Journal of Information Systems Engineering and Business Intelligence
Vol. 8 No. 2 (2022): October

Information Security Risk Assessment (ISRA): A Systematic Literature Review

Rias Kumalasari Devi (Faculty of Computer Science, Universitas Indonesia, Indonesia)
Dana Indra Sensuse (Faculty of Computer Science, Universitas Indonesia, Indonesia)
Kautsarina (Faculty of Computer Science, Universitas Indonesia, Indonesia)
Ryan Randy Suryono (Faculty of Computer Science, Universitas Indonesia, Indonesia and Faculty of Engineering and Computer Science, Universitas Teknokrat Indonesia, Indonesia)



Article Info

Publish Date
29 Oct 2022

Abstract

Background: Information security is essential for organisations, hence the risk assessment. Information security risk assessment (ISRA) identifies, assesses, and prioritizes risks according to organisational goals. Previous studies have analysed and discussed information security risk assessment. Therefore, it is necessary to understand the models more systematically. Objective: This study aims to determine types of ISRA and fill a gap in literature review research by categorizing existing frameworks, models, and methods. Methods: The systematic literature review (SLR) approach developed by Kitchenham is applied in this research. A total of 25 studies were selected, classified, and analysed according to defined criteria. Results: Most selected studies focus on implementing and developing new models for risk assessment. In addition, most are related to information systems in general. Conclusion: The findings show that there is no single best framework or model because the best framework needs to be tailored according to organisational goals. Previous researchers have developed several new ISRA models, but empirical evaluation research is needed. Future research needs to develop more robust models for risk assessments for cloud computing systems.   Keywords: Information Security Risk Assessment, ISRA, Security Risk

Copyrights © 2022






Journal Info

Abbrev

JISEBI

Publisher

Subject

Computer Science & IT

Description

Jurnal ini menerima makalah ilmiah dengan fokus pada Rekayasa Sistem Informasi ( Information System Engineering) dan Sistem Bisnis Cerdas (Business Intelligence) Rekayasa Sistem Informasi ( Information System Engineering) adalah Pendekatan multidisiplin terhadap aktifitas yang berkaitan dengan ...