Sungkar, Raihan (2026) Analisis Risiko Serangan Siber Pada Perusahaan Ketenagalistrikan Nasional Dalam Mendukung Program Digitalisasi Perusahaan. Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
5010221174-Undergraduate_Thesis.pdf - Accepted Version Restricted to Repository staff only Download (2MB) | Request a copy |
Abstract
Transformasi digital pada sektor ketenagalistrikan mendorong penggunaan sistem digital dan integrasi sistem IT–OT yang meningkatkan efisiensi operasional sekaligus memperbesar risiko serangan siber. Perusahaan Ketenagalistrikan Nasional telah mengadopsi standar ISO/IEC 27001:2022 dan ISO 31000:2018 dengan metode identifikasi risiko berupa Fault Tree Analysis (FTA), Fishbone Diagram, dan Root Cause Analysis (RCA), serta Failure Mode and Effects Analysis (FMEA) untuk risk assessment. Namun, pendekatan yang digunakan masih perlu dikembangkan untuk mengidentifikasi hubungan antara Risk Event dan Risk Agent serta menentukan prioritas mitigasi secara kuantitatif. Penelitian ini bertujuan mengembangkan analisis manajemen risiko siber melalui integrasi ISO/IEC 27001:2022 dan metode House of Risk (HOR) berbasis model SHELL. Data diperoleh melalui wawancara, Focus Group Discussion (FGD), dan analisis dokumen internal perusahaan. Hasil penelitian mengidentifikasi 24 Risk Event, 25 Risk Agent, 14 Risk Agent prioritas (ARP kumulatif 78,28%), serta 15 Preventive Action. Simulasi menunjukkan penerapan Preventive Action diproyeksikan menurunkan total Aggregate Risk Potential (ARP) sebesar 31,6%, dari 9.204 menjadi 6.295. Pendekatan ini menghasilkan analisis risiko yang lebih komprehensif, terstruktur, dan objektif sehingga mendukung pengelolaan risiko siber dalam transformasi digital perusahaan.
==================================================================================================================================
Digital transformation in the electricity sector has accelerated the adoption of digital systems and IT–OT integration, improving operational efficiency while increasing cybersecurity risks. The National Electricity Company has implemented ISO/IEC 27001:2022 and ISO 31000:2018 standards using Fault Tree Analysis (FTA), Fishbone Diagram, Root Cause Analysis (RCA), and Failure Mode and Effects Analysis (FMEA) for risk identification and assessment. However, the existing approach requires further development to identify relationships between Risk Events and Risk Agents and prioritize mitigation quantitatively. This study aims to develop a cybersecurity risk management analysis by integrating ISO/IEC 27001:2022 with the House of Risk (HOR) method based on the SHELL model. Data were collected through interviews, Focus Group Discussions (FGDs), and internal document analysis. The results identified 24 Risk Events, 25 Risk Agents, 14 priority Risk Agents (cumulative ARP of 78.28%), and 15 recommended Preventive Actions. Simulation results projected a 31.6% reduction in total Aggregate Risk Potential (ARP), from 9,204 to 6,295, after implementing the proposed Preventive Actions. The proposed approach provides a more comprehensive, structured, and objective cybersecurity risk analysis, thereby supporting more effective risk management in the company's digital transformation.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | keamanan siber, manajemen risiko, ISO/IEC 27001:2022, HOR, residual risk, cybersecurity, risk management, ISO/IEC 27001:2022, HOR, residual risk |
| Subjects: | H Social Sciences > HD Industries. Land use. Labor > HD61 Risk Management Q Science |
| Divisions: | Faculty of Industrial Technology > Industrial Engineering > 26201-(S1) Undergraduate Thesis |
| Depositing User: | Raihan Sungkar |
| Date Deposited: | 31 Jul 2026 01:01 |
| Last Modified: | 31 Jul 2026 01:01 |
| URI: | http://repository.its.ac.id/id/eprint/140129 |
Actions (login required)
![]() |
View Item |
