Cyber-Risk Management Planning Using NIST CSF V1.1, ISO/IEC 27005:2018, and NIST SP 800-53 Revision 5 (A Study Case to ABC Organization)
Ellisa Hani Nur Safitri, Herman Kabetta · 2023
Digital transformation continues to be carried out throughout the government and private sectors which has led to an increase in the quality of service to the community. The rapid process of digitalization is directly proportional to the cyber threats that lurk in organizational assets. So as to mitigate the risks that occur to organizational assets, it is necessary to carry out cyber risk management planning. As an organization engaged in information technology, ABC organization has an ICT unit that supports the duties and responsibilities in managing infrastructure, information systems, and organizational services. However, this unit has never done risk management planning for its assets, so it is likely that the risks that have occurred can be repeated without mitigation. Therefore, this research was made to design a cyber risk plan aimed at the ICT unit of the ABC organization using 3 security standards, including NIST CSF v1.1 as the main framework, ISO/ IEC 27005: 2018 as a supporting framework, and NIST SP 800-53 revision 5 as a recommendation for actions taken for identified risks. From the results of this study, 105 risk scenarios were obtained in the ICT unit with details of 64 accepted risks and 43 mitigated risks with 86 control recommendations. The provision of control recommendations is adjusted to the risks experienced by the organization, with the aim of controlling cyber risks.