SIMRS RISK ASSESSMENT USING OCTAVE ALLEGRO METHOD AND ISO/IEC 27001:2022 CONTROL STANDARD

Authors

  • Ito Setiawan Universitas Amikom Purwokerto image/svg+xml
  • Kharisma Putri Sholekha Universitas Amikom Purwokerto
  • Retno Waluyo Universitas Amikom Purwokerto

DOI:

https://doi.org/10.33480/jitk.v12i1.7670

Keywords:

Information Security, ISO/IEC 27001:2022, OCTAVE Allegro, Risk Assessment, SIMRS

Abstract

Cilacap Regional General Hospital has been using the SIMRS system since 2006 to the present day. however, its use has encountered several challenges, such as human error, lengthy data synchronisation processes and time-consuming application maintenance. Previous studies have analyzed risk assessments regarding application usage, yet there is a gap in the implementation of risk mitigation.  The aim of the research is to carry out a risk assessment of the SIMRS using the OCTAVE Allegro method and to propose risk mitigation measures in accordance with ISO/IEC 27001. The novelty of this research lies in the combination of methods used to conduct risk assessment and mitigation utilising the ISO/IEC 27001:2022 control standards. Results of research identify the areas of impact, reputation, finance and productivity. The areas of concern are human error, hardware management and software management. Scenarios were developed based on these areas of concern; according to the calculations, the score for human error was 31, for hardware management 24 and for software management 18. Mitigation, as set out in ISO/IEC 27001:2022, focuses on organisational controls in clauses 5.1, 5.15, 5.24, 5.26, 5.28, 5.33, 5.37. People controls in clauses 6.2, 6.3, 6.5, 6.8. Physical controls in clauses 7.5, 7.7, 7.10, 7.12, 7.13. Technological controls in clauses 8.2, 8.5, 8.7, 8.12, 8.13, 8.20, 8.22, 8.32. The scientific contribution lies in the integration of the OCTAVE Allegro and ISO/IEC 27001:2022 approaches to produce a risk assessment process that is not only capable of identifying and prioritising risks, but also directly provides relevant security controls.

Downloads

Download data is not yet available.

References

[1] E. B. Pratama and A. Hendini, “Implementasi Extreme Programming Pada Perancangan SIMRS (Sistem Informasi Manajemen Rumah Sakit),” J. Khatulistiwa Inform., vol. 10, no. 2, pp. 107–112, 2022, doi: 10.31294/jki.v10i2.14159.

[2] R. T. Perkasa and F. Samopa, “Analisa Pengembangan Fitur Lebih Lanjut dengan Pendekatan Requirement Analysis dan Design Thinking,” Kesatria J. Penerapan Sist. Inf. (Komputer Manajemen), vol. 5, no. 3, pp. 866–873, 2024, doi: 10.30645/kesatria.v5i3.412.

[3] G. Winarti, “Literature Review: Faktor Keberhasilan Implementasi Sistem Informasi Manajemen Rumah Sakit (SIMRS),” Communnity Dev. J., vol. 4, no. 1, pp. 486–497, 2023.

[4] I. V. Santosa, M. N. Subekti, G. S. Jagaddhito, and A. D. Susanti, “Analisis Implementasi Sistem Informasi Manajemen Rumah Sakit (SIMRS) dalam Meningkatkan Pengelolaan Rumah Sakit yang Efisien di Rumah Sakit Umum Daerah Surakarta,” Sejah. J. Inspirasi Mengabdi Untuk negeri, vol. 3, no. 1, pp. 189–197, 2024, doi: 10.58192/sejahtera.v3i1.1716.

[5] Suriani, O. Keteren, and J. Hutajulu, “Studi Penerapan Aplikasi Sistem Informasi Manajemen Rumah Sakit (SIMRS),” J. Telenursing, vol. 5, no. 1, pp. 245–253, 2023, doi: 10.26418/justin.v12i4.78493.

[6] M. Suorsa and P. Helo, “Information security failures identified and measured–ISO/IEC 27001:2013 controls ranked based on GDPR penalty case analysis,” Inf. Secur. J., vol. 33, no. 3, pp. 285–306, 2024, doi: 10.1080/19393555.2023.2270984.

[7] T. P. P. Kusuma, I. Setiawan, M. A. Aziz, and B. D. Putranto, “Manajemen Risiko Sistem Informasi Akademik Menggunakan OCTAVE Allegro dan ISO/EIC 27001 di Universitas Perwira Purbalingga,” JUSTIN J. Sist. dan Teknol. Inf., vol. 12, no. 4, pp. 592–598, 2024, doi: 10.26418/justin.v12i4.78493.

[8] H. Julianni and E. Rachmawati, “Analisis Persepsi Resiko Terhadap Minat Beli Produk Makanan Online Pada Aplikasi Shopee,” JEMPER (Jurnal Ekon. Manaj. Perbankan), vol. 6, no. 2, pp. 120–129, 2024, doi: 10.32897/jemper.v6i2.3309.

[9] W. Harefa and K. D. Hartomo, “Analisis Manajemen Risiko Dengan Menggunakan Framework ISO 31000:2018 Pada Sistem Informasi Gudang,” J. Tek. Inform. dan Sist. Inf., vol. 9, no. 1, pp. 407–420, 2022, doi: W. Harefa and K. D. Hartomo, “Analisis Manajemen Risiko Dengan Menggunakan Framework ISO 31000:2018 Pada Sistem Informasi Gudang,” J. Tek. Inform. dan Sist. Inf., vol. 9, no. 1, pp. 407–420, 2022.

[10] P. N. Emmanuel and R. Maulany, “Penilaian Risiko Sistem Informasi Menggunakan Metode OCTAVE Allegro pada Indonesia Publishing House,” Krea-Tif J. Tek. Inform., vol. 11, no. 1, pp. 37–52, 2023, doi: 10.32832/krea-tif.v11i1.14179.

[11] R. Zefri, D. A. Wulandari, and Suripin, “Analisis Risiko Kegagalan Bendungan Paselloreng Dengan Metode Pohon Kejadian (Event Tree),” SIKLUS J. Tek. Sipil, vol. 8, no. 2, pp. 149–160, 2022, doi: 10.34010/jati.v12i2.6829.

[12] I. P. A. S. Putra and I. K. R. Hendrawan, “Analisis Manajemen Risiko SIMRS pada Rumah Sakit Ganesha Menggunakan ISO 31000,” JATI J. Teknol. dan Inf., vol. 14, no. 1, pp. 88–98, 2024, doi: 10.34010/jati.v14i1.

[13] F. Kitsios, E. Chatzidimitriou, and M. Kamariotou, “The ISO/IEC 27001 Information Security Management Standard: How to Extract Value from Data in the IT Sector,” Sustain., vol. 15, no. 7, 2023, doi: 10.3390/su15075828.

[14] H. Sulaeman, H. P. Utomo, and A. I. Suryana, “Penilaian Risiko Keamanan Informasi Pada Sistem Informasi Akademik (SIAKAD) Dengan Menggunakan Framework NIST-SP 800 30,” in Prosiding Seminar Nasional Teknologi Komputer dan Sains, 2023, pp. 414–432.

[15] A. Arista and K. N. M. Ngafidin, “An Information System Risk Management of a Higher Education Computing Environment,” Int. J. Adv. Sci. Eng. Inf. Technol., vol. 12, no. 2, pp. 557–564, 2022, doi: 10.18517/ijaseit.12.2.13953.

[16] M. Rifial, A. Razak, D. Darmawansyah, I. Indar, and A. Rahman, “Evaluation of the Utilization of the Hospital Management Information System (SIMRS) at Madani Regional General Hospital, Palu,” J. Public Heal. Pharm., vol. 5, no. 2, pp. 274–286, 2025, doi: 10.56338/jphp.v5i2.6169.

[17] B. S. Deva and R. Jayadi, “Analisis Risiko dan Keamanan Informasi pada Sebuah Perusahaan System Integrator Menggunakan Metode Octave Allegro,” J. Teknol. dan Inf., vol. 12, no. 2, pp. 106–117, 2022, doi: 10.34010/jati.v12i2.6829.

[18] Suroso and Wasilah, “Analisis Keamanan Informasi SIMRS dengan Metode Indeks KAMI dan OCTAVE Allegro,” J. Tek., vol. 19, no. 3, pp. 795–808, 2025, doi: 10.35446/teknika.v19i3.10705.

[19] S. Alfarisi and N. Surantha, “Risk assessment in fleet management system using OCTAVE allegro,” Bull. Electr. Eng. Informatics, vol. 11, no. 1, pp. 530–540, 2022, doi: 10.11591/eei.v11i1.3241.

[20] T. Ali, M. Al-Khalidi, and R. Al-Zaidi, “Information Security Risk Assessment Methods in Cloud Computing: Comprehensive Review,” J. Comput. Inf. Syst., vol. 66, no. 1, pp. 123–150, 2026, doi: 10.1080/08874417.2024.2329985.

[21] R. W. Astuti, R. A. Putra, and I. S. Putra, “Penilaian Risiko Penggunaan Sistem Informasi Akademik Pada STIQ Al-Lathifiyyah Palembang Dengan Metode Octave Allegro,” J. Comput. Inf. Syst. Ampera, vol. 4, no. 1, pp. 44–54, 2023, doi: 10.51519/journalcisa.v4i1.337.

[22] R. F. P. Wahyu, R. G. Utomo, and M. Al Makky, “Analisis Risiko Keamanan Informasi Pada Divisi Penjualan Pt Matahari Department Store Cabang Jogja City Mall Menggunakan Metode Octave Allegro,” in e-Proceeding of Engineering, 2023, pp. 5073–5079.

[23] H. A. Setia, E. M. Safitri, V. R. Putri, and C. P. Wibowo, “Analisis Keamanan Website Dinas Perhubungan Provinsi Jawa Timur Menggunakan Metode OCTAVE Allegro Dan FMEA,” in Prosiding Seminar Nasional Teknologi dan Sistem Informasi (SITASI), 2023, pp. 299–308, doi: 10.33005/sitasi.v3i1.554.

[24] A. A. Ipungkarti, “Penerapan IT Security Awareness Standar Keamanan ISO 27001 Di BPJS Ketenagakerjaan Kantor Cabang Purwakarta,” J. Media Infotama, vol. 19, no. 1, pp. 103–110, 2023, doi: 10.37676/jmi.v19i1.3481.

[25] B. Aurabillah, L. A. Putri, N. C. Fadhlilla, and A. Wulansari, “Implementasi Framework ISO 27001 Sebagai Proteksi Keamanan Informasi Dalam Pemerintahan (Systematic Literature Review),” JATI (Jurnal Mhs. Tek. Inform., vol. 8, no. 1, pp. 454–460, 2024, doi: 10.36040/jati.v8i1.8736.

[26] K. Sari, A. Harnia, S. N. Hidayah, and N. Sri, “Integrated Strategy For Information System Security Assessment Through The Implementation Of ISO 27001 Standards,” in International Conference on Computer Science, Engineering, Social Science, and Multi-Disciplinary Studies (CESSMUDS), 2025, pp. 668–671, doi: 10.64803/cessmuds.v1.129.

[27] P. Prasetyo and G. Yudoko, “Information Security Management System Transition Strategy From ISO/IEC 27001:2013 To ISO/IEC 27001:2022 At PT PKT,” Ekombis Rev. J. Ilm. Ekon. dan Bisnis, vol. 14, no. 2, pp. 2587–2600, 2026, [Online]. Available: https://jurnal.unived.ac.id/index.php/er/indexDOI:https://doi.org/10.37676/ekombis.v14i2

[28] D. Widiyasti, I. Rusi, and F. Febriyanto, “Manajemen Risiko Keamanan Teknologi Informasi Menggunakan Metode OCTAVE Allegro Dan Kontrol ISO/IEC 27001:2013 (Studi Kasus: PLN UP2D Kalimantan Barat),” CODING J. Komput. dan Apl., vol. 11, no. 02, pp. 227–237, 2023, doi: 10.26418/coding.v11i2.62011.

[29] M. T. Anwar, U. Aryanti, M. Wijana, and D. Atmoko, “Mitigasi Risiko Keamanan Informasi Menggunakan SNI ISO / IEC 27001 : 2013 Berbasis Manajemen Risiko OCTAVE Allegro di Perguruan Tinggi : Studi kasus Perguruan Tinggi x,” Informatics Educ. Prof. J. Informatics, vol. 9, no. 1, pp. 73–83, 2024, doi: 10.51211/itbi.v9i1.2913.

[30] N. R. Romadhoni, M. S. Hasibuan, and K. Muludi, “Analisis Keamanan Informasi pada Sistem Komputerisasi Terpadu Menggunakan Metode Indeks KAMI dan Octave Allegro,” J. Ilmu Komput. Agri-Informatika, vol. 12, no. 1, pp. 38–49, 2025, doi: 10.29244/jika.12.1.38-49.

Downloads

Published

2026-08-19

How to Cite

[1]
“SIMRS RISK ASSESSMENT USING OCTAVE ALLEGRO METHOD AND ISO/IEC 27001:2022 CONTROL STANDARD”, jitk, vol. 12, no. 1, pp. 237–245, Aug. 2026, doi: 10.33480/jitk.v12i1.7670.