Abstract:
This independent study is for studying the risk assessment in information security of the Data Center within the medium organization, which is aiming to support the decision making based on ISO/IEC 27001:2013 in a part of Annex A. Herein, this study is a scenario-based risk assessment separating in two parts with 22-risk items. Firstly, performing a risk assessment of the current situation of the existing environment is conducted. The study found those 10 low-risk items with 45.45%, 5 medium risk items with 22.73%, and 7 high-risk items with 31.82%. The second, performing a risk assessment after measuring security or mitigating is considered. The study found those decreasing risks of 19 low-risk items with 86.36%, 2 medium risk items with 9.09%, and 1 high-risk item with 4.55%. To conclude, this could show that majority of the medium and high-risk items becoming to low-risk items after applying the security measure or mitigation. Also, the 41 of 114 of Annex A was applied to the organization with 34.7%. The found risks, here, were considered by the executives and support them to make a decision of risk planning in the organization.