Information Security Risk Management Analysis Using ISO 27005: 2011 For The Telecommunication Company
Syopiansyah Jaya Putra, Muhamad Nur Gunawan, Achmad Falach Sobri, JM Muslimin, Amilin Amilin, Didin Saepudin · 2020 8th International Conference on Cyber and IT Service Management (CITSM) · 2020
The implementation of information security risk management in the telecommunications company is carried out to systematically manage potential losses arising from opportunities and consequences in the information security business process. This implementation uses ISO 27005 in relation to the requirements of ISO 27001 which has control objectives that can be used as a basis for controlling risk. The maintenance and inspection program implemented in the telecommunications company has not considered the risk aspects in the decision-making process so that the problem has resulted in not optimal risk handling and control. The purpose of this study is to determine the selection of the right control object for the basis of a suitable risk control program to support the requirements of the ISO 27001 information security management system standard. This study begins with context establishment, followed by risk identification, risk analysis, risk evaluation, and risk treatment. The sampling technique used purposive sampling and snowball sampling. Data collection was obtained from the management and processed with computer-assisted qualitative data analysis software NVivo 10. This study produces 26 impact scenarios for the highest rank category and 12 impact scenarios as the top priority. Based on the results of risk evaluation, eight ISO 27001 control objectives need to be considered in order to support information security. The results of this study can be used for planning decisions and risk control work programs.