Analisis Risiko Keamanan Informasi pada Layanan Sertifikasi Elektronik Menggunakan Metode FMEA Berbasis ISO/IEC 27001:2022 (Studi Kasus: Dinas Komunikasi dan Informatika Provinsi Jawa Timur)

Tsabitah, Adinda Wira Zahra (2026) Analisis Risiko Keamanan Informasi pada Layanan Sertifikasi Elektronik Menggunakan Metode FMEA Berbasis ISO/IEC 27001:2022 (Studi Kasus: Dinas Komunikasi dan Informatika Provinsi Jawa Timur). Undergraduate thesis, UPN Veteran Jawa Timur.

[img] Text (Cover)
22082010231-cover_removed.pdf

Download (695kB)
[img] Text (Bab 1)
22082010231-bab 1.pdf

Download (3MB)
[img] Text (Bab 2)
22082010231-bab 2.pdf
Restricted to Repository staff only until 2029.

Download (25MB) | Request a copy
[img] Text (Bab 3)
22082010231-bab 3.pdf
Restricted to Repository staff only until 2029.

Download (19MB) | Request a copy
[img] Text (Bab 4)
22082010231-bab 4.pdf
Restricted to Repository staff only until 2029.

Download (24MB) | Request a copy
[img] Text (Bab 5)
22082010231-bab 5.pdf
Restricted to Repository staff only until 2029.

Download (1MB) | Request a copy
[img] Text (Daftar Pustaka)
22082010231-daftar pustaka.pdf

Download (3MB)
[img] Text (Lampiran)
22082010231-lampiran.pdf
Restricted to Repository staff only until 2029.

Download (5MB) | Request a copy

Abstract

Individual electronic certification services at the Department of Communication and Informatics of East Java Province are crucial for digital government administration; however, their processes entail the management of sensitive documents, user data, access privileges, and electronic signatures. The absence of a quantifiable risk assessment complicates the organization's ability to determine mitigation priorities. This study aims to analyze information security risks within these services utilizing the Failure Mode and Effect Analysis (FMEA) method based on ISO/IEC 27001:2022. The research methodology involves observation, interviews, documentary studies, and questionnaires distributed to 30 respondents. Risks were evaluated using Severity, Occurrence , and Detection parameters to compute the Risk Priority Number (RPN). The findings identified 20 information security risks, categorized into 5 very high, 5 high, 3 medium, 5 low, and 2 very low risks. The highest-ranked risk was weak, reused, or shared passphrases, with an RPN value of 252.0772. These results demonstrate that authentication aspects, user behavior, and account management constitute primary vulnerabilities. Control recommendations formulated based on ISO/IEC 27001:2022 Annex A encompass reinforcing passphrase policies, prohibiting account delegation, and drafting information security governance documentation to enhance service security sustainably. Keywords: FMEA, ISO/IEC 27001:2022, information security, electronic certification service, Risk Priority Number

Item Type: Thesis (Undergraduate)
Contributors:
ContributionContributorsNIDN/NIDKEmail
Thesis advisorMukaromah, SitiNIDN0004078106sitimukaromah.si@upnjatim.ac.id
Thesis advisorFaroqi, AsifNIDN0019058703asiffaroqi.si@upnjatim.ac.id
Subjects: T Technology > T Technology (General) > T58.6-58.62 Management Information Systems
Divisions: Faculty of Computer Science > Departemen of Information Systems
Depositing User: Adinda 22082010231 Tsabitah
Date Deposited: 22 Jul 2026 06:31
Last Modified: 22 Jul 2026 07:16
URI: https://repository.upnjatim.ac.id/id/eprint/55427

Actions (login required)

View Item View Item