Facebook pixel tracking

The Science and Information (SAI) Organization publishes open-access peer-reviewed journals in computer science and artificial intelligence.

Contact Info
Website thesai.org
Follow Us
Contact Info
Follow Us
Research Article | Open Access |

Integrated Methodology for Information Security Risk Management using ISO 27005:2018 and NIST SP 800-30 for Insurance Sector

Author 1: Arief Prabawa Putra Author 2: Benfano Soewito
International Journal of Advanced Computer Science and Applications (IJACSA) · Vol. 14, No. 4 · Published 2023 · Cited by 10

DOI: https://doi.org/10.14569/IJACSA.2023.0140468

Abstract

The development of Information and Communication Technology (ICT) in the Industrial Revolution 4.0 era shows very fast and disruptive developments that encourage increased use of Information Technology (IT) services within organizations. However, there is a risk of creating vulnerabilities and threats to owned information systems. Plans and strategies are required to implement information security risk management to address vulnerabilities in threat events. This research is a case study of the Enterprise Resource Planning System in the Insurance Sector. The proposed methodologies for integrating information security risk management using ISO/IEC 27005:2018 as a risk management framework and NIST SP 800-30 Rev. 1 as guidance for risk assessments. The risk evaluation stage is the process of comparing the results of the risk analysis with the risk criteria to then determine whether the risk rating is acceptable or tolerable. For risk treatment and control using the ISO/IEC 27002:2022 framework.

Keywords

How to Cite this Article

Putra, A. P., & Soewito, B. (2023). Integrated Methodology for Information Security Risk Management using ISO 27005:2018 and NIST SP 800-30 for Insurance Sector. International Journal of Advanced Computer Science and Applications, 14(4). https://doi.org/10.14569/IJACSA.2023.0140468

Putra, Arief Prabawa, and Benfano Soewito. "Integrated Methodology for Information Security Risk Management using ISO 27005:2018 and NIST SP 800-30 for Insurance Sector." International Journal of Advanced Computer Science and Applications, vol. 14, no. 4, 2023, https://doi.org/10.14569/IJACSA.2023.0140468.

@article{Putra2023,
  title     = {Integrated Methodology for Information Security Risk Management using ISO 27005:2018 and NIST SP 800-30 for Insurance Sector},
  journal   = {International Journal of Advanced Computer Science and Applications},
  volume    = {14},
  number    = {4},
  year      = {2023},
  publisher = {The Science and Information Organization},
  author    = {Arief Prabawa Putra and Benfano Soewito},
  doi       = {10.14569/IJACSA.2023.0140468},
  url       = {https://doi.org/10.14569/IJACSA.2023.0140468}
}

Open Access — licensed under a Creative Commons Attribution 4.0 International License. Unrestricted use, distribution, and reproduction in any medium, even commercially, as long as the original work is properly cited.