Preparation of Information Security Risk Management Based on Iso / IEC 27001: 2022 at Diskominfo West Java Province
DOI:
https://doi.org/10.47747/ijmhrr.v6i1.2596Keywords:
Information Security, Information Security Risk Management, ISO 27001:2022Abstract
Information security and awareness of the dangers of information leakage are the most important things in information technology, especially information that is classified and has strategic value. Information security risk management is an approach organizations use to identify, distribute, measure, and manage risks related to information security, which, if left unchecked, can paralyze existing business process activities in the organization. In carrying out its business processes, the West Java Province Diskominfo still has risk problems, namely that information security incidents often disrupt institutional business processes, where some incidents can be handled directly (reactively) in the field. However, several other incidents require planning and time. There are quite a few solutions, and there is no proper supervision and planning in managing data and information security, so Information Security Risk Management based on ISO/IEC 27001:2022 is needed. The results of this research show that there are forty-one information security risks in the West Java Province Diskominfo, and recommendations have been given for each risk in accordance with the ISO/IEC 27001:2022 standard.
References
Ahmedi, B., & Ibrahimi, A. (2024). Mastering information security through standard implementation. International Journal of Informatics and Communication Technology, 13(3), 428–435. https://doi.org/10.11591/ijict.v13i3.pp428-435
Budiarto, R. (2017). Manajemen Risiko Keamanan Sistem Informasi Menggunakan Metode FMEA dan ISO 27001 pada Organisasi XYZ. CESS (Journal of Computer Engineering System and Science), 2(2), 48–58. https://doi.org/https://doi.org/10.24114/cess.v2i2.6264
Carvalho, C., & Marques, E. (2019). Adapting ISO 27001 to a Public Institution. Iberian Conference on Information Systems and Technologies, CISTI, 2019-June. https://doi.org/10.23919/CISTI.2019.8760870
Chavez, S., Anahue, J., & Ticona, W. (2024). Implementation of an ISMS Based on ISO/IEC 27001:2022 to Improve Information Security in the Internet Services Sector. Proceedings of the 14th International Conference on Cloud Computing, Data Science and Engineering, Confluence 2024, 184–189. https://doi.org/10.1109/Confluence60223.2024.10463392
Fahmi Rifai, Jazman, M., Angraini, A., & Megawati, M. (2023). Design of Application Information Security Self-Assessment Using Vba and Msxml2.Xmlhttp Case Study: Diskominfo Kabupaten Kampar. Jurnal Teknik Informatika (Jutif), 4(6), 1523–1534. https://doi.org/10.52436/1.jutif.2023.4.6.1033
Fajri, K. S. Al, & Harwahyu, R. (2024). Information Security Management System Assessment Model by Integrating ISO 27002 and 27004. MALCOM: Indonesian Journal of Machine Learning and Computer Science, 4(2), 498–506. https://doi.org/10.57152/malcom.v4i2.1245
Fitrani, L. D. (2022). Risk Risk Assessment and Development of Access Control Information Security Governance Based on ISO/IEC 27001:2013 At XYZ University. JATISI (Jurnal Teknik Informatika Dan Sistem Informasi), 9(2), 891–907. https://doi.org/10.35957/jatisi.v9i2.1643
Folorunso, A., Mohammed, V., Wada, I., & Samuel, B. (2024). The impact of ISO security standards on enhancing cybersecurity posture in organizations.
Hernandez, L., Pranolo, A., & Wibawa, A. P. (2024). Implementation plan of the information security management system based on the NTC-ISO-IEC 27001:2013 standard and security risk analysis. Case study: Higher education institution. Transactions on Energy Systems and Engineering Applications, 5(2). https://doi.org/10.32397/tesea.vol5.n2.635
Holt, T. J. (2017). Identifying gaps in the research literature on illicit markets on-line. Global Crime, 18(1), 1–10. https://doi.org/10.1080/17440572.2016.1235821
Indonesia, G. of. (2023). Peraturan Gubernur Jawa Barat Nomor 6 Tahun 2023 Tentang Pedoman Pengelolaan Risiko Di Lingkungan Pemerintah Daerah Provinsi Jawa Barat (p. 100).
Intan Mafiana, A., Hanum, L., Ilmi, H. M., & Febriliani, S. (2023). Implementasi Manajemen Keamanan Informasi Berbasis Iso 27001 Pada Sistem Informasi Akademik. Journal of Digital Business and Innovation Management, 2(2), 139–163. https://doi.org/10.26740/jdbim.v2i2.57580
Jaya Putra, S., Nur Gunawan, M., Falach Sobri, A., Muslimin, J. M., Amilin, & Saepudin, D. (2020). Information Security Risk Management Analysis Using ISO 27005: 2011 for the Telecommunication Company. 2020 8th International Conference on Cyber and IT Service Management, CITSM 2020. https://doi.org/10.1109/CITSM50537.2020.9268845
Jevelin, J., & Faza, A. (2023). Evaluation the Information Security Management System: A Path Towards ISO 27001 Certification. Journal of Information Systems and Informatics, 5(4), 1240–1256. https://doi.org/10.51519/journalisi.v5i4.572
Kovilage, M. P., Yapa, S. T. W. S., & Hewagamage, C. (2022). Research Areas, Gaps and Future Research Directions of Operational Excellence: A Systematic Literature Review. South Asian Journal of Business Insights, 2(1), 3–32. https://doi.org/10.4038/sajbi.v2i1.31
Kusnandar, A., Rochim, A. F., & Gunawan, V. (2024). Pengukuran Tingkat Risiko dan Keamanan Informasi Menggunakan Metode FMEA Berbasis ISO / IEC 27001 pada Instansi XYZ untuk Keamanan Sistem Informasi. 04. https://doi.org/10.21456/vol14iss4pp375-384
Mahardika, F. (2017). Manajemen Risiko Keamanan Informasi Menggunakan Framework NIST SP 800-30 Revisi 1 (Studi Kasus: STMIK Sumedang). Jurnal Informatika: Jurnal Pengembangan IT, 2(2), 1–8. https://doi.org/10.30591/jpit.v2i2.484
Malatji, M. (2023). Management of enterprise cyber security: A review of ISO/IEC 27001:2022. 2023 International Conference on Cyber Management and Engineering, CyMaEn 2023, 117–122. https://doi.org/10.1109/CyMaEn57228.2023.10051114
Matondang, N., Isnainiyah, I. N., & Muliawatic, A. (2018). Analisis Manajemen Risiko Keamanan Data Sistem Informasi (Studi Kasus: RSUD XYZ). Jurnal RESTI (Rekayasa Sistem Dan Teknologi Informasi), 2(1), 282–287. https://doi.org/10.29207/resti.v2i1.96
Nugraha, A. A., & Nasyuha, A. H. (2024). Integrating ISO 27001 and Indonesia’s Personal Data Protection Law for Data Protection Requirement Model. Journal of Information Systems and Informatics, 6(2), 1052–1069. https://doi.org/10.51519/journalisi.v6i2.754
Nurbojatmiko, Aini, Q., Wasiqi, N. C., Alfajri, M. F., Ulinnuha, Z., Purwati, Y. K., Ayu, I. K., & Yasmin, N. A. (2024). Risk Assessment Maturity Level of Academic Information System Using Iso 27001 System Security Engineering-Capability Maturity Model. Journal of Applied Engineering and Technological Science, 5(2), 941–954. https://doi.org/10.37385/jaets.v5i2.2971
Paksoy, A. A. M. P. M. (2023). Of azerbaijan high technical educational institutions azərbaycan ali̇ texni̇ki̇ məktəbləri̇ni̇n xəbərləri̇. Proceedings of Azerbaijan High Technical Educational Institutions, 27(04). https://doi.org/10.36962/PAHTEI
Pamungkas, A. C., Hulu, W. S., & Samihardjo, R. (2024). Information Security Risk Management Web-Based Final Semester Summative Assessment Application Using ISO 27001:2013. Journal of Information Systems and Informatics, 6(1), 349–362. https://doi.org/10.51519/journalisi.v6i1.668
Patrick, H., van Niekerk, B., & Fields, Z. (2018). Developing Cybersecurity Resilience in the Provincial Government. 336–363. https://doi.org/10.4018/978-1-5225-4763-1.ch012
Putra, A. P., & Soewito, B. (2023). Integrated Methodology for Information Security Risk Management using ISO 27005:2018 and NIST SP 800-30 for Insurance Sector. International Journal of Advanced Computer Science and Applications, 14(4), 625–633. https://doi.org/10.14569/IJACSA.2023.0140468
Rilyani, A. N., Firdaus, Y., & Jatmiko, D. D. (2015). Analisis Risiko Teknologi Informasi Berbasis Risk Management Menggunakan ISO 31000. E-Proceeding of Engineering, 2(2), 6201–6208. https://doi.org/https://doi.org/10.35957/jatisi.v8i4.1082
Ringga, M. (2022). Analysis of Information Technology Governance at the Office of Communication and Information (Diskominfo) using the Cobit 4.1 Method. Journal of Computer Scine and Information Technology, 111–118. https://doi.org/10.35134/jcsitech.v8i4.48
Seydvalieva, A. R. (2024). Legal provision of information security of state institutions. Upravlenie Kachestvom (Quality Management), 7, 34–41. https://doi.org/10.33920/pro-01-2407-05
Sin, K. Y., & Jusoh, M. S. (2019). Identifying and Prioritizing Research Gaps in Studies related to Total Quality Management on Competitive Advantage in Malaysian Hotel Industries. International Journal of Academic Research in Business and Social Sciences, 9(5). https://doi.org/10.6007/ijarbss/v9-i5/5875
Supradono, B. (2009). Manajemen Risiko Keamanan Informasi dengan Menggunakan Metode Octave (Operationally Critical Threat, Asset, and Vulnerability Evaluation). Media Elektrika, 2(1), 4–8.
Supristiowadi, E., & Sucahyo, Y. G. (2018). Manajemen Risiko Keamanan Informasi pada Sistem Aplikasi Keuangan Tingkat Instansi (SAKTI) Kementerian Keuangan. Indonesian Treasury Review Jurnal Perbendaharaan Keuangan Negara Dan Kebijakan Publik, 3(1), 23–33. https://doi.org/10.33105/itrev.v3i1.20
Susanto, E., Legowo, N., & Ady Prabowo, B. (2023). Assessing Information Security Risks in Clinical Laboratory in Accordance With ISO/IEC 27001 Standard. Journal of Indonesian Applied Economics, 11(2), 206–216. https://doi.org/10.21776/ub.jiae.2023.011.02.8
Syahindra, I. P. S., Hetty Primasari, C., & Bagas Pradipta Iriantor, A. (2022). Evaluasi Risiko Keamanan Informasi Diskominfo Provinsi Xyz Menggunakan Indeks Kami Dan Iso 27005 : 2011. Jurnal Teknoinfo, 16(2), 165. https://doi.org/10.33365/jti.v16i2.1246
Tanjung, D. F., Dwi Nurhayati, O., & Wibowo, A. (2024). Design Information Security in Electronic-Based Government Systems Using NIST CSF 2.0, ISO/IEC 27001: 2022 and CIS Control. International Journal of Innovative Science and Research Technology (IJISRT), 523–530. https://doi.org/10.38124/ijisrt/ijisrt24jun1212
Tintin, R., & Hidalgo, M. (2023). Could an ISMS Model (ISO/IEC 27001:2013 Standard) Implementation Really Protect Public Data? 2023 9th International Conference on EDemocracy and EGovernment, ICEDEG 2023. https://doi.org/10.1109/ICEDEG58167.2023.10122109
Vinet, L., & Zhedanov, A. (2011a). A “missing” family of classical orthogonal polynomials. Journal of Physics A: Mathematical and Theoretical, 44(8), 1–14. https://doi.org/10.1088/1751-8113/44/8/085201
Vinet, L., & Zhedanov, A. (2011b). A “missing” family of classical orthogonal polynomials. Journal of Physics A: Mathematical and Theoretical, 44(8), 2582–2595. https://doi.org/10.1088/1751-8113/44/8/085201
Wicaksono, A. C., Prabowo, S., & Oktaria, D. (2022). Risk and Security Measurement Based on ISO 27001 Using FMEA Methodology Case Study: National Government Agency. 2022 1st International Conference on Software Engineering and Information Technology, ICoSEIT 2022, 6–11. https://doi.org/10.1109/ICoSEIT55604.2022.10029988
Wiemas N. G., K., & Suroso, J. S. (2024). Analysis of Risk Management Information System Applications Using Iso/Iec 27001:2022. Syntax Literate ; Jurnal Ilmiah Indonesia, 7(11), 18372–18391. https://doi.org/10.36418/syntax-literate.v7i11.15426
Wijaya, F., & Senen, S. H. (2024). Strategic Human Resource Management in Social Enterprises : A Systematic Review of Practices and Challenges. Journal of Social Entrepreneurship Theory and Practice (JSETP), 3(2). https://doi.org/https://doi.org/10.31098/jsetp.v3i2.2821
Wijaya, F., Waspada, I., & Sari, M. (2024). A Systematic Literature Review of Investment Strategies in Perfect Capital Markets : Insights from the PRISMA Framework. International Journal of Entrepreneurship and Sustainability Studies (IJEASS), 4(2). https://doi.org/https://doi.org/10.31098/ijeass.v4i2.2813
Wijayanto, A., Utami, E., & Prasetio, A. B. (2020). Analysis of Vulnerability Webserver Office Management of Information and Documentation Diskominfo using OWASP Scanner. 2020 2nd International Conference on Cybernetics and Intelligent System, ICORIS 2020. https://doi.org/10.1109/ICORIS50180.2020.9320833
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Ginanjar Nugraha, Ina Siti Nurhasanah, Idi Sumardi, Yuda Prasetia Nugraha

This work is licensed under a Creative Commons Attribution 4.0 International License.
Copyrights
Copyright for this article is retained by the author(s), with first publication rights granted to the journal.
This is an open-access article distributed under the terms and conditions of the Creative Commons Attribution license (http://creativecommons.org/licenses/by/4.0/)




