首页> 外文会议>International Conference on Orange Technologies >Evaluation Of IS Risk Management Using Octave Allegro In Education Division
【24h】

Evaluation Of IS Risk Management Using Octave Allegro In Education Division

机译:在教育部门使用八度快板进行IS风险管理评估

获取原文

摘要

Nowadays, information systems is an important point in supporting business strategies including in education division. Critical assets related to information systems are very susceptible to threats that can exploit and damage assets until they lead to disruption of business processes and even lead to financial losses. PT. Autocomp Systems Indonesia (PASI) has implemented Information Security Management System (ISMS) based on ISO / IEC 27001 to define a set of risk management strategies. However, some threats still occur and make the organization to get losses. The organization needs to conduct an evaluation of risk management that has been implemented to determine whether the risk protection strategy is adequate. Evaluation is done by comparing the current condition with the expected ideal condition using Catalogue of Practices from OCTAVE. The gaps found and then the risk assessment of the related assets is carried out. The results of this study indicate that the level of risk management maturity obtained by the organization is 89.40 %. The biggest gap is found in the contingency plan/disaster recovery plan and vulnerability management. Then a mitigation plan is proposed from the results of the risk assessment using the OCTAVE Allegro approach so the risk can be controlled properly.
机译:如今,信息系统已成为支持业务战略(包括教育部门)的重要方面。与信息系统相关的关键资产非常容易受到威胁的威胁,这些威胁可能会利用和破坏资产,直到它们导致业务流程中断甚至造成财务损失。 PT。 Autocomp Systems Indonesia(PASI)已基于ISO / IEC 27001实施了信息安全管理系统(ISMS),以定义一组风险管理策略。但是,仍然存在一些威胁,使组织蒙受损失。组织需要对已经实施的风险管理进行评估,以确定风险保护策略是否适当。通过使用OCTAVE的《操作目录》将当前条件与预期的理想条件进行比较来进行评估。找到差距,然后对相关资产进行风险评估。这项研究的结果表明,该组织获得的风险管理成熟度为89.40%。最大的差距是在应急计划/灾难恢复计划和漏洞管理中。然后,使用OCTAVE Allegro方法从风险评估结果中提出缓解计划,以便可以适当地控制风险。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号