
Analysis of Information Technology Security Management UKSW SIASAT Using ISO/IEC 27001:2013
Author(s) -
Andeka Rocky Tanaamah,
Friska Juliana Indira
Publication year - 2021
Publication title -
ijitee (international journal of information technology and electrical engineering)
Language(s) - English
Resource type - Journals
ISSN - 2550-0554
DOI - 10.22146/ijitee.65670
Subject(s) - notice , information security , information security management system , itil security management , information security management , business , standard of good practice , business continuity , information security standards , control (management) , computer science , computer security , security service , security information and event management , cloud computing security , cloud computing , political science , law , network security policy , operating system , artificial intelligence
IT security management is essential for organizations to notice the occurring risks and opportunities because they will profoundly affect the ongoing business processes within the organization. The Satya Wacana Academic Information System, more often called SIASAT, is an IT component playing an essential role in running core business processes at Satya Wacana Christian University under the control of the Information Systems and Technology Bureau. At this time, the implementation of SIASAT has been going well, but there are still some obstacles. Lack of human resources is one of the findings and one it becomes of the most significant risks as it affects the use of infrastructure and information security. This research was conducted using the international standard ISO/IEC 27001:2013, prioritizing information security by taking a planning clause focusing on risk assessment. From the results of this study, there were nine recommendations given. Some of which were the most important, i.e., creating separated standard operating procedure documents for SIASAT, which previously were still affiliated with the Academic Administration Bureau; distributing job descriptions; and providing clear and documented access rights for everyone. It is expected that this research can reduce the occurring risks and can be considered for establishing improvements to enhance academic services in the future.