IRCI Article ID: IRCI-AR-0000002816

Information Security Evaluation at Hospital Using Index KAMI 5.0 and Recommendations Based on ISO/IEC 27001:2022

Journal: Journal of Information Systems and Informatics

Publication: 2024-12-31 · Vol. 6 No. 4 · pp. 3070–3086

DOI: 10.51519/journalisi.v6i4.949

Cite this article

Citation

Choose a citation style or copy BibTeX for your reference manager.

 
View Original Publication

Abstract

Bali Mandara Regional Hospital integrates information technology into its healthcare services, but ransomware attacks pose significant risks to data security. In accordance with the 2016 Indonesian Ministry of Communication and Informatics regulation, Electronic System Operators (PSE) are required to ensure information security, emphasizing confidentiality, integrity, and availability. To support this, the National Cyber and Crypto Agency introduced the Index KAMI, an evaluation tool aligned with ISO/IEC 27001 standards. This study evaluates the hospital’s information security using Index KAMI 5.0, yielding a score of 177, which classifies its readiness as “Not Eligible” for ISO 27001 compliance. Recommendations for improvement include establishing clear governance policies, implementing systematic risk management, enhancing asset management with integrated inventories, and strengthening data protection through access control and encryption. Additional measures involve improving physical security with surveillance systems and fostering stronger vendor relationships through binding SLA agreements. By adopting these measures, Bali Mandara Regional Hospital can enhance its security system, protect patient data, and achieve compliance with international standards.

0
IRCI Cited By
0
Indexed References

Authors

References

No references were harvested yet.

Cited By (0)

No indexed citing article has been matched by IRCI yet.