DocumentCode :
3580861
Title :
Information security risk management planning: A case study at application module of state asset directorate general of state asset ministry of finance
Author :
Prasetyo, Sigit ; Sucahyo, Yudho Giri
Author_Institution :
Fac. of Comput. Sci., Univ. of Indonesia, Depok, Indonesia
fYear :
2014
Firstpage :
96
Lastpage :
101
Abstract :
Ministry of Finance in particular the Directorate General of State Asset (DJKN) is one organization that is tasked to undertake the management of state asset and improved services to stakeholders using information technology as a supporting element. To realize the value database of state asset into a credible executive information intact, timely, accurate and can be used for decision making process for the leadership of the Ministry of Finance then needed an information security risk management plan to the main information systems that support business processes DJKN. This research aimed to develop an information security risk management plan for DJKN particularly to applications that support key business processes that called state assets module applications using the framework of ISO 27005 and ISO 27002 for risk reduction management. The results obtained from this research is the information security risk management plan that contains the document mitigation risk, control recommendations to reduce risk and acceptance of risk which contains risk management decisions also the person in charge of mitigation risk.
Keywords :
ISO standards; asset management; risk management; security of data; DJKN; Directorate General of State Asset; ISO 27002 framework; ISO 27005 framework; Ministry of Finance; application module; business processes; decision making process; document mitigation risk; information security risk management plan; information security risk management planning; information systems; information technology; recommendation control; risk management decisions; risk reduction management; stakeholder service improvement; state asset management; state asset value database; Computer science; Decision support systems; Electronic mail; Handheld computers; ISO standards; Information security; Risk management; ISO 27002; ISO 27005; Information Security; Risk Management;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Computer Science and Information Systems (ICACSIS), 2014 International Conference on
Type :
conf
DOI :
10.1109/ICACSIS.2014.7065875
Filename :
7065875
Link To Document :
بازگشت