informatika R.I.

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (1541.95 KB) | DOI: 10.17933/mti.v5i1.58

Abstract

Information security incident is a form of attack on the security of information that can occur in all sectors. The government sector is one of the targets of information security incidents. Central Government Information Security Incident Handling was established with the aim to address all forms of attacks on information security in government sector. The sustainability Central of Government Information Security Incident Handling (GovCSIRT) needs to be supported with information system infrastructure that's sophisticated and sufficiently. This research aims to create an information system strategic planning at the Center for Government Information Security Incident Handling. Implementation of Information Systems in an organization must adapt to the vision, mission, goals and needs of the organization. Therefore, the Information Systems Strategic Planning at the Government Information Security Management Center must be performed using appropriate methodologies. There are a wide variety of methodologies in information systems Strategic Planning. This study used a Cassidy methodology which is developed by Annita Cassidy. These results are used as input in the development of infrastructure or basic Information Systems Security Management Center Information Government to realize the use of ICT in a safe and convenient administration. The results of this research is used as input or recommendation in the development of the Government Information Security Incident Response Center to actualize the use of ICT in government that is safe and comfortable.
PENGARUH KUALITAS SISTEM INFORMASI AKUNTANSI DAN KEAMANAN SISTEM INFORMASI AKUNTANSI TERHADAP KEPUASAN PENGGUNA (Studi Pada Perbankan Syariah di Bengkulu) Rizky Hariyadi; Marsellina Fitri; Debby Arisandi
JURNAL AGHNIYA Vol 2, No 2 (2019)
Publisher : STIESNU Bengkulu

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

Abstract The Effect of Quality Accounting Information System and Accounting Information System Security on User Satisfaction (Study on Islamic Banking in Bengkulu). The purpose of this study was to determine effect of quality accounting information system and security accounting information system on user satisfaction in Islamic banking. This research is descriptive research, the population in this study were all employees of Islamic banking in Bengkulu using a purposive sampling method totaling 60 respondents. The data collection method used was secondary and primary data with the analysis method, namely the reliability test, validity and multiple linear regression. The results showed that the quality accounting information system and the security accounting information system simultaneously had a significant effect on user satisfaction with a probability (sig) of 0.000

Page 10 of 130 | Total Record : 1293