INFORMATION SECURITY RISK MANAGEMENT DESIGN OF SUPERVISION MANAGEMENT INFORMATION SYSTEM AT XYZ MINISTRY USING NIST SP 800-30

نویسندگان

چکیده

SIMWAS is an information system at the XYZ Ministry that used to manage supervisory activities and follow up on results. important asset contains all internal control business processes, but in practice, security risks have not been managed properly. To overcome these problems, risk management needed SIMWAS. This study aims design analyze using NIST SP 800-30 framework. focuses a particular infrastructure its boundaries. Since purpose perform technical analysis of core IT infrastructure, it highly prescriptive. It has nine primary steps conduct assessment. The framework by identifying threats, vulnerabilities, impacts, likelihoods, recommendations for controls. assessment carried out analyzing data obtained from results interviews, observations, document reviews. this show four low-level risks, eight moderate-level five high-level risks. Very low levels are acceptable according appetite owner, moderate, high, very high-risk require avoidance, transfer reduction. need carry residual cost-benefit implementing controls each scenarios.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Curriculum Management Information System

Curriculum Management Information System

متن کامل

Information Security Risk Management

The increasing dependence on information networks for business operations has focused managerial attention on managing risks posed by failure of these networks. In this paper, we develop models to assess the risk of failure on the availability of an information network due to attacks that exploit software vulnerabilities. Software vulnerabilities arise from software installed on the nodes of th...

متن کامل

Information Security Risk Management

Security breaches on the socio-technical systems organizations depend on cost the latter billions of dollars of losses each year. Although information security is a growing concern, most organizations deploy technical security measures to prevent security attacks, overlooking social and organizational threats and the risks faced because of them. In this paper, we propose a method to information...

متن کامل

Evaluation of health information requirement in management information System

Introduction: Considering the importance of information, providing the management with a reliable information system, can facilitate decision making regarding planning, organizing and controlling. This study aimed to analyze and evaluate information needs of managers at vice - chancellorship for treatment in Iranian medical science universities. Methods: This cross-sectional study was car...

متن کامل

Integrating Shared Cyber Security Information into Information Security Risk Management

In the last couples of years, the complexity and interconnectedness of Information Systems (IS), and security related incidents increased significantly. In order to guarantee confidentiality, integrity, and availability of these IS an appropriate information security risk management (ISRM) must be in place. Reliable ISRM represents a challenge for organizations, since they take security related...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

ژورنال

عنوان ژورنال: Jurnal Teknik Informatika

سال: 2023

ISSN: ['1979-9160', '2549-7901']

DOI: https://doi.org/10.52436/1.jutif.2023.4.3.978