Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan

Sistem Informasi Administrasi Kependudukan (SIAK) is an application used in managing personal data of residents in all cities/districts in Indonesia. Personal data becomes the public attention because if it is not managed properly it will have an impact on one's legal protection and non-complia...

Full description

Bibliographic Details
Main Authors: Iqbal Santosa, Raras Yusvinindya
Format: Article
Language:English
Published: Ikatan Ahli Informatika Indonesia 2019-12-01
Series:Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi)
Subjects:
Online Access:http://jurnal.iaii.or.id/index.php/RESTI/article/view/1068
_version_ 1797334122926964736
author Iqbal Santosa
Raras Yusvinindya
author_facet Iqbal Santosa
Raras Yusvinindya
author_sort Iqbal Santosa
collection DOAJ
description Sistem Informasi Administrasi Kependudukan (SIAK) is an application used in managing personal data of residents in all cities/districts in Indonesia. Personal data becomes the public attention because if it is not managed properly it will have an impact on one's legal protection and non-compliance with regulations, i.e. Permenkominfo Nomor 20 tahun 2016 about Protection of Personal Data in the Electronic System. Risk analysis and control of personal data protection on SIAK applications are needed so that the personal data management can be carried out properly and comply with regulatory requirements. Data collected for this study are primary data, sourced from direct observations on the application, interview about assets related to SIAK along with possible risks, and also internal organizations documents. Data analysis was performed with a risk analysis using the ISO 31000: 2018 risk management process approach, where the identification of relevant risks refers to the Generic Risk Scenarios COBIT 5 For Risk, and the determination of relevant controls refers to the Department of Defense Instruction 8500.2 and NIST 800-53. This research involves the Head of Department and employees of Disdukcapil XYZ City that are related to the strategic and operational aspects of SIAK. The results of this study are the identification of 23 possible risks that are spread over 5 processes of personal data protection that classified into the medium-high risk level, and proposed risk control consisting of 19 preventive controls, 6 detective controls, and 2 corrective control.
first_indexed 2024-03-08T08:16:07Z
format Article
id doaj.art-21ae232e0d2b4b76b5dc71efa78abdde
institution Directory Open Access Journal
issn 2580-0760
language English
last_indexed 2024-03-08T08:16:07Z
publishDate 2019-12-01
publisher Ikatan Ahli Informatika Indonesia
record_format Article
series Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi)
spelling doaj.art-21ae232e0d2b4b76b5dc71efa78abdde2024-02-02T07:24:12ZengIkatan Ahli Informatika IndonesiaJurnal RESTI (Rekayasa Sistem dan Teknologi Informasi)2580-07602019-12-013349650410.29207/resti.v3i3.10681068Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi KependudukanIqbal Santosa0Raras Yusvinindya1Telkom UniversityUniversitas Telkom Sistem Informasi Administrasi Kependudukan (SIAK) is an application used in managing personal data of residents in all cities/districts in Indonesia. Personal data becomes the public attention because if it is not managed properly it will have an impact on one's legal protection and non-compliance with regulations, i.e. Permenkominfo Nomor 20 tahun 2016 about Protection of Personal Data in the Electronic System. Risk analysis and control of personal data protection on SIAK applications are needed so that the personal data management can be carried out properly and comply with regulatory requirements. Data collected for this study are primary data, sourced from direct observations on the application, interview about assets related to SIAK along with possible risks, and also internal organizations documents. Data analysis was performed with a risk analysis using the ISO 31000: 2018 risk management process approach, where the identification of relevant risks refers to the Generic Risk Scenarios COBIT 5 For Risk, and the determination of relevant controls refers to the Department of Defense Instruction 8500.2 and NIST 800-53. This research involves the Head of Department and employees of Disdukcapil XYZ City that are related to the strategic and operational aspects of SIAK. The results of this study are the identification of 23 possible risks that are spread over 5 processes of personal data protection that classified into the medium-high risk level, and proposed risk control consisting of 19 preventive controls, 6 detective controls, and 2 corrective control.http://jurnal.iaii.or.id/index.php/RESTI/article/view/1068data pribadiiso 31000perlindungan data pribadisistem informasi administrasi kependudukansiak
spellingShingle Iqbal Santosa
Raras Yusvinindya
Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan
Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi)
data pribadi
iso 31000
perlindungan data pribadi
sistem informasi administrasi kependudukan
siak
title Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan
title_full Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan
title_fullStr Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan
title_full_unstemmed Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan
title_short Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan
title_sort analisis risiko dan kontrol perlindungan data pribadi pada sistem informasi administrasi kependudukan
topic data pribadi
iso 31000
perlindungan data pribadi
sistem informasi administrasi kependudukan
siak
url http://jurnal.iaii.or.id/index.php/RESTI/article/view/1068
work_keys_str_mv AT iqbalsantosa analisisrisikodankontrolperlindungandatapribadipadasisteminformasiadministrasikependudukan
AT rarasyusvinindya analisisrisikodankontrolperlindungandatapribadipadasisteminformasiadministrasikependudukan