Risk Management Analysis of School Management Information Systems Using ISO 31000:2018

Anita Sulistiawati, Kristoko Dwi Hartomo


The school management information system (SIAHDU) is an application managed by the IT department of a Vocational High School in Salatiga City. This application is an application of SI/IT in the education sector which was created with the aim of making school business processes more effective and efficient, such as administrative activities for paying tuition fees, managing grades and report cards, violation points, attendance and student biodata that can be accessed by teachers and students. With the convenience provided, it cannot be denied that risks will always arise both internally and externally. Based on this, risk management activities need to be carried out to minimize risks that might hamper and stop the system's business processes. In this research, the ISO 31000:2018 framework is used as a risk analysis assessment guide. The stages used are divided into risk assessment and mitigation stages so that it is hoped that they can minimize and overcome existing risks. The aim of this research is to carry out risk assessments and risk mitigation in school management information system applications using ISO 31000:2018. The results of the day of research that was carried out contained 25 risk opportunities, three of which were at a high level, fourteen were at a medium level, eight were at a low level. It is hoped that the results of this risk management documentation will become a reference for schools to implement new policies to minimize risk opportunities
Keywords: risk management, ISO 31000:2018, risk analysis

Full Text:



K. Hadiono, R. Candra, and N. Santi, Menyongsong Transformasi Digital.

N. Edwin Kiky Aprianto, “Peran Teknologi Informasi dan Komunikasi dalam Bisnis,” International Journal Administration, Business and Organization (IJABO) |, vol. 2, no. 1, pp. 1–7, 2021, [Online]. Available: https://ijabo.a3i.or.id

F. Mahardika, M. Agreindra H, S. A. Fatimah, and L. T. Nur F, “Manajemen Risiko Teknologi Informasi Aplikasi E-Office ASN Menggunakan ISO 31000:2018,” Infotekmesin, vol. 14, no. 2, pp. 237–243, Jul. 2023, doi: 10.35970/infotekmesin.v14i2.1877.

G. H. Tirayoh and P. Pangeran, “Operational Risk Mitigation Based on Risk Management ISO 31000:2018-Balanced Scorecard to Increase the Income and Reputation: Case Study at IEC.”

H. Yefany Syahputri and M. L. Kitri, “Enterprise Risk Management Analysis of Group XYZ Based on ISO 31000:2018 Framework,” 2020. [Online]. Available: http://myjms.moe.gov.my/index.php/ajafin

J. Bina Komputer, P. Studi Sistem Informasi, F. Teknologi Informasi, and U. Kristen Satya Wacana, “Analisis Resiko Teknologi Informasi Aplikasi VCare PT Visionet Data Internasional.”

M. I. Fachrezi, A. Dwika Cahyono, and P. F. Tanaem, “Manajemen Risiko Keamanan Aset Teknologi Informasi Menggunakan ISO 31000:2018 Diskominfo Kota Salatiga,” Jurusan Sistem Informasi, vol. 8, no. 2, 2021, [Online]. Available: http://jurnal.mdp.ac.id

W. Harefa and K. D. Hartomo, “Analisis Manajemen Risiko Dengan Menggunakan Framework ISO 31000:2018 Pada Sistem Informasi Gudang”, [Online]. Available: http://jurnal.mdp.ac.id

S. A. Diah Pitaloka and E. Maria, “SISTEMASI: Jurnal Sistem Informasi Penerapan ISO 31000:2018 pada Aktivitas Manajemen Risiko Aplikasi Libsys Minat Siswa Implementation of ISO 31000:2018 in Risk Management Activities of Libsys Application Student Interest.” [Online]. Available: http://sistemasi.ftik.unisi.ac.id

Y. Erlika et al., “Analisis IT Risk Management di Universitas Bina Darma Menggunakan ISO31000”.

P. Kanantyo, F. S. Papilaya, K. S. Wacana, J. Blotongan, K. Salatiga, and J. Tengah, “Analisis Risiko Teknologi Informasi Menggunakan ISO 31000 (Learning Management System SMPN 6 Salatiga),” 2021. [Online]. Available: http://jurnal.mdp.ac.id

E. Ratter, M. Kalbarczyk, and K. Pietrzak-Wiszowaty, “The Utilization of Lean Management Tools in the Application of Risk Management Methods According to ISO 31000:2018 The Utilization of Lean Management Tools in the Application of Risk Management Methods According to ISO 31000:2018 66,” 2024.

R. Bisma, “Manajemen Risiko Aset Teknologi Informasi: Studi kasus Implementasi Manajemen Risiko SPBE Dinas Komunikasi dan Informatika Pemerintah Kota Balikpapan.”

M. Miftakhatun, “Analisis Manajemen Risiko Teknologi Informasi pada Website Ecofo Menggunakan ISO 31000,” Journal of Computer Science and Engineering (JCSE), vol. 1, no. 2, pp. 128–146, Aug. 2020, doi: 10.36596/jcse.v1i2.76.

D. Kurniawan, R. Prabowo, J. Ilmu Komputer FMIPA Universitas Lampung Jalan Sumantri Brojonegoro No, and B. Lampung, “Analisis Manajemen Risiko Sistem Informasi Pengelolaan Data English Proficiency Test (EPT) dan Portal Informasi di UPT Bahasa Universitas Lampung Menggunakan Metode ISO 31000,” 2020.

D. L. Ramadhan, R. Febriansyah, and R. S. Dewi, “Analisis Manajemen Risiko Menggunakan ISO 31000 pada Smart Canteen SMA XYZ,” JURIKOM (Jurnal Riset Komputer), vol. 7, no. 1, p. 91, Feb. 2020, doi: 10.30865/jurikom.v7i1.1791.

I. Putu, A. Eka, P. #1, and T. S. Pratika, “Manajemen Risiko Teknologi Informasi Terkait Manipulasi dan Peretasan Sistem pada Bank XYZ Tahun 2020 Menggunakan ISO 31000:2018,” Jurnal Telematika, vol. 15, no. 2.

K. M. Linda Lole and E. Maria, “Analisis Manajemen Risiko Pada Aplikasi Pegadaian Digital Service Menu Tabungan Emas Menggunakan ISO 31000:2018,” Jurnal Sistem Komputer dan Informatika (JSON), vol. 3, no. 3, p. 319, Mar. 2022, doi: 10.30865/json.v3i3.3891.

DOI: https://doi.org/10.32520/stmsi.v13i5.4424

Article Metrics

Abstract view : 19 times
PDF - 8 times


  • There are currently no refbacks.

Creative Commons License
This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.