Analisis Manajemen Risiko IT Pada Sistem Informasi Apotek XYZ Menggunakan ISO 31000
Keywords:
ISO 31000, Risk Priority Number (RPN), Sistem Informasi Apotek (SIA), Risiko, Teknologi InformasiAbstract
The advancement of information technology is unavoidable and necessary in all aspects of human life. The use of information technology makes work easier to perform, but it also introduces risks that can threaten the activities of an organization. Pharmacy X has implemented a Pharmacy Information System (PIS) to enhance pharmacy administrative services, such as prescription management, medication inventory, patient data entry, doctor scheduling, and payment processing. Through interviews, potential risks that could disrupt the business processes at the pharmacy were identified. This study aims to obtain the Risk Priority Number (RPN) to provide risk treatment recommendations for the Pharmacy Information System (PIS). The method used is ISO 31000 to measure the level of risk. The research stages include risk identification, risk analysis, RPN calculation, risk evaluation, and risk treatment. This study results in a ranking of risks from highest to lowest that can be used as a reference for evaluation, treatment, and recommendations to mitigate those risks







