Information Security Risk Analysis Using ISO 31000:2018 and ISO 27001:2022

Authors

  • Athiyatul Ulya Universitas Malikussaleh, Indonesia
  • Annisa Karima Universitas Malikussaleh, Indonesia
  • T. Sukma Achriadi Sukiman Universitas Malikussaleh, Indonesia
  • Anni Zulfia Universitas Malikussaleh, Indonesia
  • Rafika Rahmawati Universitas Pembangunan Nasional Veteran Jawa Timur, Indonesia

DOI:

https://doi.org/10.47709/brilliance.v5i2.6564

Keywords:

Information Security, Risk Analysis, ISO 27001:2022, ISO 31000:2018, BPS

Abstract

Information system risk audits are an important step in ensuring the security, effectiveness, and efficiency of the systems used by organizations. However, the fast advancement of information and communication technologies has made information?security threats more intricate, arising not only from internal sources like employee carelessness but also from external sources such as cyber?attacks, malware, and data?theft. This study aims to analyze information security risks at the Central Statistics Agency (BPS) of Lhokseumawe by referring to two international standards, namely ISO/IEC 27001:2022 and ISO 31000:2018. The research approach used is descriptive qualitative with a case study method. Data collection techniques were conducted through interviews, observations, and document studies. The results of the study indicate that there are still various security gaps, both technical and non-technical, such as weak system authentication, the absence of adequate security policies, and the lack of incident handling procedures. This study successfully compiled a risk register containing 30 types of risks along with their causes, impacts, likelihood levels, and relevant mitigation recommendations. Improvement recommendations include strengthening technical controls, updating information security policies, enhancing human resource capacity, and conducting regular internal audits. The results of this study are expected to serve as a reference for strengthening information security systems in a systematic and standardized manner within the BPS environment.

References

Ardiansyah, A., Ilyas, A., & Haeranah. (2023). Reformulation Of Statistical Data Sources: Big Data New Data Sources Supporting Future Official Statistics? Injuruty: Interdiciplinary Journal and Humanity.

Aven, T., & Ylönen, M. (2019). The strong power of standards in the safety and risk fields: A threat to proper developments of these fields? Reliability Engineering & System Safety, 279-286.

Aven, T. (2016). Risk Assessment and Risk Management: Review of Recent Advances on Their Foundations. European Journal of Operational Research, 1-13.

British Standard Institusion. (2018). ISO 31000:2018 - Risk Management Guidelines. Switzerland: BSI Standards Limited.

Creswell, J. W. (2014). Research Design: Qualitative, Quantitative, and Mixed Methods Approaches. Singapore: Sage Publications.

Gillis, A. S. (2025, June 30). What is the ISO 31000 Risk Management standard? Retrieved from Tech Target: https://www.techtarget.com/searchsecurity/definition/ISO-31000-Risk-Management

Hopkin, P. (2018). Fundamentals of Risk Management: Understanding, Evaluating and Implementing Effective Risk Management. London: Kogan Page Publishers.

H.?Knight, F. (1921). Risk, Uncertainty and Profit.

International Standard Organization. (2022). ISO 27001:2022 - Information Security Management Systems. Switzerland: BSI Standards Limited.

Institute of Risk Management. (2018). Standard Deviations A Risk Practitioners Guide to ISO 31000. Retrieved from The IRM: https://www.theirm.org/media/6884/irm-report-iso-31000-2018-v2.pdf

IT Governance USA. (2022). SO?27001 and ISO?27002 2022 updates. Retrieved from IT Governance: https://www.itgovernanceusa.com/iso27001-and-iso27002-2022-updates

Pubrica. (2025). What Is the Purpose and Importance of Literature Reviews in Research? England: Pubrica.

Putri, T. S., Mutiah, N. M., & Prawira, D. P. (2022). Analisis Manajemen Risiko Keamanan Informasi Menggunakan Nist Cybersecurity Framework Dan ISO/IEC 27001: 2013 (Studi Kasus: Badan Pusat Statistik Kalimantan Barat). Coding: Jurnal Komputer dan Aplikasi, 237-248.

Rachman, A., Yochanan, E., Samanlangi, A. I., & Purnomo, H. (2024). Metode Penelitian Kualitatif, Kuantitatif, dan R&D. Karawang: Saba Jaya Publisher.

Wiener. (2021). Risk Management in the Public Sector: A Systematic Literature Review. . International Journal of Public Administration, 44(10), 850-867.

Xu, T., Shi, H., Shi, Y., & You, J. (2023). From data to data asset:conceptual evolution and strategic imperatives in thedigital economy era. Asia Pacific Journal of Innovation and Entrepreneurship.

Yin, R. K. (2009). Case Study Research: Design and Methods (4th ed.). United State of America: SAGE Publications.

Downloads

Published

2025-09-08

How to Cite

Ulya, A., Karima, A., Sukiman, T. S. A., Zulfia, A., & Rahmawati, R. (2025). Information Security Risk Analysis Using ISO 31000:2018 and ISO 27001:2022. Brilliance: Research of Artificial Intelligence, 5(2), 843–853. https://doi.org/10.47709/brilliance.v5i2.6564

Most read articles by the same author(s)

Similar Articles

1 2 3 4 5 6 7 8 9 10 > >> 

You may also start an advanced similarity search for this article.