The use of ISO/IEC 27001: 2009 to analyze the risk and security of information system assets: case study in xyz, ltd
Hendry Fajar Yoseviano, Astari Retnowardhani
Abstract
Hendry Fajar Yoseviano, Astari Retnowardhani
Abstract
Information is one of the most valuable assets for the survival of an organization (company), government institution, and college. Information security aims to maintain the confidentiality, necessity and availability of information. As a fulfillment of the need for information on XYZ, Ltd that does not yet have guidelines relating to the information security process, as well as a lack of understanding of the risks of information loss and how to control information security risks. In this paper, risk management planning is implemented using ISO/IEC27001: 2009 framework for security of information system assets at XYZ, Ltd. Stages in the design process of the Information Security Management System (ISMS) include the determination of scope, risk analysis and the determination of control objects and security control. The results of this study are a security policy document, risk assessment, and ISMS procedures which will become a reference in the research and will facilitate the next stage of research.
OpenAlex reports 6 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Information is one of the most valuable assets for the survival of an organization (company), government institution, and college. Information security aims to maintain the confidentiality, necessity and availability of information. As a fulfillment of the need for information on XYZ, Ltd that does not yet have guidelines relating to the information security process, as well as a lack of understanding of the risks of information loss and how to control information security risks. In this paper, risk management planning is implemented using ISO/IEC27001: 2009 framework for security of information system assets at XYZ, Ltd. Stages in the design process of the Information Security Management System (ISMS) include the determination of scope, risk analysis and the determination of control objects and security control. The results of this study are a security policy document, risk assessment, and ISMS procedures which will become a reference in the research and will facilitate the next stage of research.
Key concepts: Information security management, Information security management system, Information security, Security management, Standard of Good Practice, Certified Information Security Manager, Security information and event management, Risk analysis (engineering)