JUSTIN (Jurnal Sistem dan Teknologi Informasi)
Vol 10, No 2 (2022)

Development of Audit Information System Index KAMI Based on ISO/IEC 27001:2013

Paradise Paradise (Institut Teknologi Telkom Purwokerto)
Wahyu Adi Prabowo (Institut Teknologi Telkom Purwokerto)



Article Info

Publish Date
31 Jul 2022

Abstract

Information security is crucial and vital in digital era. Confidentiality and security of assets must be protected to minimize IT risks. An audit is needed to control whether the organization or agency has implemented information system security standards. One of the information system security audits that has an evaluation value of the level of readiness is to use the System Security Index (KAMI) based on ISO/27001 2013. KAMI is designed to assist organizations and institutions to conduct independent assessments and evaluate the level of readiness in implementing information security which includes the criteria for Governance, Risk Management, Framework, Asset Management, Information Security Technology, and Supplements. This study designed a system with an SDLC (System Development Life Cycle) approach consisting of Planning, Analysis, Design, and Implementation. The purpose of the development of the KAMI audit information system is to facilitate auditors and related parties in the audit process carried out using the KAMI Index based on ISO/IEC 27001:2013, so that auditors do not need to use Microsoft Excel again in the audit process. The results of this study are in the form of the KAMI Index information system website based on ISO/IEC 27001:2013. The conclusion from the blackbox testing results above is "Accepted", where the audit information system website based on ISO 27001:13 functions well and serves its users efficiently. There are no missing or incorrect functions, no errors in this test sign, value input test, document input test, and menu test. 

Copyrights © 2022






Journal Info

Abbrev

justin

Publisher

Subject

Computer Science & IT

Description

JUSTIN aims to publish research results and thoughts among academics, researchers, scientists, and practitioners in the field of informatics/computer science so that they are freely available to the public, and support the exchange of knowledge. The scope of JUSTIN is but is not limited to the ...