Analisis Resiko Keamanan Informasi Website Repository Digital Library Menggunakan Framework ISO/IEC 27001 & 27002: Studi Kasus Perguruan tinggi X

Jenyta Primaranti, Aulia Faradilla Setyowardhani, Ida Nurlela, Valerian Ghrandiaz, Yulhendri Yulhendri
{"title":"Analisis Resiko Keamanan Informasi Website Repository Digital Library Menggunakan Framework ISO/IEC 27001 & 27002: Studi Kasus Perguruan tinggi X","authors":"Jenyta Primaranti, Aulia Faradilla Setyowardhani, Ida Nurlela, Valerian Ghrandiaz, Yulhendri Yulhendri","doi":"10.59653/jimat.v2i01.500","DOIUrl":null,"url":null,"abstract":"The continuous evolution of digital repositories in the era of globalization, especially in context of higher education digital libraries, poses security risks that raise concerns among users. Existence of sensitive user data that requires protection by universities adds to this concern. This research aims to conduct comprehensive analysis of information security risks associated with digital library repository websites. This research seeks to identify potential vulnerabilities, threats that could compromise the confidentiality, integrity and availability of digital assets stored in repositories. Through detailed risk analysis, this research provides actionable insights and recommendations to improve the information security posture of digital libraries using the ISO/IEC 27001 and 27002 IT governance framework specifically tailored to information security standards. This research uses a literature review and interviews with responsible parties at the University of X's digital library repository. Findings show that the use of tools such as Acunetix helps identify vulnerabilities in web repositories. Risk mitigation in digital library web repositories involves the application of ISO/IEC 27001, 27002 standards, which results in specific risk mitigation actions. For example, universities should create policies to monitor information technology assets, ensuring regular monitoring to protect technology assets. In addition, for Database Management System (DBMS) management (e.g., MySQL, PostgreSQL, Oracle, Ms SQL Server), colleges must facilitate easy access and storage of information. By implementing the recommendations obtained from this research, higher education institutions can ensure safe environment for users accessing digital library web repositories, thereby reducing concerns about the security of their information.","PeriodicalId":304042,"journal":{"name":"Jurnal Riset Multidisiplin dan Inovasi Teknologi","volume":"11 23","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2023-12-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Jurnal Riset Multidisiplin dan Inovasi Teknologi","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.59653/jimat.v2i01.500","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The continuous evolution of digital repositories in the era of globalization, especially in context of higher education digital libraries, poses security risks that raise concerns among users. Existence of sensitive user data that requires protection by universities adds to this concern. This research aims to conduct comprehensive analysis of information security risks associated with digital library repository websites. This research seeks to identify potential vulnerabilities, threats that could compromise the confidentiality, integrity and availability of digital assets stored in repositories. Through detailed risk analysis, this research provides actionable insights and recommendations to improve the information security posture of digital libraries using the ISO/IEC 27001 and 27002 IT governance framework specifically tailored to information security standards. This research uses a literature review and interviews with responsible parties at the University of X's digital library repository. Findings show that the use of tools such as Acunetix helps identify vulnerabilities in web repositories. Risk mitigation in digital library web repositories involves the application of ISO/IEC 27001, 27002 standards, which results in specific risk mitigation actions. For example, universities should create policies to monitor information technology assets, ensuring regular monitoring to protect technology assets. In addition, for Database Management System (DBMS) management (e.g., MySQL, PostgreSQL, Oracle, Ms SQL Server), colleges must facilitate easy access and storage of information. By implementing the recommendations obtained from this research, higher education institutions can ensure safe environment for users accessing digital library web repositories, thereby reducing concerns about the security of their information.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
使用 ISO/IEC 27001 和 27002 框架分析数字图书馆资源库网站的信息安全风险:X 学院案例研究
全球化时代数字资料库的不断发展,尤其是高等教育数字图书馆的发展,带来了安全风险,引起了用户的担忧。而需要高校保护的敏感用户数据的存在,更加剧了这种担忧。本研究旨在全面分析与数字图书馆资源库网站相关的信息安全风险。本研究旨在找出潜在的漏洞,以及可能危及存储在资源库中的数字资产的保密性、完整性和可用性的威胁。通过详细的风险分析,本研究提供了可操作的见解和建议,以利用专门为信息安全标准定制的 ISO/IEC 27001 和 27002 IT 治理框架改善数字图书馆的信息安全状况。本研究采用文献综述和对 X 大学数字图书馆存储库负责人的访谈。研究结果表明,使用 Acunetix 等工具有助于识别网络存储库中的漏洞。数字图书馆网络存储库的风险缓解涉及到 ISO/IEC 27001 和 27002 标准的应用,从而产生具体的风险缓解行动。例如,大学应制定监控信息技术资产的政策,确保定期监控以保护技术资产。此外,对于数据库管理系统(DBMS)的管理(如 MySQL、PostgreSQL、Oracle、Ms SQL Server),高校必须方便信息的访问和存储。通过实施本研究获得的建议,高等院校可以确保用户访问数字图书馆网络资料库的安全环境,从而减少对其信息安全的担忧。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Creation of Accessories Shape of Buffalo Head with Source of Ideas for Unan-Unan Ceremony Using Waste Techniques Creation Source of Unan-unan Offering Ideas with Computer Embroidery Techniques Using Suede Fabric on the Vest Analisis Potensi Equator Park Dalam Meningkatkan Kesejahteraan Masyarakat Di Desa Jeruju Besar Sistem Sosial dan Ekologi Pantai Batu Pinagut Peningkatan Hasil Belajar IPA Siswa Kelas V Materi Perpindahan Kalor Melalui Model Cooperative Learning Type STAD di SDN Cinere 1 Depok
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1