Abstract :
In every existing information technology, of course there are aspects that must be considered, especially security issues. The principles of information system security consist of confidentiality, integrity, and availability. If these principles are not met, it will pose a threat to the security of information systems. Kusuma Bangsa Junior High School is one of the schools that has implemented information technology in the learning process. The technology applied is an academic information system (AIS). Based on the results of interviews, Kusuma Bangsa Junior High School has problems in implementing academic information systems, namely not updating plugins, data input errors, and bugs / errors. The solution to these problems is to conduct a risk assessment or risk analysis of academic information systems. This research will use the OCTAVE Allegro method. OCTAVE stands for Operationally, Critical Threat, Asset, and Vulnerability Evaluation and was developed by the Software Engineering Institute (SEI) of Carniege Mellon University, Pittsburgh. The OCTAVE Allegro method is also actively developed and supported by the Computer Emergency Response Team (CERT) division. By using the OCTAVE Allegro method in conducting a security risk assessment of academic information systems in this study, it is expected to be able to protect information based on risk decision making for critical information technology assets. The results of this study are, 5 (five) areas of concern with 1 (one) mitigation approach that must be mitigated or suspended, 2 (two) mitigation approaches that must be mitigated, and 2 (two) mitigation approaches that must be suspended or accepted. . In addition, the results of this research are also recommendations regarding the steps that must be taken to protect the information system and its assets.
Keywords : OCTAVE Allegro, Risk, Academic Information System, AIS Security, AIS Risk Assessment.