Information Security Risk Strategy at PT. X Using NIST SP 800-30

Information security is a vital aspect that must be considered in use of information technology devices by active users. PT. X runs a business that applies information technology related to distribution aspects through company resource planning. Information technology formed assets IT infrastructure...

Full description

Saved in:
Bibliographic Details
Published inJurnal Ilmiah Merpati (Menara Penelitian Akademika Teknologi Informasi) (Online) Vol. 9; no. 3; p. 213
Main Authors Putra Eryawan, I Gusti Ngurah Made, Arya Sasmita, Gusti Made, Agung Cahyawan Wiranatha, Anak Agung Ketut
Format Journal Article
LanguageEnglish
Published 27.05.2021
Online AccessGet full text

Cover

Loading…
More Information
Summary:Information security is a vital aspect that must be considered in use of information technology devices by active users. PT. X runs a business that applies information technology related to distribution aspects through company resource planning. Information technology formed assets IT infrastructure, information systems, operating procedures, and network infrastructure. This asset has a potential threat that causes disruption resulting losses. This problem arises to cope through the response to the risk strategy. NIST SP 800-30 method has a flexible risk perspective for the organization and federation standards of American security. Research is divided into risk measurement as a risk, risk mitigation as risk planning, and risk evaluation embodied risk reports. Results of the research show the value of risk through the calculation of the likelihood and impact matrix of the highest threat is at a low level is 14, medium at 12, and high of 4 are categorized good enough. Keywords: Risk Strategy, Information Security, NIST SP 800-30, Risk
ISSN:2252-3006
2685-2411
DOI:10.24843/JIM.2021.v09.i03.p03