International Journal of Computer Applications |
Foundation of Computer Science (FCS), NY, USA |
Volume 185 - Number 28 |
Year of Publication: 2023 |
Authors: Akmal Rizqi Azhari, Imam Riadi |
10.5120/ijca2023923031 |
Akmal Rizqi Azhari, Imam Riadi . Risk Assessment Analysis Website on Tech Company using OCTAVE Allegro Framework. International Journal of Computer Applications. 185, 28 ( Aug 2023), 25-30. DOI=10.5120/ijca2023923031
Tech Company website is an information system service that supports the ongoing processes of service delivery in the organization, including administration, portfolio, and business process management. However, in the website's information system service, risk assessment needs to be conducted to identify potential threats. In this research study, risk assessment is performed using the OCTAVE Allegro framework. Tech Company is a private enterprise located in Yogyakarta. The aim of this study is to provide recommendations to Tech Company Mukti Yogyakarta regarding vulnerabilities and threats that occur. Risk assessment consists of several stages, including analyzing data obtained through interviews, responses from worksheets, and questionnaires filled out by employees working at Tech Company. The OCTAVE Allegro method is divided into 8 steps, which are building risk measurement criteria; developing a profile of the information assets owned; identifying containers within the information assets; identifying problem areas in the three aspects of the containers, namely technical, physical, and people; identifying threat scenarios; identifying risks; analyzing risks; and selecting mitigation and control approaches based on the suitability of the relative risk score calculations. The testing results conducted on the information system service of Tech Company yielded 4 containers with a mitigation approach, 2 containers with a defer approach, and 2 containers with an accept approach. The highest relative risk score was obtained in the Physical Container (PhC) with a total score of 28, mainly due to natural disasters. The lowest relative risk score was found in Technical Container (TC) 1 and 2, caused by disruptions in internet connectivity leading to service disruptions and temporary interruptions, as well as service interruptions caused by system updates