CD Skripsi
Analisis Manajemen Risiko Kemanan Sistem Informasi Pada Portal Akademik Universitas Riau Menggunakan Standar Iso/Iec 27005:2018
Information systems and technology act as tools for companies to make work easier. One very important aspect in information systems is information security. Information security is carried out to protect assets, especially data and information at the University of Riau (UR). Data and information have become important assets in an organization because they are related to the organization's image. Currently, the academic information system at Riau University is being built online, giving rise to various possible threats. Threats can arise from inside or outside the system which can disrupt organizational goals if they are not used competently and according to guidelines. Academic portals often cause problems that pose risks, such as server downtime and irresponsible parties accessing the system. However, there is no document specifically for managing these risks. Therefore, the target of this research is to obtain analysis results regarding information system security risk management on the Riau University Academic Portal using the ISO/IEC 27005:2018 standard. This research was carried out in 4 (four) stages, namely planning, data collection, data analysis, and the final stage of recommendation. The results of this research are that there are 8 (eight) categories of information system assets, 30 (thirty) identified threats, 43 (forty- three) vulnerabilities with 2 (two) high level category risks, 19 (nineteen) medium level risks and 22 (twenty-two) with low levels. Of the 43 (forty-three) threat scenarios, there are 21 (twenty-one) risks that involve risk modification, 4 (four) risks that involve risk avoidance, and 4 (four) risks that involve risk sharing. By implementing control recommendations based on ISO/IEC 27001, you can minimize and handle risks on the Riau University Academic Portal.
Keywords: ISO/IEC 27001:2013, ISO/IEC 27005:2018, Information system
security, Risk Management, Academic Portal, Universitas Riau
Tidak tersedia versi lain