Evaluation Of IS Risk Management Using Octave Allegro In Education Division

J. Suroso, Sri Mumpuni Ngesti Rahaju, Kusnadi
{"title":"Evaluation Of IS Risk Management Using Octave Allegro In Education Division","authors":"J. Suroso, Sri Mumpuni Ngesti Rahaju, Kusnadi","doi":"10.1109/ICOT.2018.8705866","DOIUrl":null,"url":null,"abstract":"Nowadays, information systems is an important point in supporting business strategies including in education division. Critical assets related to information systems are very susceptible to threats that can exploit and damage assets until they lead to disruption of business processes and even lead to financial losses. PT. Autocomp Systems Indonesia (PASI) has implemented Information Security Management System (ISMS) based on ISO / IEC 27001 to define a set of risk management strategies. However, some threats still occur and make the organization to get losses. The organization needs to conduct an evaluation of risk management that has been implemented to determine whether the risk protection strategy is adequate. Evaluation is done by comparing the current condition with the expected ideal condition using Catalogue of Practices from OCTAVE. The gaps found and then the risk assessment of the related assets is carried out. The results of this study indicate that the level of risk management maturity obtained by the organization is 89.40 %. The biggest gap is found in the contingency plan/disaster recovery plan and vulnerability management. Then a mitigation plan is proposed from the results of the risk assessment using the OCTAVE Allegro approach so the risk can be controlled properly.","PeriodicalId":402234,"journal":{"name":"2018 International Conference on Orange Technologies (ICOT)","volume":"37 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 International Conference on Orange Technologies (ICOT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICOT.2018.8705866","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Nowadays, information systems is an important point in supporting business strategies including in education division. Critical assets related to information systems are very susceptible to threats that can exploit and damage assets until they lead to disruption of business processes and even lead to financial losses. PT. Autocomp Systems Indonesia (PASI) has implemented Information Security Management System (ISMS) based on ISO / IEC 27001 to define a set of risk management strategies. However, some threats still occur and make the organization to get losses. The organization needs to conduct an evaluation of risk management that has been implemented to determine whether the risk protection strategy is adequate. Evaluation is done by comparing the current condition with the expected ideal condition using Catalogue of Practices from OCTAVE. The gaps found and then the risk assessment of the related assets is carried out. The results of this study indicate that the level of risk management maturity obtained by the organization is 89.40 %. The biggest gap is found in the contingency plan/disaster recovery plan and vulnerability management. Then a mitigation plan is proposed from the results of the risk assessment using the OCTAVE Allegro approach so the risk can be controlled properly.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
八度快板在教育部门IS风险管理中的应用评价
如今,信息系统是支持包括教育部门在内的企业战略的一个重要方面。与信息系统相关的关键资产非常容易受到威胁,这些威胁可以利用和破坏资产,直到导致业务流程中断,甚至导致财务损失。PT. Autocomp Systems Indonesia (PASI)已经实施了基于ISO / IEC 27001的信息安全管理系统(ISMS),以定义一套风险管理策略。然而,一些威胁仍然发生,使组织蒙受损失。组织需要对已实施的风险管理进行评估,以确定风险保护策略是否足够。评估是通过使用OCTAVE的实践目录将当前条件与预期的理想条件进行比较来完成的。发现差距,然后对相关资产进行风险评估。研究结果表明,该组织获得的风险管理成熟度水平为89.40%。最大的差距是在应急计划/灾难恢复计划和脆弱性管理方面。在此基础上,利用OCTAVE Allegro方法,根据风险评估结果,提出了相应的缓解方案,使风险得到有效控制。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Sentiment Analysis about E-Commerce from Tweets Using Decision Tree, K-Nearest Neighbor, and Naïve Bayes Design and Implementation of Sentence Similarity Matching and Multimedia Feedback for Intelligent Pharmacy on Zenbo Robot Motion Gesture Game for Measure Kinesthetic Level Design and Implementation of Cloud Service and APP for Drug-Drug Interaction The Effect Of Successful Enterprise Resource Planning (ERP) Systems On Employee Performance
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1