From standards to practice: Applying ISO/IEC 27005:2022 for information security risk management in regional water company
DOI:
https://doi.org/10.31315/opsi.v19i1.15917Keywords:
Information security risk management, Information technology assets, ISO/IEC 27001:2022, ISO/IEC 27005:2022, Regional water companyAbstract
Regional water companies have increasingly adopted information technology to support their operations. However, the absence of formalized information security risk management procedures can lead to substantial operational disruptions and financial losses. Therefore, this study aims to conduct a systematic risk assessment of a regional water company based on its IT assets, utilizing the ISO/IEC 27005:2022 standard. Data collection through semi-structured interviews and questionnaires with the company's IT department identified 31 assets, which were subsequently used for risk mapping and assessment. The assessment identified a total of 265 risk scenarios, categorized into 10 High (3.77%), 68 Medium (25.66%), and 187 Low (70.57%) level risks. Following the evaluation where all risks were deemed unacceptable, risk modification was recommended as treatment for all risk scenarios. Based on the results of the risk assessment, control recommendations were developed according to ISO/IEC 27001:2022 to assist the company in managing and mitigating risks. The implementation of the two ISO standards aligns to comprehensively map risks and provide a structured mitigation plan. These results are expected to assist the company in establishing formal risk management procedures and maintain business process continuity and effectiveness.
References
[1] I. Appiah-Otoo and N. Song, “The impact of ICT on economic growth-comparing rich and poor countries,” Telecomm Policy, vol. 45, no. 2, p. 102082, Mar. 2021, doi: 10.1016/j.telpol.2020.102082.
[2] D. W. Jorgenson and K. M. Vu, “The ICT revolution, world economic growth, and policy issues,” Telecomm Policy, vol. 40, no. 5, pp. 383–397, May 2016, doi: 10.1016/j.telpol.2016.01.002.
[3] R. Prasetyo and A. Komariah, “CNC programming software design to optimizing batik stamping time,” OPSI, vol. 14, no. 1, p. 21, Jun. 2021, doi: 10.31315/opsi.v14i1.4700.
[4] I. Keshta and A. Odeh, “Security and privacy of electronic health records: Concerns and challenges,” Egyptian Informatics Journal, vol. 22, no. 2, pp. 177–183, 2021, doi: 10.1016/j.eij.2020.07.003.
[5] S. Saeed, S. A. Altamimi, N. A. Alkayyal, E. Alshehri, and D. A. Alabbad, “Digital transformation and cybersecurity challenges for businesses resilience: issues and recommendations,” Sensors, vol. 23, no. 15, pp. 1–20, 2023, doi: 10.3390/s23156666.
[6] H. Riggs et al., “Impact, vulnerabilities, and mitigation strategies for cyber-secure critical infrastructure,” Sensors, vol. 23, no. 8, p. 4060, Apr. 2023, doi: 10.3390/s23084060.
[7] T. R. Reshmi, “Information security breaches due to ransomware attacks - A systematic literature review,” International Journal of Information Management Data Insights, vol. 1, no. 2, p. 100013, Nov. 2021, doi: 10.1016/j.jjimei.2021.100013.
[8] L. Coventry and D. Branley, “Cybersecurity in healthcare: A narrative review of trends, threats and ways forward,” Maturitas, vol. 113, pp. 48–52, Jul. 2018, doi: 10.1016/j.maturitas.2018.04.008.
[9] S. Saeed, S. A. Suayyid, M. S. Al-Ghamdi, H. Al-Muhaisen, and A. M. Almuhaideb, “A systematic literature review on cyber threat intelligence for organizational cybersecurity resilience,” Sensors, vol. 23, no. 16, p. 7273, Aug. 2023, doi: 10.3390/s23167273.
[10] J. A. Tanimu and W. Abada, “Addressing cybersecurity challenges in robotics: A comprehensive overview,” Cyber Security and Applications, vol. 3, p. 100074, 2024, doi: 10.1016/j.csa.2024.100074.
[11] S. Zurawski, Z. Ciekanowski, Y. Pauliuchuk, and E. Ratter, “The impact of supply chain security management on the functioning of modern organizations,” European Research Studies Journal, vol. XXVIII, no. Issue 1, pp. 44–56, Feb. 2025, doi: 10.35808/ersj/3889.
[12] E. A. Al-Qarni, “Cybersecurity in healthcare: A review of recent attacks and mitigation strategies,” International Journal of Advanced Computer Science and Applications, vol. 14, no. 5, pp. 135–140, 2023, doi: 10.14569/IJACSA.2023.0140513.
[13] A. Bello, S. Jahan, F. Farid, and F. Ahamed, “A systemic review of the cybersecurity challenges in Australian water infrastructure management,” Water (Basel), vol. 15, no. 1, p. 168, Dec. 2022, doi: 10.3390/w15010168.
[14] A. Muzakir, A. T. Wahyudi, Y. D. Astanti, and C. D. Kusmindari, “Optimizing work movements to reduce injury risk: Application development with Methods-Time Measurement and WebQual analysis,” OPSI, vol. 17, no. 2, p. 302, Dec. 2024, doi: 10.31315/opsi.v17i2.13478.
[15] N. S. Grigg, “Digital transformation in water utilities: Status, challenges, and prospects,” Smart Cities, vol. 8, no. 3, p. 99, Jun. 2025, doi: 10.3390/smartcities8030099.
[16] A. Tereso, C. Santos, and J. Faria, “Risk management practices in the purchasing system of an automotive company,” Systems, vol. 13, no. 6, p. 444, Jun. 2025, doi: 10.3390/systems13060444.
[17] J. V. Barraza de la Paz, L. A. Rodríguez-Picón, V. Morales-Rocha, and S. V. Torres-Argüelles, "A systematic review of risk management methodologies for complex organizations in industry 4.0 and 5.0," Systems, vol. 11, no. 5, p. 218, 2023, doi: 10.3390/systems11050218.
[18] H. Taherdoost, “Understanding cybersecurity frameworks and information security standards—A review and comprehensive overview,” Electronics (Switzerland), vol. 11, no. 14, p. 2181, 2022, doi: 10.3390/electronics11142181.
[19] R. Sheh, K. Geappen, and D. Harriss, “Autonomous cybersecurity and AI risk management for uncrewed systems: Challenges and opportunities using the NIST frameworks,” in XPONENTIAL 2024, Arlington, Virginia, USA: Association for Unmanned Vehicle Systems International, 2024, pp. 46–67. doi: 10.52202/075106-0003.
[20] S. Ksibi, F. Jaidi, and A. Bouhoula, “A comprehensive quantified approach for security risk management in e-health systems,” in Proceedings of the 17th International Joint Conference on e-Business and Telecommunications, SCITEPRESS - Science and Technology Publications, 2020, pp. 652–657. doi: 10.5220/0009893806520657.
[21] S. Memon, S. Memon, L. Das, and B. R. Memon, “Cyber security risk assessment methods for smart healthcare,” in 2024 IEEE 1st Karachi Section Humanitarian Technology Conference (KHI-HTC), IEEE, Jan. 2024, pp. 1–6. doi: 10.1109/KHI-HTC60760.2024.10481961.
[22] H. Boyes and M. D. Higgins, “An overview of information and cyber security standards,” Journal of ICT Standardization, vol. 12, no. 1, pp. 95–134, Sep. 2024, doi: 10.13052/jicts2245-800X.1215.
[23] N. Alsafwani, Y. Fazea, and F. Alnajjar, “Strategic approaches in network communication and information security risk assessment,” Information, vol. 15, no. 6, p. 353, Jun. 2024, doi: 10.3390/info15060353.
[24] ISO/IEC 27005 Fourth edition, “Information security, cybersecurity and privacy protection — Guidance on managing information security risks,” 2022. [Online]. Available: www.iso.org
[25] A. P. Putra and B. Soewito, “Integrated methodology for information security risk management using ISO 27005:2018 and NIST SP 800-30 for insurance sector,” International Journal of Advanced Computer Science and Applications, vol. 14, no. 4, pp. 1–9, 2023, doi: 10.14569/IJACSA.2023.0140468.
[26] ISO/IEC 27001 Third edition, “Information security, cybersecurity and privacy protection — Information security management systems — Requirements,” 2022. [Online]. Available: www.iso.org
[27] B. Reuben-Owoh and E. Haig, “A systematic review of voluntary cybersecurity standards and frameworks,” Int J Inf Secur, vol. 24, no. 5, p. 206, Oct. 2025, doi: 10.1007/s10207-025-01121-0.
[28] M. F. Kurniawan and T. D. Salma, “Risk management evaluation based on ISO/IEC 27005 framework: A case study of ABC company IT workshop room,” International Journal Software Engineering and Computer Science (IJSECS), vol. 5, no. 2, pp. 587–598, 2025, doi: 10.35870/ijsecs.v5i2.4549.
[29] M. Djunaidi and R. D. Gunari, “Analysis of factors affecting consumer satisfaction using SEM (structural equation modeling) method,” OPSI, vol. 15, no. 1, p. 85, Jun. 2022, doi: 10.31315/opsi.v15i1.6808.
[30] T. Puspitasari and I. Ismianti, “Analysis of potential hazards and control in PT XYZ’s production process with the HIRADC method,” OPSI, vol. 16, no. 1, p. 11, Jun. 2023, doi: 10.31315/opsi.v16i1.9289.
[31] P. Y. Pratama, N. Azmi, and I. P. Sari, "Proposed Design of Assistant Tools to Reduce the Risk of Disorders (MSDS) Operator of Weaving Work Station CV XYZ," OPSI, vol. 15, no. 2, p. 216, 2022, doi: 10.31315/opsi.v15i2.7724.
[32] I. M. M. Putra and K. Mutijarsa, “Designing information security risk management on Bali regional police command center based on ISO 27005,” in 2021 3rd East Indonesia Conference on Computer and Information Technology (EIConCIT), IEEE, Apr. 2021, pp. 14–19. doi: 10.1109/EIConCIT50028.2021.9431865.
[33] P. Benedek and F. Bognár, “Compliance risk assessment – Results of a comprehensive literature review,” Acta Polytechnica Hungarica, vol. 21, no. 6, pp. 243–262, 2024, doi: 10.12700/APH.21.6.2024.6.13.
[34] A. Amiruddin, H. G. Afiansyah, and H. A. Nugroho, “Cyber-risk management planning using NIST CSF v1.1, NIST SP 800-53 rev. 5, and CIS controls v8,” in 2021 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS), IEEE, Oct. 2021, pp. 19–24. doi: 10.1109/ICIMCIS53775.2021.9699337.
[35] B. Ghimire and D. B. Rawat, “Recent advances on federated learning for cybersecurity and cybersecurity for federated learning for internet of things,” IEEE Internet Things J, vol. 9, no. 11, pp. 8229–8249, 2022.
[36] S. Sutrisno and P. Puryani, “Development of multi-criteria decision making model in packed beverage industry using global criterion method,” OPSI, vol. 14, no. 2, p. 197, Dec. 2021, doi: 10.31315/opsi.v14i2.5365.
[37] P. H. Kasih, K. Rahmawati, I. Ismianti, Astrid Wahyu Adventri Wibowo, and Hasan Mastrisiswadi, “Vulnerabilities and risk mitigation in Indonesia’s halal poultry chain: Bridging compliance and practice,” OPSI, vol. 18, no. 1, pp. 34–45, Jun. 2025, doi: 10.31315/opsi.v18i1.14892.
[38] G. Samodro, “Pendekatan house of risk untuk penilaian risiko alur penyediaan dan pendistribusian obat (Studi kasus pada apotek ABC),” OPSI, vol. 13, no. 2, p. 92, Dec. 2020, doi: 10.31315/opsi.v13i2.3970.
Downloads
Published
Issue
Section
License
Authors who publish articles in this journal agree to the following conditions:
- Copyright remains with the author and gives the Opsi journal the right as a priority to publish its articles with Creative Commons Attribution 4.0 International license. Which allows articles to be shared with acknowledgement of the author of the article and this journal as the place of publication.
- Authors can distribute their articles on a non-exclusive basis (e.g. in university repositories or books) with notification or acknowledgement of publication in Opsi journals.
- Authors are allowed to post their work online (e.g. on a personal website or in a university repository) before and after the submission process (see The Effect of Open Access)
This work is Licensed Under a Creative Commons Attribution 4.0 International license.
