2018Unpublished venueRequires access

The use of ISO/IEC 27001: 2009 to analyze the risk and security of information system assets: case study in xyz, ltd

Hendry Fajar Yoseviano, Astari Retnowardhani

Open publisher page 6 citations

Abstract

Information is one of the most valuable assets for the survival of an organization (company), government institution, and college. Information security aims to maintain the confidentiality, necessity and availability of information. As a fulfillment of the need for information on XYZ, Ltd that does not yet have guidelines relating to the information security process, as well as a lack of understanding of the risks of information loss and how to control information security risks. In this paper, risk management planning is implemented using ISO/IEC27001: 2009 framework for security of information system assets at XYZ, Ltd. Stages in the design process of the Information Security Management System (ISMS) include the determination of scope, risk analysis and the determination of control objects and security control. The results of this study are a security policy document, risk assessment, and ISMS procedures which will become a reference in the research and will facilitate the next stage of research.

About this research paper

What this paper is about

Information is one of the most valuable assets for the survival of an organization (company), government institution, and college. Information security aims to maintain the confidentiality, necessity and availability of information. As a fulfillment of the need for information on XYZ, Ltd that does not yet have guidelines relating to the information security process, as well as a lack of understanding of the risks of information loss and how to control information security risks. In this paper, risk management planning is implemented using ISO/IEC27001: 2009 framework for security of information system assets at XYZ, Ltd. Stages in the design process of the Information Security Management System (ISMS) include the determination of scope, risk analysis and the determination of control objects and security control. The results of this study are a security policy document, risk assessment, and ISMS procedures which will become a reference in the research and will facilitate the next stage of research.

Why it matters

OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Information is one of the most valuable assets for the survival of an organization (company), government institution, and college. Information security aims to maintain the confidentiality, necessity and availability of information. As a fulfillment of the need for information on XYZ, Ltd that does not yet have guidelines relating to the information security process, as well as a lack of understanding of the risks of information loss and how to control information security risks. In this paper, risk management planning is implemented using ISO/IEC27001: 2009 framework for security of information system assets at XYZ, Ltd. Stages in the design process of the Information Security Management System (ISMS) include the determination of scope, risk analysis and the determination of control objects and security control. The results of this study are a security policy document, risk assessment, and ISMS procedures which will become a reference in the research and will facilitate the next stage of research.

Key concepts: Information security management, Information security management system, Information security, Security management, Standard of Good Practice, Certified Information Security Manager, Security information and event management, Risk analysis (engineering)

Related papers

Back to paper searchBrowse research topicsOriginal source
The use of ISO/IEC 27001: 2009 to analyze the risk and security of information system assets: case study in xyz, ltd — Research Paper | ScholarLens