Risk Assessment Maturity Level of Academic Information System Using ISO 27001 System Security Engineering-Capability Maturity Model

Nurbojatmiko Nurbojatmiko, Qurrotul Aini, Nabil Cahya Wasiqi, Muhammad Fitra Alfajri, Zahra Ulinnuha, Yuni Purwati, Indah Kusuma Ayu, Natasya Aurora Yasmin
{"title":"Risk Assessment Maturity Level of Academic Information System Using ISO 27001 System Security Engineering-Capability Maturity Model","authors":"Nurbojatmiko Nurbojatmiko, Qurrotul Aini, Nabil Cahya Wasiqi, Muhammad Fitra Alfajri, Zahra Ulinnuha, Yuni Purwati, Indah Kusuma Ayu, Natasya Aurora Yasmin","doi":"10.37385/jaets.v5i2.2971","DOIUrl":null,"url":null,"abstract":"Risk measurement from standard operating procedures implemented by an institution determines the level of maturity of a service system at that institution. The government's determination of the Tri Dharma of Higher Education consists of education and teaching, research, and community service. These activities must be implemented in the academic information system of every university in Indonesia. Appropriate and fast academic services depend on information technology and adequate and trained human resources (HR). Factors that influence information system security determine the stability of application services. The ISO/IEC 27001:2005 standard is an international benchmark for measuring the level of maturity and security risks of an application. Risk assessment in standard operating procedures in organizations can use the ISO/IEC 27001 standard. This research aims to determine the current level of Academic Information System (AIS) service by measuring maturity and security risks. Three clauses measure the maturity level of information security controls with the ISO 27001 System Security Engineering-Capability Maturity Model (SSE-CMM). These research respondents are educational work units at the Science and Technology Faculty in UIN Syarif Hidayatullah Jakarta. This research method uses quantitative research methods. This research results show the maturity level of information security in the academic information system based on three clauses as the embodiment of the stability of the academic administration activities services at the Science and Technology Faculty. The measurement results reveal that the average score of information security controls on AIS is 3.51, which means good or average standard processing has been carried out following procedures.","PeriodicalId":509378,"journal":{"name":"Journal of Applied Engineering and Technological Science (JAETS)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2024-06-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Applied Engineering and Technological Science (JAETS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.37385/jaets.v5i2.2971","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Risk measurement from standard operating procedures implemented by an institution determines the level of maturity of a service system at that institution. The government's determination of the Tri Dharma of Higher Education consists of education and teaching, research, and community service. These activities must be implemented in the academic information system of every university in Indonesia. Appropriate and fast academic services depend on information technology and adequate and trained human resources (HR). Factors that influence information system security determine the stability of application services. The ISO/IEC 27001:2005 standard is an international benchmark for measuring the level of maturity and security risks of an application. Risk assessment in standard operating procedures in organizations can use the ISO/IEC 27001 standard. This research aims to determine the current level of Academic Information System (AIS) service by measuring maturity and security risks. Three clauses measure the maturity level of information security controls with the ISO 27001 System Security Engineering-Capability Maturity Model (SSE-CMM). These research respondents are educational work units at the Science and Technology Faculty in UIN Syarif Hidayatullah Jakarta. This research method uses quantitative research methods. This research results show the maturity level of information security in the academic information system based on three clauses as the embodiment of the stability of the academic administration activities services at the Science and Technology Faculty. The measurement results reveal that the average score of information security controls on AIS is 3.51, which means good or average standard processing has been carried out following procedures.
利用 ISO 27001 系统安全工程-能力成熟度模型评估学术信息系统的风险成熟度水平
从一个机构实施的标准操作程序中进行风险测量,决定了该机构服务系统的成熟程度。政府确定的高等教育三法包括教育与教学、研究和社区服务。印尼每所大学的学术信息系统都必须开展这些活动。适当而快速的学术服务取决于信息技术和充足且训练有素的人力资源(HR)。影响信息系统安全的因素决定了应用服务的稳定性。ISO/IEC 27001:2005 标准是衡量应用程序成熟度和安全风险的国际基准。企业标准操作程序中的风险评估可以使用 ISO/IEC 27001 标准。本研究旨在通过衡量成熟度和安全风险,确定学术信息系统(AIS)服务的当前水平。有三个条款采用 ISO 27001 系统安全工程-能力成熟度模型(SSE-CMM)来衡量信息安全控制的成熟度。这些研究对象是雅加达 Syarif Hidayatullah 大学科技学院的教育工作单位。本研究采用定量研究方法。研究结果显示,学术信息系统的信息安全成熟度基于三个条款,是科技学院学术管理活动服务稳定性的体现。测量结果显示,学术信息系统信息安全控制的平均得分为 3.51,这意味着已按照程序进行了良好或平均标准的处理。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信