PERANCANGAN TATA KELOLA KEAMANAN INFORMASI BERBASIS ISO/IEC 27001 UNTUK PERLINDUNGAN DATA PELANGGAN PADA FLOWCAMP.ID

DIYASTA, AGUNG NUGRAHA (2026) PERANCANGAN TATA KELOLA KEAMANAN INFORMASI BERBASIS ISO/IEC 27001 UNTUK PERLINDUNGAN DATA PELANGGAN PADA FLOWCAMP.ID. S1 thesis, Universitas Mercu Buana Jakarta.

[img]
Preview
Text (HAL COVER)
Cover.pdf

Download (441kB) | Preview
[img] Text (BAB I)
bab i.pdf
Restricted to Registered users only

Download (40kB)
[img] Text (BAB II)
bab ii.pdf
Restricted to Registered users only

Download (195kB)
[img] Text (BAB III)
bab iii.pdf
Restricted to Registered users only

Download (60kB)
[img] Text (BAB IV)
bab iv.pdf
Restricted to Registered users only

Download (306kB)
[img] Text (BAB V)
bab v.pdf
Restricted to Registered users only

Download (27kB)
[img] Text (DAFTAR PUSTAKA)
dafpus.pdf
Restricted to Registered users only

Download (87kB)
[img] Text (LAMPIRAN)
lampiran.pdf
Restricted to Registered users only

Download (103kB)

Abstract

Startups and Small and Medium Enterprises (SMEs) in Indonesia currently manage sensitive customer data using unstructured tools, creating a high vulnerability to data breaches. This issue becomes critical due to two main factors: the new legal obligation under the Personal Data Protection Law (UU PDP) that demands compliance, and the complexity of the global ISO 27001 standard, which is often seen as impractical or too costly for SMEs to implement in full. Prior research has also shown that ISO 27001 alone is not sufficient to ensure compliance with UU PDP, indicating a need for integration with privacy considerations. To bridge this gap, the main contribution of this research is a simplified (tailored) information security governance model designed specifically for the SME context, adapting the complexity of ISO/IEC 27001 to align with SMEs' limited resources while remaining integrated with the privacy requirements of UU PDP. This model was developed through a case study on Flowcamp.id, beginning with a risk assessment using Failure Mode and Effect Analysis (FMEA) and a gap analysis using the KAMI Index (PAMAN KAMI) framework, a tool specifically designed by BSSN for SMEs. Based on this proposed model, the research produces practical artifacts consisting of: (1) a Risk Analysis Document, (2) a Gap Analysis Report, and (3) a set of Security Policy and Procedure (SOP) documents such as an Access Control SOP and an Incident Handling SOP ready for implementation by Flowcamp.id to protect customer data both legally and operationally. Overall, this research offers a more realistic and applicable approach to information security governance for similar SMEs, without compromising the essence of compliance with prevailing standards and regulations. Keywords : Design, Information Security Governance, ISO 27001, UU PDP, SMEs, FMEA, KAMI Index Startup dan Usaha Kecil Menengah (UKM) di Indonesia kini mengelola data pelanggan sensitif menggunakan tools yang tidak terstruktur, sehingga menciptakan kerentanan tinggi terhadap kebocoran data. Permasalahan ini menjadi kritis karena dua faktor utama: adanya kewajiban hukum baru dari Undang-Undang Pelindungan Data Pribadi (UU PDP) yang menuntut kepatuhan, dan kompleksitas standar global ISO 27001 yang sering dianggap tidak praktis atau terlalu mahal untuk diterapkan secara penuh oleh UKM. Penelitian terdahulu juga menunjukkan bahwa penerapan ISO 27001 saja tidak cukup untuk menjamin kepatuhan terhadap UU PDP, sehingga diperlukan integrasi dengan pertimbangan privasi. Untuk menjembatani kesenjangan tersebut, penelitian ini menghasilkan kontribusi utama berupa rancangan model tata kelola keamanan informasi yang disederhanakan (tailored) khusus untuk konteks UKM, dengan mengadaptasi kompleksitas ISO/IEC 27001 agar selaras dengan keterbatasan sumber daya UKM sekaligus tetap terintegrasi dengan tuntutan privasi UU PDP. Model ini dirancang melalui studi kasus pada Flowcamp.id, diawali dengan penilaian risiko menggunakan Failure Mode and Effect Analysis (FMEA) dan analisis kesenjangan (gap analysis) menggunakan framework Indeks KAMI (PAMAN KAMI) yang dirancang khusus oleh BSSN untuk UKM. Dari rancangan model tersebut, penelitian ini menghasilkan artefak praktis berupa: (1) Dokumen Analisis Risiko, (2) Laporan Analisis Kesenjangan, dan (3) satu set dokumen Kebijakan dan Prosedur (SOP) keamanan seperti SOP Kontrol Akses dan SOP Penanganan Insiden yang siap diimplementasikan oleh Flowcamp.id untuk melindungi data pelanggan secara legal dan operasional. Dengan demikian, penelitian ini menawarkan pendekatan tata kelola keamanan informasi yang lebih realistis dan aplikatif bagi UKM sejenis, tanpa mengorbankan esensi kepatuhan terhadap standar dan regulasi yang berlaku. Kata Kunci: Perancangan, Tata Kelola Keamanan Informasi, ISO 27001, UU PDP, UKM, FMEA, Indeks KAMI.

Item Type: Thesis (S1)
NIM/NIDN Creators: 41822010050
Uncontrolled Keywords: Perancangan, Tata Kelola Keamanan Informasi, ISO 27001, UU PDP, UKM, FMEA, Indeks KAMI.
Subjects: 000 Computer Science, Information and General Works/Ilmu Komputer, Informasi, dan Karya Umum > 000. Computer Science, Information and General Works/Ilmu Komputer, Informasi, dan Karya Umum > 005 Computer Programmming, Programs, Data/Pemprograman Komputer, Program, Data > 005.8 Computer Security, Data Security/Keamanan Komputer, Keamanan Data
300 Social Science/Ilmu-ilmu Sosial > 330 Economics/Ilmu Ekonomi > 339 Macroeconomics and Related Topics/Makroekonomi, Ekonomi Makro dan Topik Terkait > 339.5 Macroeconomics Policy/Kebijakan Makroekonomi, Kebijakan Ekonomi Makro
Divisions: Fakultas Ilmu Komputer > Sistem Informasi
Depositing User: khalimah
Date Deposited: 23 Sep 2026 04:12
Last Modified: 23 Sep 2026 04:12
URI: http://repository.mercubuana.ac.id/id/eprint/104064

Actions (login required)

View Item View Item