scholarly journals Evaluasi Tingkat Kesiapan Keamanan Informasi Pada Lembaga Pendidikan Menggunakan Indeks Kami 4.0

2019 ◽  
Vol 1 (2) ◽  
pp. 53-62
Author(s):  
Pramudhita Ferdiansyah ◽  
Subektiningsih Subektiningsih ◽  
Rini Indrayani

Evaluasi keamanan sistem informasi sangat diperlukan bagi sebuah organisasi, instansi, maupun perusahaan guna mencegah kebocoran data ataupun kerusakan sistem informasi. Penelitian ini dilakukan di sektor pendidikan pada lembaga UPTD XYZ di bawah kuasa Dinas Pendidikan Provinsi Daerah Istimewa Yogyakarta. Evaluasi kematangan dan tata kelola keamanan informasi diterapkan berdasarkan standar ISO/IEC 27001:2017 dengan menggunakan indeks keamanan informasi KAMI versi 4.0. Metode pengumpulan data dilakukan dengan cara observasi langsung dan interview terhadap penanggungjawab sistem informasi. Hasil yang didapatkan dari evaluasi untuk kebutuhan sistem elektronik sebesar 20, sedangkan tingkat kelengkapan informasi mendapatkan skor 245. Dari hasil tersebut dapat disimpulkan bahwa tingkat keamanan informasi masih sangat rendah dan diperlukan perbaikan sistem keamanan informasi dengan bekerja sama dengan pengembang keamanan informasi dari pihak ketiga. Information system security evaluation is indispensable for an organization, agency, or company to prevent data leakage or damage to information systems. This research was conducted in the education sector at the UPTD XYZ institution under the authority of the Yogyakarta Provincial Education Office. Information security maturity and governance evaluation is implemented based on ISO / IEC 27001: 2017 standard by using the WE information security index version 4.0. The data collection method is done by direct observation and interviews with the person in charge of the information system. The results obtained from the evaluation for electronic system requirements were 20, while the level of completeness of information got a score of 245. From these results it can be concluded that the level of information security is still very low and it is necessary to improve information security systems in collaboration with information security developers from third parties.

2021 ◽  
Vol 4 (2) ◽  
pp. 115-130
Author(s):  
Yahya Dwi Wijaya

Information systems are a valuable asset for business actors, one of which is engaged in e-commerce. Pasdeal is a credit distributor and server service that implements an e-commerce information system. The use of information systems in the field of sales or electronic commerce is considered efficient because it has become a platform for media and services and new and unique capabilities that are not found in the physical world. Information security factor is a very important aspect to consider considering the performance of ICT governance. For this reason, information systems need an information security evaluation in order to find out the gaps and deficiencies in information security in the information system. The KAMI index is a reference tool to evaluate the level of readiness of information system security in an organization. Evaluation is carried out on various areas that are the target of information security implementation based on the ISO/IEC 27001:2013 standard. Based on the results of the KAMI index assessment, it was found that Pasdeal got a score of 591 points from the application of the ISO 27001 standard with a pretty good predicate.


Author(s):  
N. Baisholan ◽  
K.E. Kubayev ◽  
T.S. Baisholanov

Efficiency of business processes in modern organizations depends on the capabilities of applied information technologies. The article describes and analyzes the role and features of audit tools and other methodological tools and models in ensuring the quality and security of information systems. The standard’s principles are reviewed, as well as the importance of meeting business needs. In order to protect virtual values in a company’s system environment, the importance of using information security models is revealed. Practical proposals in risk management and information security in information technology are analyzed through the COBIT standard. Measures for protecting the information system of an organization from accidental, deliberate or fake threats are considered. The possibility of using one of the real information security models by the information recipient or provider in accordance with the requirements of external processes is reported. Furthermore, in connection with increase in the number of attack methods and techniques and development of their new tools and vectors, the need to improve and ways to ensure information security are being considered. The essential tasks of security audit are considered, and the stages of their implementation are described. With regard to security of information systems, an analytical model is proposed for determining vulnerability’s numerical value.


2019 ◽  
Vol 5 (1) ◽  
Author(s):  
I Gede Putu Krisna Juliharta

ABSTRACT e-Governement in Indonesia is a must this time. Good E-Governments certainly have the ability to provide good information to the public and fulfill aspects of confidentiality, integrity and availability, Kediri in East Java is one of the government that use e-Government. To measure these three aspects the system must be measured. Indeks KAMI (Keamanan Informasi) is an application that is used as a tool to analyze and evaluate the level of readiness (completeness and maturity) for implementing information security in an organization in accordance with SNI ISO / IEC 27001 criteria. Government of Kediri the score for the electronic system category was 20, for the governance assessment the score was 75, risk management score 18, the information security framework was 58, asset management 74, and the application of security and information technology had a value of 83, and the results measurement says the City Government of Kediri needs to improve the system management.<br />Keywords: Index, KAMI , Security, Information Technology<br />ABSTRAK Penerapan e-Governement dalam tata kelola Pemerintahan di Indonesia saat ini merupakan sebuah keharusan. E-Governement yang baik tentu memiliki kemampuan untuk memberikan Informasi yang baik kepada masyarakat dan memenuhi aspek kerahasiaan (confidentiality), keutuhan (integrity) dan ketersediaan (availability), Pemerintah Kota (Pemkot) Kediri adalah salah lembaga pemerintah yang menggunakan e-Government. Untuk mengukur ketiga aspek tersebut sistem haruslah diukur. Indeks KAMI (Keamanan Informasi) merupakan aplikasi yang digunakan sebagai alat bantu untuk menganalisa dan mengevalusi tingkat kesiapan (kelengkapan dan kematangan) penerapan keamanan informasi di sebuah organisasi sesuai dengan kriteria pada SNI ISO/IEC 27001. Untuk Pemkot Kediri didapatkan skor kategori sistem elektronik (SE) adalah 20, untuk penilaian tata kelola skornya adalah 75, pengelolaan resiko skornya 18, kerangka kerja keamanan informasi nilainya 58, pengelolaan asset 74, dan penerapan teknologi keamanan dan informasi memiliki nilai 83, dan hasil pengukuran menyebutkan Pemkot Kediri perlu meningkatkan system pengelolaan system yang dimiliki.<br />Kata Kunci : indeks, KAMI, keamanan, teknologi informas


The paper describes the development of the "Complex-analytical information system of scientific degrees" for electronic document exchange and digitization of the attestation process for scientific degrees in the field of attestation of highly qualified scientific and scientific-pedagogical personnel, modules that make up the system, their functions, also information security of the system, requirements for functions performed by the system, client-server architecture of data processing in information system.


Author(s):  
Lytvynov Vitalii ◽  
Mariia Dorosh ◽  
Iryna Bilous ◽  
Mariia Voitsekhovska ◽  
Valentyn Nekhai

Relevance of the research. Ensuring the effectiveness of the information security systems requires creation of an appropriate information security culture for the employees of the organization in order to reduce human-related risks. Target setting. The techniques currently available for assessing information security risk are excluded as a source of the potential vulnerability. Considering the role of the personnel in the organization's information security systems, there is a need to create automated systems of human-machine interaction assessment through the level of the personnel information security culture, and to determine the integral indicator of the organization's information security culture. Actual scientific researches and issues analysis. Open access publications on the problems of integrating the information security culture into the corporate culture of the organization as a tool for ensuring the proper information security level of business processes are considered. Uninvestigated parts of general matters defining. The absence of formalized models for assessing the organization's information security culture level, as well as an automated process for its assessing were revealed by source analysis. The research objective. The purpose of the article to build a model that describes the process of obtaining an organization's information security culture level assessment in IDEF0 notation. Then, to create an architecture and database for system of information security culture assessment to support the general organization's information security system. The statement of basic materials. According to functional requirements, a conceptual model of «The organization`s ISC level determination» development process was created. Input information, governing elements, execution elements and mechanism, and output information were defined. To accomplish these tasks, an architecture and database of information system for assessing the information security culture level of the organization were proposed. Conclusions. The functional model of top-level development process was proposed. Formed functional requirements became the basis for development of information system architecture with description of its modules and database structure.


2019 ◽  
Vol 12 (1) ◽  
pp. 51-55
Author(s):  
Nurhafifah Matondang ◽  
Bayu Hananto ◽  
Catur Nugrahaeni

The University has a number of data relating to Academic and Higher Education Governance. The large amount of data that requires security, especially in terms of readiness to secure information systems. Maintaining information system security in the university environment aims to maintain confidentiality, fulfill the availability of the system for those who have authority for those who use it and the integrity of the system. The University of National Development "Veteran" Jakarta has work units such as the Faculty, UPT and Bureau where each has the task and function to manage data. The problem is the need to measure the level of information system security to see the maturity of an information system at UPN Veteran Jakarta. OUR Index stands for Information Security Index which is used as a tool to analyze and measure and evaluate the maturity level of information security with the application of SNI ISO / IEC 27001: 2009 standards that can be applied within government agencies. As for the KAMi index version used, namely version 3.1. The method used to solve the problems in OUR index is through six stages, namely the first stage of electronic systems, both information security governance, third information security risk management, the four information security management frameworks, the five asset information management and the six information security technologies. The results obtained after taking measurements using the US Index need improvement in system security in managing information security risks and governance.


2021 ◽  
Vol 11 (2) ◽  
pp. 55-62
Author(s):  
Andi Sofyan Anas ◽  
◽  
I Gusti Ayu Sri Devi Gayatri Utami ◽  
Adam Bachtiar Maulachela ◽  
Akbar Juliansyah ◽  
...  

XYZ University is one of the universities that has used information technology to create quality service for students and the entire academic community. This Information technology service is managed by Information Technology and Communication Center (PUSTIK) which is responsible to carry out the development, management, service, and maintaining the security of information and communication technology. Good information technology governance should be able to maintain information security. Therefore, it is necessary to evaluate information system security especially the security of academic information systems. This information system security evaluation uses Keamanan Informasi (KAMI) Index which refers to the ISO/IEC 27001:2013 standard to be able to determine the maturity level of information security. An evaluation of five areas of the KAMI Index shows the Information Security Risk Management area gets the lowest score at 10 out of a total of 72. The result of the KAMI Index dashboard shows that the maturity level of each area of information security is at levels I and I+ with a total score of 166. This means that the level of completeness of implement ISO 27001:2013 standard is in the inadequate category.


2019 ◽  
Vol 3 (1) ◽  
pp. 162-171
Author(s):  
Muhammad Ramadhan Slamet ◽  
Febrina Wulandari ◽  
Diah Amalia

As an electronic learning system organizer State Polytechnic of Batam (Polibatam) must arrange secured electronic learning system. Ministry of Communication and Information of Indonesia expects the organizations which arrange electronic system can perform SNI ISO 27001 certification related to information security. Information security condition on organizations which will perform on certifiation is expected on maturity level at III+ (Directorate of Information Security Team, 2011). On the other hand, there is a gap between expected conditon and actual condition. Information security index (KAMI) is a tool to assess the implementation of information security that has been done. This research is assessed related to technology component because of high dependency of organization on technology. The purpose of research is to identify how far the security of technology at State Polytechnic of Batam by using information security index. Based on research, electronic learning system that is organized by State Polytechnic of Batam is low categorized. The total percentage is 65 or 54,17% out of maximum percentage. Therefore, the maturity level of technology security is on maturity level II which means the maturity level of technology security is under the expected maturity level for minimum readiness certification on III+. It is caused the position of State Polyetechnic of Batam is on a organizational development stage. Moreover, the focus of organization is related on operational, not strategic.


TRIKONOMIKA ◽  
2018 ◽  
Vol 17 (1) ◽  
pp. 28
Author(s):  
Akmal Zaifullah Maingak ◽  
Candiwan Candiwan ◽  
Listyo Dwi Harsono

The purpose of this research is to determine the existing gap to achieve ISO/IEC 27001:2013 certification and determine the maturity level of the information system owned by X Government Institution. The information system of X Government Institution would be assessed based on 14 clauses contained in ISO/IEC 27001: 2013. The method used is qualitative method, data collection and data validation with triangulation technique (interview, observation, and documentation). Data analysis used gap analysis and to measure the maturity level of this research used CMMI (Capability Maturity Model for Integration). The result of the research showed that information security which had been applied by X Government Institution was at level 1 (Initial) which meant there was evidence that the institution was aware of problems that needed to be overcome, unstandardized process, and tended to handle the problem individually or by case.


Sign in / Sign up

Export Citation Format

Share Document