Information Security Risk Management in Contactless Toll System Using ISO 27005

Information Security Risk Management ISO/IEC 27005 Toll Transaction System Payment System

Authors

August 14, 2026

Downloads

The rapid digital transformation of transportation systems has encouraged the adoption of contactless toll transactions to improve traffic efficiency and user convenience. However, their dependence on real-time processing, continuous availability, sensitive data, and external payment integration creates significant information security risks. This study aims to design an information security risk management framework for the Let It Flo contactless toll transaction system at PT Jasamarga Tollroad Operator using ISO/IEC 27005:2022. A qualitative case study approach was employed, with data collected through semi-structured interviews, direct observations, and organizational documentation. The data were analyzed using thematic analysis, while ISO/IEC 27001:2022 and ISO/IEC 27002:2022 supported the formulation of appropriate security controls. The findings identified 26 information security risk scenarios: three were classified as high risk, twelve as moderate-to-high, two as moderate, and nine as low-to-moderate. Seventeen scenarios required mitigation, whereas nine were considered acceptable under the organization’s risk acceptance criteria. Recommended treatments include role-based access control, backup and disaster recovery mechanisms, encryption, penetration testing, physical security controls, system testing, and network redundancy. The study concludes that the ISO/IEC 27005:2022-based framework provides a structured approach to identifying, evaluating, treating, and accepting information security risks, thereby supporting the reliability, security, and continuity of contactless toll transaction services.