{"title":"Analysis of cause and effect relationship risk using fishbone diagram in SDLC SPASI v. 4.0 business process","authors":"Azzahra Ratu Kamila, S. Sutikno","doi":"10.1109/ICITSI.2016.7858186","DOIUrl":null,"url":null,"abstract":"One of the requirements contained in IT general control is the availability of an SDLC. But until now, PT. Telkom has yet to implement risk management in the SDLC process. In order to manage the risks properly, risk assessment is needed to determine approriate internal controls for SDLC. This study tries to present a methodology to assess this value using semi-quantitative risk assessment. The methodology addresses risk by using fishbone diagram to determine casuality relationship among SDLC risks. SPASI 4.0, PT. Telkom's standard for software development lifecycle, is used to determine the current IT general control, which is desired. The results of the research in this case is the gap analysis of control.","PeriodicalId":172314,"journal":{"name":"2016 International Conference on Information Technology Systems and Innovation (ICITSI)","volume":"13 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 International Conference on Information Technology Systems and Innovation (ICITSI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICITSI.2016.7858186","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
One of the requirements contained in IT general control is the availability of an SDLC. But until now, PT. Telkom has yet to implement risk management in the SDLC process. In order to manage the risks properly, risk assessment is needed to determine approriate internal controls for SDLC. This study tries to present a methodology to assess this value using semi-quantitative risk assessment. The methodology addresses risk by using fishbone diagram to determine casuality relationship among SDLC risks. SPASI 4.0, PT. Telkom's standard for software development lifecycle, is used to determine the current IT general control, which is desired. The results of the research in this case is the gap analysis of control.
IT通用控制中包含的需求之一是SDLC的可用性。但到目前为止,PT. Telkom尚未在SDLC过程中实施风险管理。为了适当地管理风险,需要进行风险评估,以确定SDLC的适当内部控制。本研究试图提出一种方法来评估这种价值使用半定量风险评估。该方法通过鱼骨图确定SDLC风险之间的因果关系来处理风险。SPASI 4.0, PT. Telkom的软件开发生命周期标准,用于确定当前的IT一般控制,这是需要的。本案例的研究结果是控制的差距分析。