scholarly journals Manajemen keamanan informasi menggunakan framework COBIT 5 dan ISO 27001:2013 dalam pembuatan dokumen standard operating procedure

Teknologi ◽  
2021 ◽  
Vol 11 (2) ◽  
pp. 59-74
Author(s):  
Juliet Regina Woda ◽  
◽  
Rahadian Bisma ◽  

This research to improve the quality of public services in accordance with the expectations of the community as service users. According to ISO 27001: 2013, an information security management system is an integrated part of an organizational process and in overall information security management in maintaining confidentiality, integrity and availability of information, managing and controlling security risks. information. To maintain consistency in providing optimal services, internal improvements need to be made to build a management system that will guarantee the quality of the education process according to the set standards. So, one of which is a standard that will become a reference in the form of an SOP (Standard Operating Procedure) on information security management. This research was conducted in Regional Financial and Aset Management Board (BPKAD) East Java Province. Therefore, this study proposes the making of SOP (Standard Operating Procedure) as a standard regarding information management using the Cobit 5 and ISO 27001:2013 framework. This study proposes the making of SOP (Standard Operating Procedure) as a standard regarding information management using the Cobit 5 and ISO 27001:2013 framework. This research will produce SOP documents that refer to Cobit 5 and ISO 27001: 2013 regarding information system security management. This research resulted, (1) document processing problems procedures; (2) aset management procedures; (3) server and network access room management system; (4) facility management procedures; (5) change management procedures; (6) management of capacity management procedures; (7) LOG management procedures; (8) management of service continuity procedures; (9) remote access management procedures; (10) backup management procedures.

2017 ◽  
Vol 11 (2) ◽  
pp. 41
Author(s):  
Muhammad Bakri ◽  
Nia Irmayana

Kantor bagian Program dan Pelaporan (Prolap) menggunakan beberapa sistem untuk melaporkan hasil pengawasan salah satunya Sistem Informasi Manajemen Hasil Pengawasan (SIMHP). Kompleksitas pada SIMHP harus dipandang dari berbagai sudut pandang, terutama aspek keamanan yang nantinya mendukung ketahanan aplikasi SIMHP tersebut. Salah satu pengendalian yang secara khusus mengedepankan faktor keamanan informasi saat ini adalah ISO (Intenational Organization for Standardization) 27001. ISO 27001 merupakan standar untuk mengaudit keamanan sebuah sistem informasi dan digunakan sebagai acuan untuk menghasilkan dokumen (temuan dan rekomendasi). ISO 27001 memiliki kelebihan yaitu standar ini sangat fleksibel yang dikembangkan tergantung kebutuhan organisasi, tujuan organisasi, persyaratan keamanan dan juga SNI ISO 27001 menyediakan sertifikat implementasi Sistem Manajemen Keamanan Informasi (SMKI) yang diakui secara nasional dan internasional yang disebut Information Security Management System (ISMS). Penelitian ini berfokus pada penilaian dan pemetaan permasalahan keamanan terhadap aset informasi pada SIMHP. Pendekatan tersebut akan digunakan sebagai pedoman dalam membuat rancangan model pengendalian keamanan informasi menggunakan ISO 27001.


2014 ◽  
Vol 1 (1) ◽  
pp. 46-58
Author(s):  
IGN Mantra

There is a need for an Information Security Management System Standard (ISO 27001:2005) at Perbanas University in general. Particularly ABFII Perbanas needs IT governance on Information Security. ISO 27001:2005 is an Information Security Standard that widely used as Information Security Management System (ISMS). IT Governance approach is the main interest within ISO 27001:2005 for Perbanas University.


Sign in / Sign up

Export Citation Format

Share Document