Filter By Year

1945 2024


Found 1,305 documents
Search KEAMANAN INFORMASI

Penilaian Kapabilitas Tata Kelola Keamanan Informasi Menggunakan Cobit5 Pada PT.Denya Ikhwan, Ali; Ardiyansyah, Agung; Rayhannur, Muhammad Jaffar; Hidayat, Riyan
Jurnal Sains dan Teknologi (JSIT) Vol. 3 No. 1 (2023): January-April
Publisher : CV. Information Technology Training Center - Indonesia (ITTC)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47233/jsit.v3i1.496

Abstract

This research assesses the copability of asset and information security governance using the COBIT5 framewort. The study aims to evaluate the current state of security goverenance in an organization and identify areas of improvement using the COBIT5 framework. The research will analyze the processes and controls in place for managing and protecting information and assets, and assess their aligmnment with the COBIT5 giudelines. The result of the study will procide valuable insights for ornganizations looking to improve their security governance and compliance with industry standards.
Kajian Kebijakan Keamanan Sistem Informasi Sebagai Bentuk Perlindungan Kerahasiaan Pribadi Karyawan Perusahaan BFI Finance Hafizd, Daffa Al; Asnawi, Azi; Assidiqie, Muhammad Fikri
Jurnal Sains dan Teknologi (JSIT) Vol. 3 No. 1 (2023): January-April
Publisher : CV. Information Technology Training Center - Indonesia (ITTC)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47233/jsit.v3i1.497

Abstract

Technology that connects computers around the world makes it possible to exchange information and data and even communicate with each other in the form of images and videos. The more valuable information is, the more security standards are needed to protect that information. The goal of computer security, among others, is to protect information. The higher the security standards provided, the higher the privacy protection of information. Protection of employee privacy in a company is one of the factors that must be considered in the implementation of information systems. Information system security policies include: System maintenance, risk management, setting access rights and human resources, security and control of information assets and server security policies. The policies that have been reviewed will not only be a form of protection for company information, but also a form of protection for the personal privacy of employees of BFI Finance Company..
Evaluasi Manajemen Keamanan Sistem Informasi Pada Perusahaan PT.Wook Tecnology Wahyu Sofianda; Taufiqurrahman; Satria Habibi Ritonga; Adnan Buyung Nasution
Jurnal Sains dan Teknologi (JSIT) Vol. 3 No. 1 (2023): January-April
Publisher : CV. Information Technology Training Center - Indonesia (ITTC)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47233/jsit.v3i1.498

Abstract

PT WOOK TECNOLOGY adalah salah satu perusahaan besar yang bergerak dibidang jasa logistiks di Indonesia.Manajemen keamanan informasi sangat diperlukan sebagai upaya untuk meminimalkan resiko dalam meningkatnya ancaman data dan informasi. Keamanan Sistem informasi terdiri atas perlindungan harian, yang disebut keamanan informasi (information security) dan persiapan-persiapan operasional. Pengolahan data merupakan bagian dari operasional bisnis perusahaan. standard ISO 27001:2005 adalah yang digunakan dalam penelitian ini. menyesuaikan dengan instrumen penelitian pada kebutuhan organisasi yang dikembangkan dan fokus pada manajemen keamanan informasi adalah standard ISO 27001:2005. Dikugnakannya standard ISO 27001:2005 agar dapat mengurangi resiko tingkat keamanan, dan meningkatkan control keamanan yang direkomendasikan pada PT.WOOK TECNOLOGY, serta melakukan evaluasi secara berkesinambungan.
Kapabilitas Tata Kelola Keamanan Informasi Menggunakan Cobit5 Pada Perguruan Tinggi Graha Kirana Miana Sweety; Dedi Irawan; Anggi Refachriati2; Miftahul Jannah Toar
Jurnal Penelitian Dan Pengkajian Ilmiah Eksakta Vol 2 No 1 (2023): Jurnal Hasi Penelitian Dan Pengkajian Ilmiah Eksakta - JPPIE
Publisher : LPPM Universitas Dharma Andalas

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47233/jppie.v2i1.703

Abstract

Information security management governance is needed to maintain the confidentiality, integrity and availability of information in the company. This research requires an understanding of information security that is ongoing in the company to conduct a capability assessment and provide recommendations for improvements using COBIT 5 at Graha Kirana College. In the process, the five COBIT frameworks are used to increase the effectiveness of agency security. The selection of the COBIT domain was carried out by reviewing the business documents of Graha Kirana College and interviews with IT managers. Good news security can be achieved through the implementation of a number of technical measures supported by appropriate management policies and procedures. As an activity carried out to guide and manage the company in the context of facing risks. Risk management can be understood as a process that is carried out rationally and systematically arranged to guide, identify, monitor, prepare solutions, and report hazards.
Analisis Manajemen Resiko Keamanan Informasi pada Kantor Dinas Pendidikan Gunung Tua Lili Saputri; Mirna Annifah Hsb; Tursina Juliani
Journal on Education Vol 5 No 2 (2023): Journal on Education: Volume 5 Nomor 2 Tahun 2023
Publisher : Departement of Mathematics Education

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.31004/joe.v5i2.1024

Abstract

Implementation of Information Technology in government institutions is currently needed to facilitate data collection and strategic decision making. The Tax Service Office is one of the government agencies engaged in education. The Education Officeiis ia government agency located in theiGunung Tua Regency Government iOfficeiComplex, in its services such as processing data fromieach school, which isiiniPesawaran Regency whichican be used in processing certification data. Information technology analysis is carried out to ensure the operational continuity used byithe service, whether the existing information technology is used as well as ipossible, because if itiis not iused properly it will cause isome problems or existing losses suchias data loss, or ierrors. idata iuse, computer abuse, inaccurate information, because in this system the data is confidential and isensitive. iFor this reason, an Information Security Management System (ISMS) isineeded in managing its isecurity. iIn implementing ISO 27001ipreviously required information security risk imanagement. iThis risk management iactivity iis ineeded ito determine ithe iControl iObjectives ithat iwill ibe itaken ito handle irisks ithat imight ioccur. iIn implementing risk management, results were obtained only for username and password ilevel iassets ithat ihadiaihigh irisk i(6.67%) iof the 15 assets ithat ihad been iregistered, so that isecurity icontrols irelated ito iusernames iand ipasswords iwere ineeded ito minimize ior ireduce irisk.
Analisis Tingkat Kesadaran Keamanan Informasi: Studi Kasus Pengguna Aplikasi Perbankan Digital di Indonesia Guna Mencegah Social Engineering Taufiq Ramadhan; Betty Purwandari
Syntax Idea 86-98
Publisher : Ridwan Institute

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.46799/syntax-idea.v5i1.2113

Abstract

Digital adoption, especially in the digital banking sector in Indonesia, is the fastest in Asia. The increase in the number of digital banking service utilization is faced with digital security threats. The government and banking service providers have tried various information security awareness programs, but many users are still subject to social engineering which results in loss of access to applications and material losses. The problem found is that there is no reference to the level of information security awareness among users of digital banking applications. In order for an information security awareness raising program to be effective and in line with user needs, information on the level of information security awareness is needed. This research was conducted to measure the level of information security awareness of users of digital banking applications to prevent cases of social engineering. This study uses the Knowledge-Attitude-Behaviour (KAB) model which is applied to the Human Aspects of Information Security Questionnaire (HAIS-Q) and the taxonomy of security awareness of cellular users. Research data was collected using a questionnaire and got 299 valid respondents. The results of this study indicate that the level of information security awareness of users of banking service applications in Indonesia is at a good level with a value of 81.30%. The value of each dimension of information security awareness is the knowledge dimension of 84.45% (good), the attitude dimension is 84.68% (good) and the behavioral dimension is 78.06% (average). Based on these results, there are several recommendations regarding maintaining information security awareness, namely on regulation on illegal application installation and information security awareness improvement materials to reduce the risk of social engineering.
SISTEM INFORMASI MONITORING SERANGAN KEAMANAN MAIL SERVER DI YAYASAN ASSYIFA AL-KHOERIYYAH Aldy Kustyandi; Sofwandi Noor
Global Vol. 8 No. 2 (2021): GLOBAL
Publisher : FAKULTAS ILMU KOMPUTER

Show Abstract | Download Original | Original Source | Check in Google Scholar | Full PDF (1006.171 KB)

Abstract

Serangan brute force adalah serangan keamanan yang menggunakan algoritma percobaan terhadap seluruh kemungkinan kunci akses sebuah sistem yang biasanya juga di sebut algoritma brute force, serangan brute force dapat terjadi pada segala aspek sistem komputer baik berupa sistem komputer server maupun komputer client. Serangan brute force selain dapat memecahkan sebuah kunci masuk sebuah sistem, serangan brute force juga dapat menghabis kan resource sebuah sistem komputer. peneliti membatasi pembahasan pada aspek serangan brute force pada layanan SSH (secure shell) sebuah mail server di yayasan asyifa al-khoeriyyah, hal ini di karenakan serangan brute force dapat terjadi di segala aspek sistem komputer dari mulai brute force pada sistem aplikasi komputer berbasis web hingga serangan brute force pemecahan kunci akses sebuah personal komputer oleh program malware sehingga hal ini membutuhkan pembahasan yang lebih luas. Hasil dari penelitian penulis menemukan bahwa penanganan serangan brute force yang saat ini berjalan pada mail server di yayasan assyifa al khoeriyyah kurang maksimal dikarenakan informasi serangan hanya dalam bentuk log file dan notifikasi yang akan di rotasi dan di hapus, maka penulis menyimpul kan yayasan assyifa al khoeriyah membutuhkan sebuah sistem inforamsi yang dapat membantu mengelola data serangan tersebut.
EVALUASI DAN REKOMENDASI PEDOMAN SISTEM MANAJEMEN KEAMANAN INFORMASI (SMKI) SPBE PADA INSTANSI XYZ I Gede Putu Krisna Juliharta; Ni Kadek Sinta Febriani; Ketut Queena Fredlina
Jurnal Teknologi Informasi dan Komputer Vol 9, No 1 (2023): Jurnal Teknologi Informasi dan Komputer
Publisher : LPPM Universitas Dhyana Pura

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

ABSTRACTThe use of technology, information, and communication in the field of government is known as e-Government. One of the implementations of e-Government carried out by government agencies or agencies in Indonesia is SPBE. To ensure that the SPBE runs according to the goals set, a monitoring and evaluation process is needed from the SPBE itself. The XYZ Agency itself has many systems that are intended for the community, to make it easier and to be able to reach all levels of government. To maintain and improve the quality of information security management at XYZ Agency is to evaluate the level of readiness and completeness of information security management using the KAMI Index parameters, which will later become a reference for producing recommendations in the form of ISMS guidelines.Based on the results of an evaluation of the implementation of information security management related to the implementation of SPBE at the XYZ Agency, it is at an inappropriate level with the implementation of information security management that has been running which is still at level I to I+. To be able to adjust to these values. The XYZ Agency needs to prepare an Information Security Management System document as a standard guide in implementing SPBE.Keywords: SPBE, Information Security, ISMS, KAMI Index, Guidelines, E-governmentABSTRAKPemanfaatan teknologi, informasi dan komunikasi di bidang pemerintahan dikenal dengan e-Government. Salah satu penerapan e-Government yang dilakukan oleh lembaga ataupun instansi pemerintah di Indonesia yaitu SPBE. Untuk menjamin jalannya SPBE tersebut agar berjalan sesuai dengan tujuan yang telah tetapkan maka diperlukan proses pemantauan dan evaluasi dari SPBE itu sendiri. Instansi XYZ sendiri memiliki banyak sistem yang diperuntukkan kepada masyarakat, guna mempermudah dan dapat menjangkau semua lapisan masyarakat. Untuk menjaga dan meningkatkan kualitas manajemen keamanan informasi pada Instansi XYZ adalah dengan mengevaluasi tingkat kesiapan dan kelengkapan dari manajemen keamanan informasi menggunakan parameter Indeks KAMI, yang nantinya akan menjadi acuan untuk menghasilkan rekomendasi berupa panduan SMKI.Berdasarkan hasil evaluasi penerapan manajemen keamanan informasi terkait dengan penyelenggaraan SPBE pada Instansi XYZ berada pada level tidak layak dengan penyelenggaraan manajemen keamanan informasi yang telah berjalan yang masih berada pada tingkat I sampai I+. Untuk dapat menyesuaikan dengan nilai tersebut. Instansi XYZ perlu menyusun dokumen Sistem Manajemen Keamanan Informasi sebagai panduan baku dalam penyelenggaraan SPBE.Kata Kunci : SPBE, Keamanan Informasi, SMKI, Indeks KAMI, Pedoman, E-goverment
Analisis Tingkat Kematangan (Maturity Level) Dan PDCA (Plan-Do-Check-Act) Dalam Penerapan Audit Sistem Manajemen Keamanan Informasi Pada PT Indonesia Game Menggunakan Metode ISO 27001:2013 Eri Riana; Meiva Eka Sri Sulistyawati; Octa Pratama Putra
Journal of Information System Research (JOSH) Vol 4 No 2 (2023): January 2023
Publisher : Forum Kerjasama Pendidikan Tinggi (FKPT)

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47065/josh.v4i2.2552

Abstract

It has become a current requirement in every company regarding the implementation of governance in the ICT field in an effort to improve service quality. For this reason, it is necessary to implement and at the same time carry out an ISMS periodic audit process in companies using the ISO 27001: 2013 standard. Based on the audit and research results found in Annex 7 has the lowest level compared to the other Annexes, because the work instruction documentation related to labeling has not been registered in the main document so it needs to be adjusted to the main document. existing procedures with titles, so they are not synchronized. Overall the use of ISO 27001: 2013 has been going well with a maturity level value of 97.45% level 5. With almost all annexes and clauses meeting the standards of ISO 27001: 2013, so from the results this research It is hoped that the company can make improvements again in carrying out the document archive process so that it makes it easier for the auditor to carry out internal external audits and can carry out all activities in accordance with those in the ISO 27001: 2013 standard.
ANALISIS AUDIT KEAMANAN INFORMASI WEBSITE MENGGUNAKAN METODE NETWORK MAPPER DAN QUALYS SSL Alfin Syarifuddin Syahab
Jurnal Manajemen Informatika dan Sistem Informasi Vol. 6 No. 1 (2023): MISI Januari 2023
Publisher : LPPM STMIK Lombok

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.36595/misi.v6i1.742

Abstract

Stasiun Klimatologi D.I. Yogyakarta memiliki situs web dengan domain staklimyogyakarta.com yang digunakan sebagai media dan sarana publikasi informasi cuaca, iklim, dan kualitas udara yang berlokasi di Sleman, D.I. Yogyakarta. Website ini berisi berbagai informasi yang berisi publikasi, iklim, cuaca, kualitas udara dan pelayanan data. Konten yang diunggah pada website tersebut diakses oleh publik secara ekstensif dan berkelanjutan, maka peru ditindaklajuti terkait kemampuan website dalam sisi keamanan informasi untuk dapat beroperasi optimal. Website tersebut harus terjamin keamanannya. Penelitian ini bertujuan untuk mengaudit keamanan informasi pada website staklimyogyakarta.com menggunakan tool NMap (Network Mapper) dan Qualys SSL Labs. Nmap membantu menemukan dan memvisualisasikan konektivitas jaringan dengan membuat peta jaringan. Peta ini berisi diagram jaringan, diagram alur, inventaris perangkat, dan deteksi topologi dan Qualys SSL Labs memberikan kumpulan dokumen, alat, dan pemikiran yang terkait dengan SSL. Hasil pengujian menggunakan NMap menunjukkan bahwa pada website staklimyogyakarta.com terdapat 17 port yang terbuka dengan 2 port diantaranya berstatus filtered dan 983 port tertutup dari 1000 port yang berhasil discan pada website Stasiun Klimatologi D.I. Yogyakarta. Hasil menggunakan Qualys SSL Labs menunjukkan website Stasiun Klimatologi D.I. Yogyakarta telah memiliki sertifikat SSL dan skor SSL yang didapat adalah A. Dengan status nonaktif pada SSL versi 2 dapat meningkatkan keamanan dari serangan DROWN melalui protokol SSL/TLS namun terdapat kerentanan pada 17 port terbuka.

Page 57 of 131 | Total Record : 1305