Information System Risk Scenario Using COBIT 5 for Risk And NIST SP 800-30 Rev. 1 A Case Study
Yose Supriyadi, Charla Wara Hardani
Abstract
Yose Supriyadi, Charla Wara Hardani
Abstract
The use of Risk Scenario is key to risk management. From the IT security perspective, risk management is the process of understanding and responding to factors that may lead to a failure in information security of an information system. Risk Scenario needs to be built as a starting point to conduct its risk assessment. Risk Assessment is an essential component of risk management to define appropriate response or security control to handle risk. Risk assessment which involves an understanding of possible risk, knowledge of likely risks and threats, measured assessments of established controls and executed plans to address identified vulnerabilities. To resume the result from risk assessment process in COBIT 5 for Risk known as risk scenario document. This paper discusses how to create a Risk Scenario on a critical application system owned by a government agency as a case study. While NIST SP 800-30 Revision 1 to fulfill risk assessment process. The result is a Risk Scenario document and can be used as a starting point for implementing comprehensive risk management COBIT 5 for Risk framework.
OpenAlex reports 15 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The use of Risk Scenario is key to risk management. From the IT security perspective, risk management is the process of understanding and responding to factors that may lead to a failure in information security of an information system. Risk Scenario needs to be built as a starting point to conduct its risk assessment. Risk Assessment is an essential component of risk management to define appropriate response or security control to handle risk. Risk assessment which involves an understanding of possible risk, knowledge of likely risks and threats, measured assessments of established controls and executed plans to address identified vulnerabilities. To resume the result from risk assessment process in COBIT 5 for Risk known as risk scenario document. This paper discusses how to create a Risk Scenario on a critical application system owned by a government agency as a case study. While NIST SP 800-30 Revision 1 to fulfill risk assessment process. The result is a Risk Scenario document and can be used as a starting point for implementing comprehensive risk management COBIT 5 for Risk framework.
Key concepts: COBIT, Risk management, IT risk management, Risk analysis (engineering), Risk management framework, Risk assessment, Factor analysis of information risk, Risk management information systems