DESIGNING A THIRD-PARTY RISK MANAGEMENT POLICY FOR PT XYZ USING ISO 31000, NIST CSF 2.0, ISO/IEC 27701, CIS CONTROLS V8, AND UU PDP

dc.contributor.authorYasmin, Tamara Sinatrya
dc.contributor.authorAmin Soetomo, Mohammad Achmad
dc.contributor.authorLim, Charles
dc.date.accessioned2026-04-27T09:27:20Z
dc.date.issued2025-08-13
dc.description.abstractBusinesses are leaning more on third-party vendors when advancing their digital transformation, yet this dependency exposes them to heightened cybersecurity and privacy threats. For PT XYZ, a financial institution in Indonesia, the challenges are intensified by strict privacy requirements set by the Personal Data Protection Law (UU PDP). This study identifies critical governance gaps in PT XYZ, including the absence of standardized due diligence, lack of vendor monitoring, and insufficient data protection clauses in contracts. Using a mixed-methods approach such as document review, surveys, and interviews. This research integrates ISO 31000, NIST CSF 2.0, ISO/IEC 27701, and CIS Controls v8 to design a risk-based third-party management framework. Findings highlight three priority areas: implementing structured vendor onboarding, establishing continuous monitoring, and enforcing contractual obligations for data protection and secure deletion. Validation by internal stakeholders and external experts confirmed the framework’s feasibility, regulatory alignment, and operational relevance. The research concludes that PT XYZ can adopt this integrated policy framework that will enhance the cybersecurity posture, align completely with UU PDP, and provide a replicable governance model for other financial institutions.
dc.identifier.urihttps://dspace-repository.sgu.ac.id/handle/123456789/89
dc.language.isoen
dc.publisherSwiss German University
dc.subjectThird-Party Risk Management
dc.subjectCybersecurity
dc.subjectISO 31000
dc.subjectNIST CSF 2.0
dc.subjectUU PDP
dc.titleDESIGNING A THIRD-PARTY RISK MANAGEMENT POLICY FOR PT XYZ USING ISO 31000, NIST CSF 2.0, ISO/IEC 27701, CIS CONTROLS V8, AND UU PDP
dc.typeThesis

Files

Original bundle

Now showing 1 - 5 of 6
Loading...
Thumbnail Image
Name:
COVER.pdf
Size:
501.15 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 1.pdf
Size:
549.87 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 2.pdf
Size:
286.29 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 3.pdf
Size:
394.65 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 4.pdf
Size:
454 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description:

Collections