• DocumentCode
    560961
  • Title

    Designing a tool for IT Governance Risk Compliance: A case study

  • Author

    Puspasari, Dewi ; Hammi, M. Kasfu ; Sattar, Muhammad ; Nusa, Rein

  • Author_Institution
    Lab. of IT Governance, Univ. of Indonesia, Depok, Indonesia
  • fYear
    2011
  • fDate
    17-18 Dec. 2011
  • Firstpage
    311
  • Lastpage
    316
  • Abstract
    Awareness of the importance of risk management related to the implementation of information technology in Indonesia companies began to grow. This is in line with increasingly strict regulations, such as regulations the Minister of State-Owned Enterprises on the necessity of carrying out risk management in state-owned enterprises environment and regulations issued by other authorities such as Bank of Indonesia that must be obeyed by all public banks. Bank of Indonesia has required the implementation of risk management in the use of information technology. This obligation has been implemented by XYZ Bank with the internal policies adopted from that rules, though their IT risk management is currently not providing satisfactory results. Governance, risk management, and compliance in IT are still standing separately so that when incidents occur, sluggish handling often happens. Finally, this can impact on company reputation and resulting financial loss. The bad experiences drive the XYZ Bank to create a tool that combines governance, risk, and compliance in IT. This tool is custom made to fit the needs of the company. Framework selected in the design tool, is the unified modeling language with the use of case diagrams, sequence diagrams and class diagrams.
  • Keywords
    Unified Modeling Language; bank data processing; local government; public finance; risk management; Bank of Indonesia; IT governance risk compliance; IT risk management; Indonesia company; Minister of state-owned enterprise; case diagram; class diagram; financial loss; information technology; public bank; sequence diagram; state-owned enterprise environment; unified modeling language; Best practices; Companies; Monitoring; Registers; Risk management; Security; Unified modeling language;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Computer Science and Information System (ICACSIS), 2011 International Conference on
  • Conference_Location
    Jakarta
  • Print_ISBN
    978-1-4577-1688-1
  • Type

    conf

  • Filename
    6140793