CD Skripsi
Analisis Manajemen Risiko Keamanan Informasi Menggunakan Standar Iso/Iec 27005:2022 Pada Upt Tik Universitas Riau
Information technology plays a critical role in transforming higher education services from non-digital to digital formats. At Universitas Riau, UPT TIK is responsible for managing various online application services across the rectorate, faculties, and institutional units. The main problem faced by UPT TIK UNRI is the failure to meet a 2024 strategic objective: the implementation of governance aligned with Good University Governance principles. This issue stems from the inadequate application of risk management practices, as documented in the Universitas Riau Strategic Plan 2020–2024. This research aims to develop a reference model for information security management based on the risk management framework defined in ISO/IEC 27005:2022, with ISO/IEC 27001:2022 as the supporting risk control measures. The research methodology star with planning, data collection, data analysis, and providing recommendations. The assessment identified 79 assets, categorized into 10 asset types, 24 threat events, and 71 vulnerabilities. Risk evaluation results indicate 1 high, 8 medium, 20 low, and 18 very low risks. Consequently, 15 mitigation recommendations were proposed to address 8 prioritized risks.
Keywords: ISO/IEC 27001:2022, ISO/IEC 27005:2022, Risk Management, UPT TIK UNRI, Universitas Riau
Tidak tersedia versi lain