Analisis Risiko Serangan Siber Pada Perusahaan Ketenagalistrikan Nasional Dalam Mendukung Program Digitalisasi Perusahaan

Sungkar, Raihan (2026) Analisis Risiko Serangan Siber Pada Perusahaan Ketenagalistrikan Nasional Dalam Mendukung Program Digitalisasi Perusahaan. Other thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 5010221174-Undergraduate_Thesis.pdf] Text
5010221174-Undergraduate_Thesis.pdf - Accepted Version
Restricted to Repository staff only

Download (2MB) | Request a copy

Abstract

Transformasi digital pada sektor ketenagalistrikan mendorong penggunaan sistem digital dan integrasi sistem IT–OT yang meningkatkan efisiensi operasional sekaligus memperbesar risiko serangan siber. Perusahaan Ketenagalistrikan Nasional telah mengadopsi standar ISO/IEC 27001:2022 dan ISO 31000:2018 dengan metode identifikasi risiko berupa Fault Tree Analysis (FTA), Fishbone Diagram, dan Root Cause Analysis (RCA), serta Failure Mode and Effects Analysis (FMEA) untuk risk assessment. Namun, pendekatan yang digunakan masih perlu dikembangkan untuk mengidentifikasi hubungan antara Risk Event dan Risk Agent serta menentukan prioritas mitigasi secara kuantitatif. Penelitian ini bertujuan mengembangkan analisis manajemen risiko siber melalui integrasi ISO/IEC 27001:2022 dan metode House of Risk (HOR) berbasis model SHELL. Data diperoleh melalui wawancara, Focus Group Discussion (FGD), dan analisis dokumen internal perusahaan. Hasil penelitian mengidentifikasi 24 Risk Event, 25 Risk Agent, 14 Risk Agent prioritas (ARP kumulatif 78,28%), serta 15 Preventive Action. Simulasi menunjukkan penerapan Preventive Action diproyeksikan menurunkan total Aggregate Risk Potential (ARP) sebesar 31,6%, dari 9.204 menjadi 6.295. Pendekatan ini menghasilkan analisis risiko yang lebih komprehensif, terstruktur, dan objektif sehingga mendukung pengelolaan risiko siber dalam transformasi digital perusahaan.
==================================================================================================================================
Digital transformation in the electricity sector has accelerated the adoption of digital systems and IT–OT integration, improving operational efficiency while increasing cybersecurity risks. The National Electricity Company has implemented ISO/IEC 27001:2022 and ISO 31000:2018 standards using Fault Tree Analysis (FTA), Fishbone Diagram, Root Cause Analysis (RCA), and Failure Mode and Effects Analysis (FMEA) for risk identification and assessment. However, the existing approach requires further development to identify relationships between Risk Events and Risk Agents and prioritize mitigation quantitatively. This study aims to develop a cybersecurity risk management analysis by integrating ISO/IEC 27001:2022 with the House of Risk (HOR) method based on the SHELL model. Data were collected through interviews, Focus Group Discussions (FGDs), and internal document analysis. The results identified 24 Risk Events, 25 Risk Agents, 14 priority Risk Agents (cumulative ARP of 78.28%), and 15 recommended Preventive Actions. Simulation results projected a 31.6% reduction in total Aggregate Risk Potential (ARP), from 9,204 to 6,295, after implementing the proposed Preventive Actions. The proposed approach provides a more comprehensive, structured, and objective cybersecurity risk analysis, thereby supporting more effective risk management in the company's digital transformation.

Item Type: Thesis (Other)
Uncontrolled Keywords: keamanan siber, manajemen risiko, ISO/IEC 27001:2022, HOR, residual risk, cybersecurity, risk management, ISO/IEC 27001:2022, HOR, residual risk
Subjects: H Social Sciences > HD Industries. Land use. Labor > HD61 Risk Management
Q Science
Divisions: Faculty of Industrial Technology > Industrial Engineering > 26201-(S1) Undergraduate Thesis
Depositing User: Raihan Sungkar
Date Deposited: 31 Jul 2026 01:01
Last Modified: 31 Jul 2026 01:01
URI: http://repository.its.ac.id/id/eprint/140129

Actions (login required)

View Item View Item