Designing a Cybersecurity Risk Assessment Framework for Local Government Web-Based Applications

Setiawan, Edoh and Nugroho, Lukito Edi and Hartanto, Rudy (2023) Designing a Cybersecurity Risk Assessment Framework for Local Government Web-Based Applications. In: Proceeding - 2023 2nd International Conference on Computer System, Information Technology, and Electrical Engineering: Sustainable Development for Smart Innovation System, COSITE 2023, 02-03 August 2023, Banda Aceh.

[thumbnail of Designing_a_Cybersecurity_Risk_Assessment_Framework_for_Local_Government_Web-Based_Applications.pdf] Text
Designing_a_Cybersecurity_Risk_Assessment_Framework_for_Local_Government_Web-Based_Applications.pdf
Restricted to Registered users only

Download (479kB) | Request a copy

Abstract

Administrators of e-government (SPBE) applications must prepare to manage cybersecurity risks to limit the impact of the growing number of cyber attacks on the government sector. The government has established regulations regarding SPBE risk management guidelines that need to be implemented by central and local governments. However, X District Government experienced difficulties, especially in risk assessment activities, when implementing these guidelines in the context of cyber security risks for applications. This research aims to design a risk assessment framework that is suitable for use in the context of cybersecurity risks in applications by considering the limitation of X District Government. The designed framework was tested on application Z belonging to the X District Government. Several approaches are used to carry out risk assessments, including CVSS, CAPEC, and the use of asset sensitivity forms to determine risk sensitivity. The test was performed successfully and obtained 13 high-risk categories, 7 medium-risk categories, and 1 low-risk category.

Item Type: Conference or Workshop Item (Paper)
Additional Information: Library Dosen
Uncontrolled Keywords: Cybersecurity, Risk Assessment, CVSS, CAPEC
Subjects: T Technology > T Technology (General)
T Technology > T Technology (General) > Communication of technical information
Divisions: Faculty of Engineering > Electronics Engineering Department
Depositing User: Rita Yulianti Yulianti
Date Deposited: 08 Jul 2024 03:43
Last Modified: 08 Jul 2024 03:43
URI: https://ir.lib.ugm.ac.id/id/eprint/206

Actions (login required)

View Item
View Item