Filter By Year

1945 2024


Found 1,304 documents
Search KEAMANAN INFORMASI

Risk Assessment Keamanan Informasi dengan Menggunakan ISO/IEC 27001: Studi Kasus PT Dyandra Promosindo Putra, Mahansa; Aji, Rizal Fathoni
J-SAKTI (Jurnal Sains Komputer dan Informatika) Vol 8, No 1 (2024): EDISI MARET
Publisher : STIKOM Tunas Bangsa Pematangsiantar

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.30645/j-sakti.v8i1.775

Abstract

PT Dyandra Promosindo is a company that operates in the event organizer sector, when carrying out their daily business processes they will always be in contact with important information from their clients. Therefore, it is necessary to carry out a risk assessment to avoid loss of confidentiality, integrity and availability of an information asset. The author wants to know how big the risk impact that threatens the security of information assets and provide control recommendations over these assets. The risk assessment process can be divided into three stages, namely, risk identification through interviews and document review, risk analysis using asset valuation and vulnerability and threat ratings, and finally risk evaluation using risk impact measurements. The results of this research showed that 10 critical information assets were identified and only 1 was in the Tolerable risk mitigation group where the other assets were in the Acceptable group. Recommendations for controls for PT Dyandra Promosindo information assets risk based on Annex A ISO/IEC 27001:2022 show 15 controls consisting of 4 Organizational control, 5 People control, 1 Physical control, and 5 Technological control
Evaluasi Keamanan Informasi Menggunakan ISO/IEC 27001: Studi Kasus PT XYZ Fatih, Dayyan; Aji, Rizal Fathoni
J-SAKTI (Jurnal Sains Komputer dan Informatika) Vol 8, No 1 (2024): EDISI MARET
Publisher : STIKOM Tunas Bangsa Pematangsiantar

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.30645/j-sakti.v8i1.767

Abstract

PT XYZ is one of the government-owned enterprises of the Republic of Indonesia that engaged in agribusiness. PT XYZ already has an information security management system (ISMS), but there are still several obstacles that are found, such as low personnel attention to information security, the need to remain compliant with government regulations, to technical constraints that arise, so PT XYZ wants to improve its information security-related capabilities. This study aims to determine the current condition of the existing ISMSĀ  at PT XYZ and provide recommendations for improving the ISMS. This research uses information security controls based on the ISO/IEC 27001: 2022 standard to get the information security condition gap, then divides the information technology (IT) assets owned by the IT division of PT XYZ into several categories using the ISO/IEC 27005: 2018 standard, and conducts a risk assessment using the gap result data, namely the selected information security controls. Then recommendations were made based on the ISO/IEC 27002:2022 standard. The findings of this study were the discovery of 17 ISO/IEC 27001:2022 control activities whose value results were not maximised. These 17 controls are then divided into 3 categories of recommendations based on the urgency, from the results of the risk assessment.
Peran Manajemen Persuratan Dalam Menjaga Keamanan Informasi Persuratan Tengku Darmansah; Indra Wahyudi Z; Nurul Mupida Lubis; Raudhatul Jannah; Tiara Amanda
Jurnal Pendidikan Sosial Dan Konseling Vol. 2 No. 1 (2024): April - Juni
Publisher : CV. ITTC INDONESIA

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.47233/jpdsk.v2i1.970

Abstract

Manajemen persuratan merupakan aspek penting dalam menjaga keamanan informasi di dalam organisasi. Dokumen-dokumen yang dikirim dan diterima melalui surat menyurat mengandung informasi yang sensitif dan rahasia, sehingga perlu dikelola dengan baik untuk mencegah kebocoran atau penyalahgunaan informasi. Peran manajemen persuratan mencakup pengaturan alur surat, penyimpanan dokumen, pembatasan akses, serta prosedur pengiriman dan penerimaan surat. Dengan manajemen persuratan yang efektif, organisasi dapat melindungi informasi penting dari ancaman internal maupun eksternal, sehingga menjaga kerahasiaan, integritas, dan ketersediaan informasi. Selain itu, manajemen persuratan yang baik juga dapat meningkatkan efisiensi proses administrasi dan komunikasi dalam organisasi. Oleh karena itu, penerapan manajemen persuratan yang komprehensif merupakan strategi penting dalam menjaga keamanan informasi persuratan di dalam organisasi.
Uji kerentanan keamanan pada web Sistem Informasi Akademik Satya Wacana menggunakan metode Vulnerability Assessment Efendi, Rissal; Wahyono, Teguh; Widiasari, Indrastanti R.
AITI Vol 21 No 1 (2024)
Publisher : Fakultas Teknologi Informasi Universitas Kristen Satya Wacana

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24246/aiti.v21i1.44-57

Abstract

Vulnerability assessment is a process to look for system security gaps that can cause information technology process system failure. In carrying out a vulnerability assessment there are three main stages, namely information collection, assessment and exploit using the Greybone Openvas tool with a Full Scan template on the object and several credentials provided by a website. From the vulnerability assessment process, five vulnerabilities were found on assets, namely critical risk with a few 0, high risk with a few 2, medium risk with a few 2, and low risk with a few 1. Based on the conclusions from the vulnerability analysis the website and the results of identity verification, it was concluded that the website had a few weaknesses and vulnerabilities that needed to be fixed to maintain the security and quality of the website. Corrective actions on website configuration need to be taken such as setting cookies, SSL, HTTP headers, and others. SSL/TLS services do not accurately limit the renegotiation stage of the system, making it easier for attackers to carry out Denial of Service attacks by carrying out many renegotiations in one connection.
Kematangan risiko keamanan informasi layanan TI menggunakan pendekatan NIST dan standar ISO 27001:2013 (Studi kasus: Bapenda Provinsi Jawa Tengah) Aminudin, Agus; Supriyanto, Aji
AITI Vol 21 No 2 (2024)
Publisher : Fakultas Teknologi Informasi Universitas Kristen Satya Wacana

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24246/aiti.v21i2.210-229

Abstract

The application of Information Technology (IT) often poses risks, such as incorrect application processes, data theft and data corruption. With the increasing risk, greater control is needed. For this reason, it is necessary to see whether the running system is equipped with adequate control. The Regional Revenue Management Agency (BAPENDA) of Central Java Province has utilized IT in its activities. The absence of adequate information security standards impacts data or information that is less secure, both in terms of confidentiality, integrity, and availability. The aims and objectives of the research are to measure KAMI risk maturity, such as conducting an IT assessment managed by BAPENDA. For example, vehicle tax payment service application, Android (New Sakpole), and IT infrastructure. The results of KAMI Maturity Level at BAPENDA in security policy clauses were 0.76, organization KAMI 1.24, control asset classification 0.63, personnel security 1.12, incident management KAMI 1.21, business continuity management 0.51, physical and environmental security 1.61, system development and maintenance 2.94, access control 4.18, communications and operations management 4.58 and, compliance 2.07. Mapping asset identification with NIST-CSF obtained several assets: hardware, software, employee, and information/data. The results show that assets in BAPENDA have a high risk (High) Risk Avoidance, so they require mitigation using NIST controls and Annex ISO-IEC 27001:2013.
Pengukuran Kematangan Keamanan Siber pada Perusahaan Teknologi Informasi dengan Framework Center for Internet Security Controls Jauhari, Mohammad Afdhal; Wardijono, Bheta Agus; Hegarini, Ega
Jurnal Saintekom : Sains, Teknologi, Komputer dan Manajemen Vol 14 No 1 (2024): Maret 2024
Publisher : STMIK Palangkaraya

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.33020/saintekom.v14i1.610

Abstract

This research evaluates the cybersecurity maturity of a technology information company in Jakarta, using the CIS Controls framework that encompasses all controls within Implementation Group 1 (IG1). The company has not conducted formal measurements regarding cybersecurity maturity, leading to uncertainty about the effectiveness of security efforts. The aim of this study is to measure, assess, and provide recommendations to enhance cybersecurity within the company. The research methodology involves an assessment of CIS Controls implementation and maturity level measurements. The measurement results indicate a low level of maturity, with an overall score of 0.41. The company needs to make significant improvement efforts in the cybersecurity aspect. Recommendations derived from this analysis emphasize the need for policy enhancements, control improvements, and increased employee training, serving as a guide for the company to strengthen weak cybersecurity aspects. The company should adopt a sustainable approach with management commitment and active engagement of all stakeholders.
Meningkatkan Keamanan Informasi melalui Sustainable IT Capabilities: Studi tentang Integrasi Information Security Management dalam Organisasi Suhartono, Bambang; Asbari, Masduki
Journal of Information Systems and Management (JISMA) Vol. 3 No. 1 (2024): February 2024
Publisher : AGUSPATI RESEARCH INSTITUTA

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.4444/jisma.v3i1.1120

Abstract

This study explores the relationship between sustainable IT capabilities and ISM Assimilation (Information Security Management Assimilation) in organizations. By focusing on the three main Sustainable IT Capabilities, namely IT Infrastructure, IT Business Spanning Capability (widespread IT business capabilities), and IT Proactive Stance (IT's proactive attitude), this research investigates how these three capabilities influence the integration of ISM practices in the organizational context. Data collected from 157 upper management level employees in several companies in Indonesia that implemented ISM were analyzed using structural equation modeling. Data were analyzed using SEM PLS and SmartPLS 4.0 software. The research results show that there is a positive influence of sustainable IT capabilities on ISM Assimilation. So the three factors of sustainable IT capabilities, namely: IT Infrastructure, IT Business Spanning Capability, and IT Proactive Stance have a positive effect on ISM Assimilation. These findings provide valuable insights for organizational leaders and business owners to develop sustainable IT strategies that improve information security and promote the assimilation of ISM practices for sustainable asset management.
Persepsi Kemudahan, Kegunaan, Keamanan, dan Kerahasiaan terhadap Minat Wajib Pajak Orang Pribadi dalam Menggunakan E-Filing dengan Kesiapan Teknologi Informasi Sebagai Variabel Moderating pada KPP Pratama Serang Barat Gemilang, Sandra; Lestari, Dini Martinda; Afriani, Raden Irna
EKALAYA : Jurnal Ekonomi Akuntansi Vol. 2 No. 3 (2024): Ekalaya : Jurnal Ekonomi Akuntansi
Publisher : CV. Kalimasada Group

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59966/ekalaya.v2i3.1195

Abstract

The purpose of this research is to analyze the effect of perceived ease of use, usefulness, security, and confidentiality on the interest of individual taxpayers in using E-Filing, with information technology readiness as a moderating variable. Many individual taxpayers still face challenges in using E-Filing, such as technology access, understanding of use, and lack of socialization and education about the benefits of E-Filing. This research uses an associative and descriptive quantitative method with 100 taxpayer respondents. Data analysis was carried out using the Structural Equation Modeling (SEM) method using SmartPLS 3.2.9 software. The results of hypothesis testing indicate that perceived ease of use and usefulness have a significant effect on taxpayers' interest in using E-Filing. However, perceptions of security and confidentiality do not have a significant effect. Moreover, perceptions of ease of use, usefulness, security, and confidentiality do not have a significant effect on information technology readiness. In conclusion, perceptions of ease of use and usefulness affect taxpayers' interest in using E-Filing, while security and confidentiality do not have an effect. Information technology readiness does not moderate the effect of perceptions of ease of use, usefulness, security, and confidentiality on taxpayers' interest in using E-Filing.
IMPLEMENTASI UU PERLINDUNGAN DATA PRIBADI TERHADAP KEAMANAN INFORMASI IDENTITAS DI INDONESIA Mahameru, Danil Erlangga; Nurhalizah, Aisyah; Badjeber, Haikal; Wildan, Ahmad; Rahmadia, Haikal
Esensi Hukum Vol 5 No 2 (2023): Desember - Jurnal Esensi Hukum
Publisher : Fakultas Hukum Universitas Pembangunan Nasional "Veteran" Jakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.35586/esensihukum.v5i2.240

Abstract

The growth of information and communication technologies. The main obstacle that arises safeguards personal information and privacy amidst technological sophistication. The biggest challenge is developing an effective regulatory framework to protect individual privacy while facilitating technological innovation. Both the public and private sectors must exhibit significant endeavors to overcome this problem. Examining all laws and regulations pertaining to Personal Data Protection, this study employs a legislative approach, namely through the 1945 Constitution, Personal Data Protection Regulation No. 20 of 2016, Law No. 11 of 2008 Concerning Electronic Information and Transactions, and Law No. 27 of 2022 Asserting the Authority of the Minister of Communication and Information. Implementation of the Personal Data Protection Law is an important step to orderly implement regulations and prevent legal uncertainty. Delays in issuing implementing regulations can create legal uncertainty and obstruct the fulfillment of the Law's goals.
Pentingnya Kepatuhan Keamanan Informasi Dalam Mengurangi Risiko Data Breach Ripa Sabila Usni Sitompul; Muhammad Irwan Padli Nasution
Maeswara : Jurnal Riset Ilmu Manajemen dan Kewirausahaan Vol. 2 No. 1 (2024): FEBRUARI : Maeswara
Publisher : Asosiasi Riset Ilmu Manajemen Kewirausahaan dan Bisnis Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.61132/maeswara.v2i1.587

Abstract

This research aims to find out how vital information security compliance is in reducing the risk of Data Breach. The method used in this research is Library Research (Library) which is the method used in this writing, and in its use, this method uses books, and journals both in written form and online. Based on the results obtained from this research, it can be concluded that a Data Breach is an incident where sensitive data or important information becomes vulnerable or is accessed by unauthorized parties. To prevent a Data Breach, organizations need to take various security measures, policies, and practices, such as encryption, access management, physical security, network security, security training and awareness, security policies, and monitoring and auditing. Sensitive data protection helps maintain the confidentiality, integrity, and availability of data and protects the reputation and trust of customers and business partners. By implementing good sensitive data protection, organizations can reduce the risk of data breaches which can be financially detrimental and damage the company's image.

Page 80 of 131 | Total Record : 1304