Technology is currently developing rapidly and covers almost all fields, one of which is business. XYZ Boutique is a women's clothing business that uses IS/IT in its business activities. However, using technology still has shortcomings and opportunities for business damage. Therefore, this research will analyze IS/IT risks at XYZ Boutique using the ISO 31000:2018 framework. In analyzing risk, data is needed that is collected through interviews and observations with related parties or places. Based on the interview results, 16 risks were obtained and based on the likelihood and impact tables, 5 high risks, 9 medium risks and 2 low risks were obtained. All these risks will be provided with solutions to handle them.

This work is licensed under a Creative Commons Attribution 4.0 International License.
[2] Saputra, E., Rudianto, C., & Tanaem, P. F. (2022). Analisis Resiko Sistem Informasi Penjualan Berbasis ISO 31000: Study Kasus PT XYZ. Jurnal Pengembangan Sistem Informasi dan Informatika, 3(1), 1-10.
[3] ISO, “ISO 31000:2018 Risk Management - Guidelines,” 2018. [Daring]. Tersedia: [21 Feb 2022].
[4] K. B. Mahardika, A. F. Wijaya, and D. Cahyono.2018,“Manajemen Risiko Teknologi Informasi Menggunakan ISO31000 : 2018 (Studi Kasus: CV. XY),”Vol. 2018, pp. 277–284.
[5] Fachrezi, M. I. (2021). Manajemen Risiko Keamanan Aset Teknologi Informasi Menggunakan Iso 31000: 2018 Diskominfo Kota Salatiga. JATISI (Jurnal Teknik Informatika dan Sistem Informasi), 8(2), 764-773.
[6] Lenaini, I. (2021). Teknik pengambilan sampel purposive dan snowball sampling. Historis: Jurnal Kajian, Penelitian dan Pengembangan Pendidikan Sejarah, 6(1), 33-39.
[7] Pribadi, H. I., & Ernastuti, E. (2020). Manajemen Risiko Teknologi Informasi Pada Penerapan E-Recruitment Berbasis ISO 31000: 2018 Dengan FMEA (Studi Kasus PT Pertamina). JSINBIS (Jurnal Sistem Informasi Bisnis), 10(1), 28-35.
[8] Sukma Artha Atmojo, 2020, “Analisis Manajemen Risiko Teknologi Informasi pada Website Ecofo Menggunakan ISO 31000,”J. Comput. Sci. Eng., Vol. 1, No. 2, pp. 128–146, doi: 10.36596/jcse.v1i2.76
[9] W. Harefa and K. D. Hartomo, “Analisis Manajemen Risiko dengan menggunakan Framework ISO 31000:2018 pada Sistem Informasi Gudang,” J. Tek. Inform. dan Sist. Inf., vol. 9, no. 1, pp. 407–420, 2022
[10] G. W. Lantang, A. D. Cahyono, and M. N. N. Sitokdana, 2019, “Analisis Risiko Teknologi Informasi pada Aplikasi Sap Di PT Serasi Autoraya Menggunakan Iso 31000,” Sebatik, Vol. 23, No. 1, pp. 36–43, doi: 10.46984/sebatik.v23i1.441.