利用NIST 800-34框架在朝觐和朝圣总局信息系统上设计灾难恢复计划

Nurhanudin Nurhanudin
{"title":"利用NIST 800-34框架在朝觐和朝圣总局信息系统上设计灾难恢复计划","authors":"Nurhanudin Nurhanudin","doi":"10.38101/SISFOTEK.V11I2.391","DOIUrl":null,"url":null,"abstract":"The Directorate General of Hajj and Umrah manages an information system that is used to provide services in the business process of organizing Hajj and Umrah, the services provided include registration, cancellation, settlement, portion assignment, hajj document management, embarkation operations, Saudi Arabia operations, and debarkation operations. The services are provided throughout the year, thus requiring infrastructure support and adequate information systems that can run24 hours a day. To maintain and ensure the continuity of Hajj and Umrah services, a Disaster Recovery Plan is designed, which is used as a guide in dealing with disasters or disturbances that can occur at any time and can disrupt all operational activities of the organization. In this study, the NIST 800-34 framework is used, starting with risk identification and assessment, Business Impact Analysis (BIA), preventive controls identification, contingency strategies, and contingency plans. The contingency plan preparation phase includes the activation phase, the recovery phase, and the reconstitution phase. Based on the result of research, there are ten risks that can threaten the continuity of information system services and based on Business Analysis Impact, services with a high critical level are Siskohat and Haji Pintar applications. The research produced is in the form of a Disaster Recovery Plan document that is adapted to the organizational conditions of the Directorate General of Hajj and Umrah.","PeriodicalId":378682,"journal":{"name":"JURNAL SISFOTEK GLOBAL","volume":"34 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-09-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Designing a Disaster Recovery Plan Using NIST 800-34 Framework on the Information System of The Directorate General of Hajj and Umrah\",\"authors\":\"Nurhanudin Nurhanudin\",\"doi\":\"10.38101/SISFOTEK.V11I2.391\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The Directorate General of Hajj and Umrah manages an information system that is used to provide services in the business process of organizing Hajj and Umrah, the services provided include registration, cancellation, settlement, portion assignment, hajj document management, embarkation operations, Saudi Arabia operations, and debarkation operations. The services are provided throughout the year, thus requiring infrastructure support and adequate information systems that can run24 hours a day. To maintain and ensure the continuity of Hajj and Umrah services, a Disaster Recovery Plan is designed, which is used as a guide in dealing with disasters or disturbances that can occur at any time and can disrupt all operational activities of the organization. In this study, the NIST 800-34 framework is used, starting with risk identification and assessment, Business Impact Analysis (BIA), preventive controls identification, contingency strategies, and contingency plans. The contingency plan preparation phase includes the activation phase, the recovery phase, and the reconstitution phase. Based on the result of research, there are ten risks that can threaten the continuity of information system services and based on Business Analysis Impact, services with a high critical level are Siskohat and Haji Pintar applications. The research produced is in the form of a Disaster Recovery Plan document that is adapted to the organizational conditions of the Directorate General of Hajj and Umrah.\",\"PeriodicalId\":378682,\"journal\":{\"name\":\"JURNAL SISFOTEK GLOBAL\",\"volume\":\"34 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2021-09-30\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"JURNAL SISFOTEK GLOBAL\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.38101/SISFOTEK.V11I2.391\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"JURNAL SISFOTEK GLOBAL","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.38101/SISFOTEK.V11I2.391","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

朝觐和朝圣总局管理着一个信息系统,用于在组织朝觐和朝圣的业务流程中提供服务,提供的服务包括登记、取消、结算、分配部分、朝觐文件管理、登船业务、沙特阿拉伯业务和登船业务。这些服务是全年提供的,因此需要每天24小时运行的基础设施支助和足够的信息系统。为了维持和确保朝觐和朝觐服务的连续性,本组织制定了一项灾难恢复计划,作为处理随时可能发生并可能中断本组织所有业务活动的灾难或干扰的指南。在本研究中,使用了NIST 800-34框架,从风险识别和评估、业务影响分析(BIA)、预防控制识别、应急策略和应急计划开始。应急计划准备阶段包括启动阶段、恢复阶段和重建阶段。根据研究结果,有十个可能威胁信息系统服务连续性的风险,根据业务分析影响,具有高临界级别的服务是Siskohat和Haji Pintar应用。所进行的研究以《灾难恢复计划》文件的形式进行,该文件根据朝觐和朝圣总局的组织条件进行了调整。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Designing a Disaster Recovery Plan Using NIST 800-34 Framework on the Information System of The Directorate General of Hajj and Umrah
The Directorate General of Hajj and Umrah manages an information system that is used to provide services in the business process of organizing Hajj and Umrah, the services provided include registration, cancellation, settlement, portion assignment, hajj document management, embarkation operations, Saudi Arabia operations, and debarkation operations. The services are provided throughout the year, thus requiring infrastructure support and adequate information systems that can run24 hours a day. To maintain and ensure the continuity of Hajj and Umrah services, a Disaster Recovery Plan is designed, which is used as a guide in dealing with disasters or disturbances that can occur at any time and can disrupt all operational activities of the organization. In this study, the NIST 800-34 framework is used, starting with risk identification and assessment, Business Impact Analysis (BIA), preventive controls identification, contingency strategies, and contingency plans. The contingency plan preparation phase includes the activation phase, the recovery phase, and the reconstitution phase. Based on the result of research, there are ten risks that can threaten the continuity of information system services and based on Business Analysis Impact, services with a high critical level are Siskohat and Haji Pintar applications. The research produced is in the form of a Disaster Recovery Plan document that is adapted to the organizational conditions of the Directorate General of Hajj and Umrah.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信