Risk and Security Measurement Based on ISO 27001 Using FMEA Methodology Case Study: National Government Agency
Alfan Cahyo Wicaksono, Sidik Prabowo, Dita Oktaria · 2022
XYZ government agency utilizes information technology in its operations. The utilization of Information Technology (IT) assets cannot be separated from the risk of information security. This research focuses on evaluating security risks and determining appropriate risk mitigation by ISO 27001 and 27002 standards. The risk assessment process uses the Failure Mode and Effect Analysis method. The FMEA method will produce a Risk Priority Number value, which will determine the priority level from the highest to the lowest risk. The risk assessment in the organization resulted in 14 risk classifications that needed to be handled. Of the 14 chances, 3 have a High-risk level, 6 have a medium-risk level and 5 have a Low level. The list of risks and the results of the assessment will be handled or mitigated by the ISO 27002:2013 standard. XYZ Agencies use risk mitigation documents to reduce risk levels and improve information security management aspects.