MANAJEMEN RISIKO TEKNOLOGI INFORMASI BERBASIS NIST SP800-30 DI UNIVERSITAS JENDERAL ACHMAD YANI
Abstract
As an educational institution of the University of General Achmad Yani certainly utilizes information technology to support the ongoing sustainability of information systems. For Unjani information technology is one of the most important part in the management of information systems, where the success of college services one of them depends on the extent to which the management of information technology has been done. However, in the use of information technology is not always running as expected, in the process of its use often appear risks - risks that can disrupt the sustainability of information systems so that it can cause harm to both material and nonmaterial losses. So that information technology risk management is very important to be applied at the University of General Achmad Yani, because with the implementation of risk management is expected to reduce the risk that will occur in information technology. Risk assessment at the University of General Achmad Yani will be implemented using the NIST Sp800-30 framework, the objective of this risk assessment is to define the risks that may occur in information technology at the University of General Achmad Yani and provide recommendations for control for the prevention of such risks.