Analisis Risiko Terhadap Sistem Manajemen Keamanan Informasi (SMKI) Diskominfo Jatim Menggunakan ISO/IEC 27001:2022

Abimanyu, Pramudya and Aurabillah, Bilqis and Firmansyah, Adrian Noval (2025) Analisis Risiko Terhadap Sistem Manajemen Keamanan Informasi (SMKI) Diskominfo Jatim Menggunakan ISO/IEC 27001:2022. Project Report (Praktek Kerja Lapang dan Magang). UPN Veteran Jawa Timur. (Unpublished)

[img] Text (Cover)
Cover.pdf

Download (1MB)
[img] Text (Bab1)
Bab1.pdf

Download (105kB)
[img] Text (Bab2)
Bab2.pdf

Download (1MB)
[img] Text (Bab3)
Bab3.pdf
Restricted to Repository staff only until 20 July 2029.

Download (300kB)
[img] Text (Bab4)
Bab4.pdf
Restricted to Repository staff only until 20 July 2029.

Download (410kB)
[img] Text (Bab5)
Bab5.pdf
Restricted to Repository staff only until 20 July 2029.

Download (122kB)
[img] Text (Daftar pustaka)
Daftar pustaka.pdf

Download (149kB)
[img] Text (Lampiran)
Lampiran.pdf
Restricted to Repository staff only

Download (2MB)

Abstract

nformation security is a crucial aspect in supporting digital-based government services. In line with this, the East Java Provincial Communication and Information Agency, as the public information management agency, needs to ensure that the systems implemented comply with international standards. This report analyzes the risks to the Information Security Management System (ISMS) to support readiness for ISO/IEC 27001:2022 recertification. The analysis was conducted through the identification of information assets, the determination of threats and vulnerabilities, and the assessment of risk levels based on a combination of impact and likelihood. The evaluation was carried out in accordance with the ISO/IEC 27001 approach and the mapping of controls in Annex A, which covers the domains of organizational, people, physical, and technological. Out of the 20 assets analyzed, five risks were identified that require mitigation as they exceed the tolerance threshold. The results of this activity produced recommendations for information security management to strengthen controls over high-risk assets. These recommendations are expected to support the effectiveness of the Information Security Management System (ISMS) and assist in the ISO/IEC 27001:2022 recertification process at the East Java Communication and Information Office.

Item Type: Monograph (Project Report (Praktek Kerja Lapang dan Magang))
Contributors:
ContributionContributorsNIDN/NIDKEmail
Thesis advisorWulansari, AnitaNIDN0715108705anita.wulansari.sisfo@upnjatim.ac.id
Subjects: Q Science > QA Mathematics > QA76.9 .A25 Computer Security
Divisions: Faculty of Computer Science > Departemen of Information Systems
Depositing User: noval firmansyah
Date Deposited: 21 Jul 2026 01:55
Last Modified: 21 Jul 2026 01:55
URI: https://repository.upnjatim.ac.id/id/eprint/56662

Actions (login required)

View Item View Item