Information Security Risk Management in Contactless Toll System Using ISO 27005
Downloads
The rapid digital transformation of transportation systems has encouraged the adoption of contactless toll transactions to improve traffic efficiency and user convenience. However, their dependence on real-time processing, continuous availability, sensitive data, and external payment integration creates significant information security risks. This study aims to design an information security risk management framework for the Let It Flo contactless toll transaction system at PT Jasamarga Tollroad Operator using ISO/IEC 27005:2022. A qualitative case study approach was employed, with data collected through semi-structured interviews, direct observations, and organizational documentation. The data were analyzed using thematic analysis, while ISO/IEC 27001:2022 and ISO/IEC 27002:2022 supported the formulation of appropriate security controls. The findings identified 26 information security risk scenarios: three were classified as high risk, twelve as moderate-to-high, two as moderate, and nine as low-to-moderate. Seventeen scenarios required mitigation, whereas nine were considered acceptable under the organization’s risk acceptance criteria. Recommended treatments include role-based access control, backup and disaster recovery mechanisms, encryption, penetration testing, physical security controls, system testing, and network redundancy. The study concludes that the ISO/IEC 27005:2022-based framework provides a structured approach to identifying, evaluating, treating, and accepting information security risks, thereby supporting the reliability, security, and continuity of contactless toll transaction services.
Alsaleh, A. (2025). Toward a conceptual model to improve the user experience of a sustainable and secure intelligent transport system. Acta Psychologica, 255, 104892.
Ayo, S. C., Ngala, B., & Amzat, O. (2018). Information security risks assessment: A case study.
Burger, G., & Guna, J. (2024). Enhancing driving safety through user experience evaluation of the C-ITS mobile application: A case study of the Dars Traffic Plus app in a driving simulator environment. Sensors, 24(15), 4948.
Dimian, M., Zadobrischi, E., Căilean, A., Beguni, C., Avătămăniței, S.-A., & Paşcu, P. (2024). Digital transformation of the transport sector towards smart and sustainable mobility. In Digital transformation: Technology, tools, and studies (pp. 215–237). Springer.
Fatorachian, H., Kazemi, H., & Pawar, K. (2025). Digital transformation for sustainable transportation: Leveraging Industry 4.0 technologies to optimize efficiency and reduce emissions. Future Transportation, 5(2), 34.
Grigaliūnas, Š., Schmidt, M., Brūzgienė, R., Smyrli, P., Andreou, S., & Lopata, A. (2024). Holistic information security management and compliance framework. Electronics, 13(19), 3955.
Herath, T. C., Herath, H. S. B., & Cullum, D. (2023). An information security performance measurement tool for senior managers: Balanced scorecard integration for security governance and control frameworks. Information Systems Frontiers, 25(2), 681–721.
Hidayatullah, D. E. R., Kunthi, R., & Harwahyu, R. (2024). Design and analysis of information security risk management based on ISO 27005: Case study on Audit Management System (AMS) XYZ Internal Audit Department. International Journal of Electrical, Computer, and Biomedical Engineering, 2(3). https://doi.org/10.62146/ijecbe.v2i3.81
Huang, Y., Hu, M., Xu, J., & Jin, Z. (2023). Digital transformation and carbon intensity reduction in transportation industry: Empirical evidence from a global perspective. Journal of Environmental Management, 344, 118541.
International Organization for Standardization. (2022). ISO/IEC 27005:2022 information security, cybersecurity and privacy protection—Guidance on managing information security risks.
International Standard Organization. (2022a). ISO/IEC 27001:2022 information security, cybersecurity and privacy protection—Information security management systems—Requirements.
International Standard Organization. (2022b). ISO/IEC 27002:2022 information security, cybersecurity and privacy protection—Information security controls.
Irfan, M. N., Ramadhania, S., Hadi, S., & Pungkasanti, P. T. (2025). ISO/IEC 27005-based e-learning risk management with blockchain architecture: A case study of Semarang University. Journal of Information Systems and Informatics, 7(3), 2898–2919. https://doi.org/10.51519/journalisi.v7i3.1265
Islam, M. D. (2025). Web-based real-time bus tracking system for enhanced commuter experience and efficient fleet management.
Kure, H. I., Islam, S., & Mouratidis, H. (2022). An integrated cyber security risk management framework and risk prediction for the critical infrastructure protection. Neural Computing and Applications, 34(18), 15241–15271.
Li, P., Xue, R., Shao, S., Zhu, Y., & Liu, Y. (2023). Current state and predicted technological trends in global railway intelligent digital transformation. Railway Sciences, 2(4), 397–412.
Mujib, M. S. (2021). Penilaian risiko keamanan informasi pada sistem informasi manajemen rumah sakit menggunakan kerangka kerja ISO/IEC 27005:2022.
Muralidharan, V. (2025). The IoT-based toll gate management system. ICNGTS.
Nazari, Z., & Musilek, P. (2023). Impact of digital transformation on the energy sector: A review. Algorithms, 16(4), 211.
Safitra, M. F., Lubis, M., & Fakhrurroja, H. (2023). Counterattacking cyber threats: A framework for the future of cybersecurity. Sustainability, 15(18), 13369.
Sharma, M., & P. C., A. (2013). A research survey: RFID security & privacy issue. Computer Science & Information Technology, 255–261. https://doi.org/10.5121/csit.2013.3526
Taherdoost, H. (2022). Understanding cybersecurity frameworks and information security standards—A review and comprehensive overview. Electronics, 11(14), 2181.
Verma, S. K., Verma, R., Singh, B. K., & Sinha, R. S. (2024). Management of intelligent transportation systems and advanced technology. In Intelligent transportation system and advanced technology (pp. 159–175). Springer.
Copyright (c) 2026 Dekaton Punjulhafiidhi, Rizal Fathoni Aji

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.



