Information Security Assessment Using ISO/IEC 27001:2013 Standard on Government Institution

  • Maingak A
  • Candiwan C
  • Harsono L
N/ACitations
Citations of this article
29Readers
Mendeley users who have this article in their library.

Abstract

The purpose of this research is to determine the existing gap to achieve ISO/IEC 27001:2013 certification and determine the maturity level of the information system owned by X Government Institution. The information system of X Government Institution would be assessed based on 14 clauses contained in ISO/IEC 27001: 2013. The method used is qualitative method, data collection and data validation with triangulation technique (interview, observation, and documentation). Data analysis used gap analysis and to measure the maturity level of this research used CMMI (Capability Maturity Model for Integration). The result of the research showed that information security which had been applied by X Government Institution was at level 1 (Initial) which meant there was evidence that the institution was aware of problems that needed to be overcome, unstandardized process, and tended to handle the problem individually or by case.

Cite

CITATION STYLE

APA

Maingak, A. Z., Candiwan, C., & Harsono, L. D. (2018). Information Security Assessment Using ISO/IEC 27001:2013 Standard on Government Institution. TRIKONOMIKA, 17(1), 28. https://doi.org/10.23969/trikonomika.v17i1.1138

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free