International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 184 - Number 27 |
Year of Publication: 2022 |
Authors: Odjie Dwianto, Imam Riadi |
10.5120/ijca2022922331 |
Odjie Dwianto, Imam Riadi . Risk Assessment Analysis of Medical Information System Services using COBIT 5 Framework. International Journal of Computer Applications. 184, 27 ( Sep 2022), 7-17. DOI=10.5120/ijca2022922331
PT. MandatechMataram Mukti is providers for application social service in theYogyakarta area. Risk management requires risk assessment analysis of ongoing business processes for business processes to run well. COBIT 5 is here to answer the challenges of this modern era, especially risk management. The need for a risk assessment analysis to measure the extent to which elements apply risk management to the enterprise. The purpose of this study is to determine the current Capability Level value (capability level) and expected value, calculate gap value, and provide recommendations following APO12 (Manage Risk) and EDM03 (Ensure Risk Optimization) domains. Risk management assessment analysis in this study uses the COBIT 5 framework using the APO12 (Manage Risk) and EDM03 (Ensure Risk Optimization) process domains including the stages of data collection, risk analysis, risk profile, risk articulation, risk tolerance values, ways to respond to risks, evaluate risk management and direct risk management. The research stages carried out have three stages of research analysis: determining the current capability, expected levels, conducting gap analysis, and providing recommendations and suggestions for improvement. Based on the results of calculations carried out in this study, the level of domain APO12 capabilities currently (Manage Risk) gets a score of 1.83 is at level 1 (Performed Process) meaning that the IT process in Medical Information System Services has carried out management and governance efforts properly. The APO12 (Manage Risk) domains gets a gap value of 1. Capability Level in EDM03(Ensuring Risk Optimization) domains gets a capability value of 1.62 (PerfomedProcess) for expected capability value at domain capability level APO12 and EDM03 is at level 2, for the result of calculation of gap value get a gap value of 1 in the EDM03(Ensuring Risk Optimization) domains, recommendations produced in this study are the following expected company objectives.