Design of information security risk management using ISO/IEC 27005 and NIST SP 800-30 revision 1: A case study at communication data applications of XYZ institute
Hermawan Setiawan, Fandi Aditya Putra, Anggi Rifa Pradana · 2017
Information security is a priority for the organization. Information can be carried as critical assets, because it's advocated a national security. Communication data applications in the XYZ Institute advocated national security. However, it has amounted vulnerabilities and threats at their information systems and networks. With vulnerabilities and threat which give impact, appears an information security risk for their organization. This causes the organization needs information security risk management process for communication data applications in XYZ Institute. To Implement design of information security risk management for communication data applications in XYZ Institute, we used ISO 27005 framework and NIST SP 800-30 revision 1 as a guideline to risk assessment, and ISO 27002 as reference to development risk treatment plan. The result of this research is how to implementation a design of information security risk management at communication data applications in XYZ Institute.