Supplementary Materials for "Incident-Driven Information System Risk Management Using ISO 31000:2018, STRIDE, and CIA Triad: A Case Study of an Indonesian Manufacturer"
收藏资源简介:
This repository contains supplementary materials for an article submitted to the International Journal of Safety and Security Engineering. The materials are designed as a transferable reference model for ISO 31000:2018 implementation in Indonesian manufacturing organisations undergoing digital transformation. They can be adopted, adapted, and re-used by other researchers and practitioners conducting information system (IS) risk management studies grounded in the ISO 31000:2018 Clause 6 cycle, STRIDE threat modelling, and the CIA Triad. The dataset includes three research instruments (perception survey, semi-structured interview guide, field observation sheet), an Excel file with six aggregated data sheets (demographics, perception means, risk register, risk ranking, treatment plan, KPI scheme), and three reference templates (ISO 31000 Clause 6 mapping, STRIDE-CIA joint analysis, and Likelihood x Impact 5x5 risk heatmap). The case organisation is referred to as "the case organisation" or "PT. ABC" as a pseudonym. All materials have been anonymised in accordance with institutional confidentiality protocols and the research permit issued by the case organisation. Raw interview transcripts, internal incident reports, internal IT audit findings, and per-respondent questionnaire data are NOT included due to commercial-confidentiality agreements.



