Analisis Manajemen Risiko TI Menggunakan ISO31000 Pada PT ABC
DOI:
https://doi.org/10.32524/jusitik.v9i2.1997Keywords:
Information Technology, ISO31000, Qualitative Study, Risk Management, Risk TreatmentAbstract
PT ABC is a pawn-based financial service company that relies on information technology to support operational activities at the head office and branches. This study aims to analyze IT risk management using the ISO31000 framework. The research used a qualitative case study approach through interviews, observation, and internal document review. The risk management process included communication and consultation, scope and criteria determination, risk assessment, risk treatment, recording and reporting, and monitoring and review. The results identified 21 IT risks related to hardware, software, networks, security, and operational procedures. Based on the risk evaluation matrix, 4 risks were classified as High, namely server down, slow system performance, 502 gateway, and server overload, while 17 risks were classified as Medium. The recommended risk treatments include increasing server capacity, monitoring system performance, strengthening network security, improving SOPs, managing access rights, and conducting regular risk review.
Key Words: Information Technology, ISO31000, Qualitative Study, Risk Management, Risk Treatment
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Ayu Elisya Natama Sianturi, Wianti Maharani, Sri Andayani

This work is licensed under a Creative Commons Attribution 4.0 International License.




