Information Security Risk Management Using ISO/IEC 27005 to Ensure the Continuity of Academic Services at UPN “Veteran” Yogyakarta

Authors

  • Juwairiah Juwairiah Information Systems Study Program, Faculty of Industrial Engineering, Universitas Pembangunan Nasional “Veteran” Yogyakarta, Indonesia
  • Herry Sofyan Information Systems Study Program, Faculty of Industrial Engineering, Universitas Pembangunan Nasional “Veteran” Yogyakarta, Indonesia
  • Hari Prapcoyo Information Systems Study Program, Faculty of Industrial Engineering, Universitas Pembangunan Nasional “Veteran” Yogyakarta, Indonesia
  • Rivan Adi Pardana Information Systems Study Program, Faculty of Industrial Engineering, Universitas Pembangunan Nasional “Veteran” Yogyakarta, Indonesia
  • Nauval Ghaina Mochamad Hanif Information Systems Study Program, Faculty of Industrial Engineering, Universitas Pembangunan Nasional “Veteran” Yogyakarta, Indonesia
  • Brigitta Chrishyandra Information Systems Study Program, Faculty of Industrial Engineering, Universitas Pembangunan Nasional “Veteran” Yogyakarta, Indonesia
  • Siti Fatimahtul Ughro Information Systems Study Program, Faculty of Industrial Engineering, Universitas Pembangunan Nasional “Veteran” Yogyakarta, Indonesia

DOI:

https://doi.org/10.31098/cset.v5i1.1180

Keywords:

Academic Information Systems; Information Security; ISO/IEC 27005; Risk Assessment; Risk Treatment

Abstract

UPA TIK of UPN ‘Veteran’ Yogyakarta operates four interdependent academic systems: Bima for academic administration, Spada Wimaya for online learning, Sadewa for student activities and achievements, and Nakula for lecturer services. Service interruptions caused by DDoS traffic, malware, unstable power, and hardware failure motivated a structured risk assessment. This study applies ISO/IEC 27005:2022 to identify, analyze, evaluate, and treat information security risks using asset-based scenarios. Evidence was obtained from document review, interface observation, interviews with the Head of UPA TIK as the risk owner and key informant, and a confirmatory survey of users. The assessment identified 257 risk scenarios: for primary assets, there are 34 in Bima, 37 in Spada Wimaya, 58 in Sadewa, 76 in Nakula, and 52 in supporting assets. Likelihood and consequence were scored on harmonized five-level scales and mapped to a 5 × 5 matrix. Based on the risk assessment results for 257 risk scenarios, 11 are high, 72 are medium, 131 are low, and 32 are very low. Consequently, 83 risks must be prioritized for mitigation using ISO/IEC 27001:2022 Annex A controls. Critical recommendations include capacity management for peak registration, redundant processing facilities and maintained power support, continuous malware protection, stronger upload validation, data classification and encryption, longer log retention, and formal incident ticketing. The principal contribution is an integrated assessment of four systems that share infrastructure and governance, producing one comparable risk register, Statement of Applicability, and implementation-oriented treatment plan. Residual risk will be measured after the recommended controls are implemented.

Downloads

Published

2026-10-07

Citation Check

How to Cite

Juwairiah, J., Sofyan, H., Prapcoyo, H., Pardana, R. A., Hanif, N. G. M., Chrishyandra, B., & Ughro, S. F. (2026). Information Security Risk Management Using ISO/IEC 27005 to Ensure the Continuity of Academic Services at UPN “Veteran” Yogyakarta. RSF Conference Series: Engineering and Technology, 5(1), 165–174. https://doi.org/10.31098/cset.v5i1.1180

Issue

Section

Articles