Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan
Sistem Informasi Administrasi Kependudukan (SIAK) is an application used in managing personal data of residents in all cities/districts in Indonesia. Personal data becomes the public attention because if it is not managed properly it will have an impact on one's legal protection and non-complia...
Main Authors: | , |
---|---|
Format: | Article |
Language: | English |
Published: |
Ikatan Ahli Informatika Indonesia
2019-12-01
|
Series: | Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi) |
Subjects: | |
Online Access: | http://jurnal.iaii.or.id/index.php/RESTI/article/view/1068 |
_version_ | 1797334122926964736 |
---|---|
author | Iqbal Santosa Raras Yusvinindya |
author_facet | Iqbal Santosa Raras Yusvinindya |
author_sort | Iqbal Santosa |
collection | DOAJ |
description | Sistem Informasi Administrasi Kependudukan (SIAK) is an application used in managing personal data of residents in all cities/districts in Indonesia. Personal data becomes the public attention because if it is not managed properly it will have an impact on one's legal protection and non-compliance with regulations, i.e. Permenkominfo Nomor 20 tahun 2016 about Protection of Personal Data in the Electronic System. Risk analysis and control of personal data protection on SIAK applications are needed so that the personal data management can be carried out properly and comply with regulatory requirements. Data collected for this study are primary data, sourced from direct observations on the application, interview about assets related to SIAK along with possible risks, and also internal organizations documents. Data analysis was performed with a risk analysis using the ISO 31000: 2018 risk management process approach, where the identification of relevant risks refers to the Generic Risk Scenarios COBIT 5 For Risk, and the determination of relevant controls refers to the Department of Defense Instruction 8500.2 and NIST 800-53. This research involves the Head of Department and employees of Disdukcapil XYZ City that are related to the strategic and operational aspects of SIAK. The results of this study are the identification of 23 possible risks that are spread over 5 processes of personal data protection that classified into the medium-high risk level, and proposed risk control consisting of 19 preventive controls, 6 detective controls, and 2 corrective control. |
first_indexed | 2024-03-08T08:16:07Z |
format | Article |
id | doaj.art-21ae232e0d2b4b76b5dc71efa78abdde |
institution | Directory Open Access Journal |
issn | 2580-0760 |
language | English |
last_indexed | 2024-03-08T08:16:07Z |
publishDate | 2019-12-01 |
publisher | Ikatan Ahli Informatika Indonesia |
record_format | Article |
series | Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi) |
spelling | doaj.art-21ae232e0d2b4b76b5dc71efa78abdde2024-02-02T07:24:12ZengIkatan Ahli Informatika IndonesiaJurnal RESTI (Rekayasa Sistem dan Teknologi Informasi)2580-07602019-12-013349650410.29207/resti.v3i3.10681068Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi KependudukanIqbal Santosa0Raras Yusvinindya1Telkom UniversityUniversitas Telkom Sistem Informasi Administrasi Kependudukan (SIAK) is an application used in managing personal data of residents in all cities/districts in Indonesia. Personal data becomes the public attention because if it is not managed properly it will have an impact on one's legal protection and non-compliance with regulations, i.e. Permenkominfo Nomor 20 tahun 2016 about Protection of Personal Data in the Electronic System. Risk analysis and control of personal data protection on SIAK applications are needed so that the personal data management can be carried out properly and comply with regulatory requirements. Data collected for this study are primary data, sourced from direct observations on the application, interview about assets related to SIAK along with possible risks, and also internal organizations documents. Data analysis was performed with a risk analysis using the ISO 31000: 2018 risk management process approach, where the identification of relevant risks refers to the Generic Risk Scenarios COBIT 5 For Risk, and the determination of relevant controls refers to the Department of Defense Instruction 8500.2 and NIST 800-53. This research involves the Head of Department and employees of Disdukcapil XYZ City that are related to the strategic and operational aspects of SIAK. The results of this study are the identification of 23 possible risks that are spread over 5 processes of personal data protection that classified into the medium-high risk level, and proposed risk control consisting of 19 preventive controls, 6 detective controls, and 2 corrective control.http://jurnal.iaii.or.id/index.php/RESTI/article/view/1068data pribadiiso 31000perlindungan data pribadisistem informasi administrasi kependudukansiak |
spellingShingle | Iqbal Santosa Raras Yusvinindya Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan Jurnal RESTI (Rekayasa Sistem dan Teknologi Informasi) data pribadi iso 31000 perlindungan data pribadi sistem informasi administrasi kependudukan siak |
title | Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan |
title_full | Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan |
title_fullStr | Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan |
title_full_unstemmed | Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan |
title_short | Analisis Risiko dan Kontrol Perlindungan Data Pribadi pada Sistem Informasi Administrasi Kependudukan |
title_sort | analisis risiko dan kontrol perlindungan data pribadi pada sistem informasi administrasi kependudukan |
topic | data pribadi iso 31000 perlindungan data pribadi sistem informasi administrasi kependudukan siak |
url | http://jurnal.iaii.or.id/index.php/RESTI/article/view/1068 |
work_keys_str_mv | AT iqbalsantosa analisisrisikodankontrolperlindungandatapribadipadasisteminformasiadministrasikependudukan AT rarasyusvinindya analisisrisikodankontrolperlindungandatapribadipadasisteminformasiadministrasikependudukan |