Risk Mitigation Plan in API Integration Using NIST SP 800 - 37

Authors

  • Rangga Octavian Pratama Information System Department, Widyatama University, Bandung, Indonesia Author
  • Prawita Oktovini Sihotang Faculty of Engineering, Department of Information System Unversitas Widyatama Author
  • Widia Rismadewi Faculty of Engineering, Department of Information System Unversitas Widyatama Author
  • Asep Rifki Pauji Faculty of Engineering, Department of Information System Unversitas Widyatama Author
  • Falahah Faculty of Engineering, Department of Information System Unversitas Widyatama Author

DOI:

https://doi.org/10.61841/xmt4s111

Keywords:

Risk, NIST 800-37, intergation, API, mitigation

Abstract

Integrating the backend system or external system in recent business system is a must. Complexity in operational system makes company or organization should have a good plan in integration. The best and easy way in integration is using application programming interface (API) that can help us integrating the system without doing lots of modification. But, integrating the API or the system using API can lead into some risky situation, such as data format problem, security, or non-standard API development issue. The risk issue need to encounter by preparing proper mitigation plan. It can be done by implementing framework for risk management or assessment such as explained on NIST SP 800-37 documents. On this research, we implement the risk assessment on integration problem at PT.X, which provide online services and needs to process data from customer, sales, and financial information. The data analysis from risk assessment shows that there are three top risks need to resolve which are accountability, hesitating over API utilization, and lack of Security. Based on this result, we also propose some mitigation plan to reduce the impact, such as establish roles and responsibility for API development and maintenance, socialized and promote API utilization, and increase the security capability.

 

Downloads

Download data is not yet available.

References

[1] Darmawi, H., 2014. Manajemen Risiko. Jakarta: Bumi Aksara.

[2] Gondodiyoto, Sanyoto. (2007). Audit Sistem Informasi Pendekatan COBIT.

[3] Idroes, F. N. (2008). Manajemen Risiko Perbankan: Pemahaman Pendektan 3

[4] Internet Banking And Commerce

[5] Jakarta: Penerbit Mitra Wacana.

[6] Kasidi, 2014. Manajemen Risiko. Bogor: Ghalia IndonesiaMedia. Pilar Kesepakatan Bassel II Terkait Aplikasi Regulasi dan Pelaksanaannya di Indonesia. Jakarta: Rajawali Pers

[7] Pinontoan, J. H. (2010). Manajemen Risiko TI Konsep-konsep. Majalah PC

[8] Stoneburner, G., Goguen, A. & Feringa, A., 2002. Risk Management Guide for Information Technology Systems Recommendation of the National Institute of Standards and Technology Special Publication 800-30.

[9] Wolingpirayat, J.2007. E-payment Strategies of Bank Card Innovation. Journal of Internet Banking And Commerce

[10] Yu, D., Ebadi, A.G., Jermsittiparsert, K., Jabarullah, N., Vasiljeva, M.V., & Nojavan, S. (2019) Risk- constrained Stochastic Optimization of a Concentrating Solar Power Plant, IEEE Transactions on Sustainable Energy, https://doi.org/ 10.1109/TSTE.2019.2927735.

[11] Michael, S.; Purba, J., 2007, Membongkar Teknologi Pemrograman Web service, Gava Media, Yogyakarta

Downloads

Published

30.09.2020

How to Cite

Pratama, R. O., Sihotang, P. O., Rismadewi, W., Pauji, A. R., & Falahah. (2020). Risk Mitigation Plan in API Integration Using NIST SP 800 - 37. International Journal of Psychosocial Rehabilitation, 24(7), 2738-2746. https://doi.org/10.61841/xmt4s111