Pratama, Ryan Adi Putra (2026) Pembuatan SOP Pengelolaan Akun Multi-Factor Authentication Berdasarkan Root Cause Analysis Menggunakan Framework ITIL V4 (Studi Kasus: DPTSI ITS). Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
5026221161-Undergraduate_Thesis.pdf - Accepted Version Restricted to Repository staff only Download (8MB) | Request a copy |
Abstract
Direktorat Pengembangan Teknologi dan Sistem Informasi (DPTSI) Institut Teknologi Sepuluh Nopember (ITS) berperan penting dalam memastikan keandalan layanan teknologi informasi bagi sivitas akademika. Namun, dalam operasionalnya masih sering terjadi insiden berulang terkait kendala login layanan myITS Single Sign-On (SSO) yang berakar pada masalah pengelolaan akun Multi-Factor Authentication (MFA). Insiden ini berdampak pada penurunan produktivitas pengguna dan penambahan beban kerja staf service desk. Oleh karena itu, penelitian ini bertujuan untuk menyusun Standar Operasional Prosedur (SOP) pengelolaan akun MFA dengan pendekatan Root Cause Analysis (RCA) yang diselaraskan dengan praktik Problem Management pada framework ITIL V4 dan standar keamanan autentikasi NIST SP 800-63B-4. Penelitian ini menggunakan metode kualitatif deskriptif yang diawali dengan pengumpulan data spesifik terkait insiden gagal login MFA dari sistem service desk DPTSI tahun 2025. Data tersebut dianalisis lebih lanjut melalui wawancara dengan staf service desk dan representasi pengguna, serta pemetaan akar penyebab menggunakan metode 5 Whys dan Fishbone Diagram. Penilaian tingkat risiko kemudian dilakukan menggunakan metode Failure Mode and Effects Analysis (FMEA). Hasil analisis menemukan dua akar penyebab utama dengan nilai Risk Priority Number (RPN) tertinggi, yaitu belum tersedianya panduan teknis penggantian perangkat (ganti device) secara mandiri yang diperparah dengan kurangnya sosialisasi berkelanjutan (RPN 810), serta belum adanya kebijakan yang mewajibkan pengisian kontak alternatif (RPN 729). Temuan ini menunjukkan bahwa insiden berulang lebih banyak disebabkan oleh rendahnya literasi pengguna dalam kelola MFA, bukan dari kegagalan teknis sistem. Selain itu, ditemukan pula kesenjangan antara praktik operasional eksisting dengan standar NIST SP 800-63B-4, seperti ketiadaan prosedur penanganan dugaan akses tidak sah dan tidak adanya notifikasi pembaruan metode autentikasi. Berdasarkan temuan akar masalah tersebut, penelitian ini menghasilkan SOP Pengelolaan MFA myITS (DPTSI-SOP-MFA-001) yang prosedur penanganannya diturunkan secara spesifik dari hasil rumusan Root Cause Analysis (RCA), bukan sekadar mengambil prosedur Incident Management dari ITIL V4 secara umum. SOP ini memuat 31 langkah terpadu yang mencakup sosialisasi, aktivasi, penanganan kendala login, penanganan dugaan akses tidak sah, hingga evaluasi berkala. Dokumen ini juga dilengkapi dengan tiga formulir pendukung dan panduan praktis penggantian perangkat bagi pengguna. SOP tersebut telah melalui tahap verifikasi oleh Kepala Subdit Layanan DPTSI dan validasi oleh staf service desk, dengan hasil dinyatakan tepat secara isi dan layak diterapkan pada lingkungan operasional DPTSI ITS guna menekan frekuensi insiden berulang di masa mendatang.
======================================================================================================================================
The Directorate of Information Technology and Systems Development (DPTSI) at Institut Teknologi Sepuluh Nopember (ITS) plays a crucial role in ensuring the reliability of information technology services for the academic community. However, in its operations, recurring incidents frequently occur regarding login issues to the myITS Single Sign-On (SSO) service, which are rooted in Multi-Factor Authentication (MFA) account management problems. These incidents result in decreased user productivity and an increased workload for service desk staff. Therefore, this research aims to develop a Standard Operating Procedure (SOP) for MFA account management using a Root Cause Analysis (RCA) approach, aligned with the Problem Management practice in the ITIL V4 framework and the NIST SP 800-63B-4 authentication security standard. This research employs a descriptive qualitative method, beginning with the collection of specific data related to MFA login failure incidents from the DPTSI service desk system in 2025. The data was further analyzed through interviews with service desk staff and user representatives, along with root cause mapping using the 5 Whys and Fishbone Diagram methods. A risk level assessment was then conducted using the Failure Mode and Effects Analysis (FMEA) method. The analysis results identified two main root causes with the highest Risk Priority Number (RPN) values: the unavailability of a technical guide for independent device replacement combined with a lack of continuous socialization (RPN 810), and the absence of a policy requiring the registration of alternative contacts (RPN 729). These findings indicate that recurring incidents are largely caused by users' low literacy in managing MFA, rather than technical system failures. Additionally, gaps were found between existing operational practices and the NIST SP 800-63B-4 standard, such as the absence of procedures for handling suspected unauthorized access and the lack of notifications for authentication method updates. Based on these root cause findings, this research produced the myITS MFA Management SOP (DPTSI-SOP-MFA-001), whose handling procedures were specifically derived from the formulated Root Cause Analysis (RCA) results, rather than merely adopting general Incident Management procedures from ITIL V4. This SOP contains 31 integrated steps covering socialization, activation, handling login issues, handling suspected unauthorized access, and periodic evaluations. The document is also complemented by three supporting forms and a practical user guide for independent device replacement. The SOP has undergone a verification stage by the Head of the DPTSI Services Sub-directorate and validation by the service desk staff, with the results declaring it to be accurate in content and feasible to be implemented in the DPTSI ITS operational environment to reduce the frequency of recurring incidents in the future.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | ITIL V4, Multi-Factor Authentication, NIST SP 800-63B-4, Root Cause Analysis, SOP. Keywords : ITIL V4, Multi-Factor Authentication, NIST SP 800-63B-4, Root Cause Analysis, SOP. |
| Subjects: | T Technology > T Technology (General) > T58.6 Management information systems |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Information System > 57201-(S1) Undergraduate Thesis |
| Depositing User: | Ryan Adi Putra Pratama |
| Date Deposited: | 20 Jul 2026 06:48 |
| Last Modified: | 20 Jul 2026 06:48 |
| URI: | http://repository.its.ac.id/id/eprint/135680 |
Actions (login required)
![]() |
View Item |
