Strategi Pengelolaan Risiko dan Keamanan Informasi pada Platform E-Bisnis: Studi Kasus Tokopedia

(Tokopedia: Bagaimana Platform Ini Menangani Insiden Kebocoran Data pada Tahun 2020, Termasuk Langkah Mitigasi dan Perbaikan Sistem Keamanannya)

Authors

  • Marsyanada* Universitas 17 Agustus 1945 Surabaya

DOI:

https://doi.org/10.63200/jebmass.v2i6.152

Keywords:

Data Security, Online Sales Transaction, Tokopedia, Data Encryption

Abstract

The data leak incident experienced by Tokopedia in 2020 is an important reminder of the need for effective risk management and information security strategies on e-business platforms. This article discusses the mitigation measures taken by Tokopedia, including system security enhancements, user education, and collaboration with cybersecurity agencies. Using a qualitative approach through case study analysis, this article reviews the incident chronology, evaluation of mitigation measures, and recommendations for more proactive risk management. The findings show that while Tokopedia's mitigation measures were successful in improving security, further investment in proactive technologies such as two-factor authentication (2FA) and end-to-end encryption is required. The article concludes with recommendations for other e-business platforms to minimize the risk of data leakage and maintain customer trust.

Downloads

Download data is not yet available.

References

Alicea, M., & Alsmadi, I. (2021). Misconfiguration in firewalls and network access controls: Literature review. In Future Internet (Vol. 13, Issue 11). https://doi.org/10.3390/fi13110283

Anderson, R. J. (2010). Security engineering: a guide to building dependable distributed systems. John Wiley & Sons.

Anwar, R. W., Abdullah, T., & Pastore, F. (2021). Firewall best practices for securing smart healthcare environment: A review. In Applied Sciences (Switzerland) (Vol. 11, Issue 19). https://doi.org/10.3390/app11199183

Bada, M., Sasse, A. M., & Nurse, J. R. C. (2019). Cyber security awareness campaigns: Why do they fail to change behaviour? ArXiv Preprint ArXiv:1901.02672.

Bringhenti, D., Marchetto, G., Sisto, R., Valenza, F., & Yusupov, J. (2023). Automated Firewall Configuration in Virtual Networks. IEEE Transactions on Dependable and Secure Computing, 20(2). https://doi.org/10.1109/TDSC.2022.3160293

Clark, D., Berson, T., & Lin, H. S. (2014). At the nexus of cybersecurity and public policy. Computer Science and Telecommunications Board. National Research Council, Washington DC: The National Academies Press.

Dmitrienko, A., Liebchen, C., Rossow, C., & Sadeghi, A. R. (2014). On the (in)security of mobile two-factor authentication. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 8437. https://doi.org/10.1007/978-3-662-45472-5_24

Equifax. (2017). Equifax Data Breach Summar.

Gupta, C. (2017). The Market’s Law of Privacy: Case Studies in Privacy and Security Adoption. IEEE Security and Privacy, 15(3). https://doi.org/10.1109/MSP.2017.57

International Organization for Standardization (ISO). (2013). Information technology – Security techniques – Information security management systems – Requirements.

Jeon, W., Kim, J., Nam, J., Lee, Y., & Won, D. (2012). An enhanced secure authentication scheme with anonymity for wireless environments. IEICE Transactions on Communications, 95(7), 2505–2508.

National Institute of Standards and Technology (NIST). (2018). Framework for Improving Critical Infrastructure Cybersecurity.

Sugiyono, P. D. (2017). Metode penelitian bisnis: pendekatan kuantitatif, kualitatif, kombinasi, dan R&D. Penerbit CV. Alfabeta: Bandung, 225.

Symantec. (2017). 2017 Internet Security Threat Report.

Tokopedia. (2020). Pernyataan Resmi mengenai Kebocoran Data pada Mei 2020.

Zuech, N., & Yardley, P. A. (2010). Machine Vision—Does the Technology Satisfy the Marketplace. A Panel Discussion. In Machine Vision for Three-Dimensional Scenes (pp. 399–403). Academic Press.

Downloads

Published

2023-11-04

How to Cite

Marsyanada, M. (2023). Strategi Pengelolaan Risiko dan Keamanan Informasi pada Platform E-Bisnis: Studi Kasus Tokopedia: (Tokopedia: Bagaimana Platform Ini Menangani Insiden Kebocoran Data pada Tahun 2020, Termasuk Langkah Mitigasi dan Perbaikan Sistem Keamanannya). JOURNAL OF ECONOMICS, BUSINESS, MANAGEMENT, ACCOUNTING AND SOCIAL SCIENCES, 2(6), 299–303. https://doi.org/10.63200/jebmass.v2i6.152
Abstract Views: 506 | File Views: 426