Analisis dan Perancangan Strategi Manajemen Keamanan Informasi pada Penggunaan Sistem Berbasis Cloud di Perusahaan Jasa

Main Article Content

Aisyah Pramudita
Robbi Rahim

Abstract

Transformasi digital mendorong perusahaan jasa memanfaatkan sistem berbasis cloud untuk mendukung operasional bisnis, namun perpindahan pengelolaan data ke lingkungan cloud turut meningkatkan kompleksitas risiko keamanan informasi. Penelitian ini bertujuan menganalisis kondisi keamanan informasi berdasarkan prinsip Confidentiality, Integrity, dan Availability (CIA Triad), menganalisis risiko keamanan informasi berdasarkan ISO/IEC 27001:2022 dan NIST Cybersecurity Framework (CSF) 2.0, serta merancang strategi manajemen keamanan informasi yang dapat diterapkan pada perusahaan jasa. Penelitian menggunakan metode kualitatif dengan pendekatan Systematic Literature Review (SLR) mengikuti tahapan PRISMA pada basis data ScienceDirect, SpringerLink, Scientific Reports, dan MDPI, sehingga diperoleh lima belas artikel yang memenuhi kriteria inklusi tahun 2022-2026. Hasil analisis menunjukkan bahwa risiko dominan meliputi akses tidak sah, kebocoran data, kesalahan konfigurasi, kerentanan aplikasi, dan lemahnya kesadaran keamanan pengguna. ISO/IEC 27001:2022 dan NIST CSF 2.0 terbukti saling melengkapi: ISO/IEC 27001:2022 memperkuat tata kelola melalui Information Security Management System (ISMS), sedangkan NIST CSF 2.0 memperkuat kesiapsiagaan operasional melalui fungsi Govern, Identify, Protect, Detect, Respond, dan Recover. Penelitian ini menghasilkan model strategi konseptual terintegrasi yang mencakup enam tahapan, yaitu tata kelola,
identifikasi risiko, implementasi kontrol, pemantauan, respons insiden, serta evaluasi berkelanjutan, sebagai rekomendasi bagi perusahaan jasa dalam memperkuat keamanan sistem berbasis cloud.

Article Details

How to Cite
Pramudita, A., & Rahim, R. . (2026). Analisis dan Perancangan Strategi Manajemen Keamanan Informasi pada Penggunaan Sistem Berbasis Cloud di Perusahaan Jasa. JIBEMA: Jurnal Ilmu Bisnis, Ekonomi, Manajemen, Dan Akuntansi, 4(1), 2507–2517. https://doi.org/10.62421/jibema.v4i1.693
Section
Articles

References

Anwar, R. W., Pastore, F., & Abdullah, T. (2026). VIRTUOSO : A Multilayer Cloud Security and Risk Management Framework. Computers, 15(272), 1–34. https://doi.org/https://doi.org/10.3390/computers15050272

Bajdor, P. (2024). Evaluating Current and Future Impacts of Cloud Computing on Enterprise Operations: A Comparative Analysis. Procedia Computer Science, 246, 5185–5194. https://doi.org/10.1016/j.procs.2024.09.614

Bitkowska, A., Dziembek, D., & Gzik, T. (2024). Enterprise Resource Planning based on Cloud Computing (Cloud ERP). Journal of Software & Systems Development, 2024, 16. https://doi.org/https://doi.org/10.5171/2024.206232

BSSN. (2023). Lanskap Keamanan Siber Indonesia 2023. TLP Clear, 1–105.

Dahal, N. (2025). Qualitative Data Analysis Reflections, Procedures, and Some Points for Consideration. Front. Res. Metr. Anal, 10. https://doi.org/https://doi.org/10.3389/frma.2025.1669578

Essien, I. A., Cadet, E., Ajayi, J. O., Erigh, E. D., Obuse, E., Ayanbode, N., & Babatunde, L. A. (2022). Optimizing Cyber Risk Governance Using Global Frameworks: ISO, NIST, and COBIT Alignment. Journal of Frontiers in Multidisciplinary Research, 03(01), 618–629. https://doi.org/https://doi.org/10.54660/.JFMR.2022.3.1.618-629

Anwar, R. W., Pastore, F., & Abdullah, T. (2026). VIRTUOSO : A Multilayer Cloud Security and Risk Management Framework. Computers, 15(272), 1–34. https://doi.org/https://doi.org/10.3390/computers15050272

Bajdor, P. (2024). Evaluating Current and Future Impacts of Cloud Computing on Enterprise Operations: A Comparative Analysis. Procedia Computer Science, 246, 5185–5194. https://doi.org/10.1016/j.procs.2024.09.614

Bitkowska, A., Dziembek, D., & Gzik, T. (2024). Enterprise Resource Planning based on Cloud Computing (Cloud ERP). Journal of Software & Systems Development, 2024, 16. https://doi.org/https://doi.org/10.5171/2024.206232

BSSN. (2023). Lanskap Keamanan Siber Indonesia 2023. TLP Clear, 1–105.

Dahal, N. (2025). Qualitative Data Analysis Reflections, Procedures, and Some Points for Consideration. Front. Res. Metr. Anal, 10. https://doi.org/https://doi.org/10.3389/frma.2025.1669578

Essien, I. A., Cadet, E., Ajayi, J. O., Erigh, E. D., Obuse, E., Ayanbode, N., & Babatunde, L. A. (2022). Optimizing Cyber Risk Governance Using Global Frameworks: ISO, NIST, and COBIT Alignment. Journal of Frontiers in Multidisciplinary Research, 03(01), 618–629. https://doi.org/https://doi.org/10.54660/.JFMR.2022.3.1.618-629

Fadli, M. R. (2021). Memahami Desain Metode Penelitian Kualitatif. Humanika, 21(1), 33–54. https://doi.org/10.21831/hum.v21i1. 38075. 33-54

Frangky, & Sinaga, R. (2024). Penerapan ISO/IEC 27001:2022 dalam Tata Kelola Keamanan Sistem Informasi: Evaluasi Proses dan Kendala. NUANSA INFORMATIKA, 18(2), 46–54. https://doi.org/https://doi.org/10.25134/ilkom.v18i2.205

Guo, J., & Guo, H. (2023). Real-Time Risk Detection Method and Protection Strategy for Intelligent Ship Network Security Based on Cloud Computing. Symmetry, 15, 988. https://doi.org/https://doi.org/10.3390/sym15050988

Hashim, S., Omar, M. K., Jalil, H. A., & Sharef, N. M. (2022). Trends on Technologies and Artificial Intelligence in Education for Personalized Learning: Systematic Literature Review Trends on Technologies and Artificial Intelligence in Education for Personalized Learning : Systematic Literature Review. International Journal of Academic Research in Progressive Education and Development, 11(1), 884–903. https://doi.org/10.6007/IJARPED/v11-i1/12230

Hsu, H.-H., & Shih, J.-R. (2023). ISO 27001 Information Security Survey of Medical Service Organizations. Engineering Proceedings, 55(19), 2–7. https://doi.org/https://doi.org/10.3390/engproc2023055019

Huang, J., & Yi, J. (2024). The Key Security Management Scheme of Cloud Storage Based on Blockchain and Digital Twins. Journal of Cloud Computing. https://doi.org/10.1186/s13677-023-00587-4

Innomesanghan, D., Kiwamu, E., Butakov, S., & Abdallah, E. G. (2025). Streamlining Security: Mapping NIST SP 800-53, SOC 2, and US CJIS Policy to ISO/IEC 27001:2022 for Service Provider SMEs. Proceedings of the 10th International Conference on Computer and Information Science and Technology, 1–8. https://doi.org/10.11159/cist25.112

Kahraman, Z., & Rigopoulos, G. (2024). Digital Transformation and Operational Efficiency for SMEs in the Food Sector. International Journal of Management and Commerce Innovations, 11(2), 208–213. https://doi.org/https://doi.org/10.5281/zenodo.10438688

Kamil, Y., Lund, S., & Islam, M. S. (2023). Information Security Objectives and the Output Legitimacy of ISO/IEC 27001: Stakeholders’ Perspective on Expectations in Private Organizations in Sweden. Information Systems and E-Business Management, 21, 699–722.

Khader, M., Karam, M., & Fares, H. (2021). Cybersecurity Awareness Framework for Academia. 12(10), 1–20. https://doi.org/https://doi.org/10.3390/info12100417

Kuldeep, G., & Zhang, Q. (2022). Multi-class Privacy-preserving Cloud Computing Based on Compressive Sensing for IoT. Journal of Information Security and Applications. https://doi.org/https://doi.org/10.1016/j.jisa.2022.103139

Marhad, S. S., Goni, S. Z. A., & Sani, M. K. J. abdullah. (2023). Implementation of Information Security Management Systems for Data Protection in Organizations: A Systematic Literature Review. Environment-Behaviour Proceedings Journal, 197–203. https://doi.org/https://doi.org/10.21834/e-bpj.v9iSI18.5483

Morol, K., Das, S. S., & Mahmood, S. (2022). Data Security and Privacy in Cloud Computing Platforms: A Comprehensive Review. International Journal of Current Science Research and Review, 05(05), 1453–1463. https://doi.org/10.47191/ijcsrr/V5-i5-09

Nugroho, A. R., & Legowo, N. (2022). Risk Assessment at it Company by Focusing on Information Security Area Using Iso 27001:2022. Syntax Literate: Jurnal Ilmiah Indonesia, 7(12).

Oyeniyi, Olusegun, J., Oyeniran, & Akinloye, O. (2025). Optimizing Information Security In Cloud Environments: A Risk Management Approach And Guide For Enterprise Cloud Security Optimizing Information Security In Cloud Environments : A Risk Management. Journal of Cybersecurity Education, Research and Practice, 2025(1). https://doi.org/https://doi.org/10.62915/2472-2707.1213

Qazi, A., Arshad, S., Ali, A., & Jadoon, K. (2026). Security Evaluation Framework for Cloud ERP Systems Using NIST and ISO Standards. Scientific Reports, 1–18. https://doi.org/https://doi.org/10.1038/s41598-026-45550-w

Rambau, T. M., Munyoka, W., Phahlamohlaka, L. J., & Kadyamatimba, A. (2026). Evaluating Cyber Resilience Frameworks for E-government: Applicability of NIST CSF, ISO/IEC 27001 and COBIT 2019 in Developing Country Contexts. Information and Computer Security, Vol. Ahead-of-Print No. Ahead-of-Print. https://doi.org/10.1108/ICS-09-2025-0376

Schmidt, M. (2023). Information Security Risk Management Terminology and Key Concepts. Risk Management, 25(1), 1–23. https://doi.org/10.1057/s41283-022-00108-8

Vasovic, D., Jana´ckovi´, G., Vranjanac, Ž., Stamenkovi´, S., & BojanVasovi´c. (2026). Enhancing CIA Triad — Confidentiality, Integrity and Availability in Educational Information Systems Through Next-Generation ISO/IEC 27001:2022-Aligned Security Model. Applied Sciences, 16(12), 6260. https://doi.org/https://doi.org/10.3390/app16126260