Supplementary Materials for "Incident-Driven Information System Risk Management Using ISO 31000:2018, STRIDE, and CIA Triad: A Case Study of an Indonesian Manufacturer"
收藏资源简介:
This repository contains supplementary materials for an article submitted to the International Journal of Safety and Security Engineering. The materials are designed as a transferable reference model for ISO 31000:2018 implementation in Indonesian manufacturing organisations undergoing digital transformation. They can be adopted, adapted, and re-used by other researchers and practitioners conducting information system (IS) risk management studies grounded in the ISO 31000:2018 Clause 6 cycle, STRIDE threat modelling, and the CIA Triad. The dataset includes three research instruments (perception survey, semi-structured interview guide, field observation sheet), an Excel file with six aggregated data sheets (demographics, perception means, risk register, risk ranking, treatment plan, KPI scheme), and three reference templates (ISO 31000 Clause 6 mapping, STRIDE-CIA joint analysis, and Likelihood x Impact 5x5 risk heatmap). The case organisation is referred to as "the case organisation" or "PT. ABC" as a pseudonym. All materials have been anonymised in accordance with institutional confidentiality protocols and the research permit issued by the case organisation. Raw interview transcripts, internal incident reports, internal IT audit findings, and per-respondent questionnaire data are NOT included due to commercial-confidentiality agreements.
本仓库收录一篇投至《国际安全与保障工程学报(International Journal of Safety and Security Engineering)》的论文补充材料。本材料专为正在推进数字化转型的印尼制造业组织实施ISO 31000:2018标准构建了可迁移参考模型。开展基于ISO 31000:2018第6条款循环、STRIDE威胁建模及CIA三元组(CIA Triad)的信息系统(Information System, IS)风险管理研究的其他研究人员与从业者,均可对本材料进行采纳、调整与复用。 本数据集包含三类研究工具:感知调查问卷、半结构化访谈提纲、现场观察表;一份包含六张汇总数据表的Excel文件,汇总数据表分别为人口统计学信息、感知均值、风险登记册、风险排序、应对计划与关键绩效指标(Key Performance Indicator, KPI)方案;以及三份参考模板:ISO 31000第6条款映射表、STRIDE-CIA联合分析模板,以及可能性×影响5×5风险热力图。 本次研究的受访组织以“案例组织”或化名PT. ABC代称。所有材料均已按照机构保密规程及受访组织出具的研究许可要求完成匿名化处理。受商业保密协议约束,原始访谈转录文本、内部事件报告、内部IT审计结果以及逐受访者问卷数据均未纳入本数据集。



