Evaluasi Keamanan Informasi Menggunakan COBIT 2019 APO13 dalam Mendukung Kualitas Layanan TI

Authors

  • Zulmi Gurhono Universitas AMIKOM Author
  • Alva Hendi Muhammad Universitas AMIKOM Author
  • Asro Nasiri Universitas AMIKOM Author

DOI:

https://doi.org/10.61805/fahma.v24i3.247

Keywords:

COBIT 2019, APO13, keamanan informasi, kualitas layanan TI, tata kelola TI

Abstract

The quality of information technology services in higher education institutions depends on well-designed information security governance. Poltekkes Kemenkes Bengkulu manages academic and health-related data exposed to cybersecurity threats but has not implemented a standardized IT governance framework to determine information security priorities. This study aims to design an IT governance system and prioritize governance and management objectives using the COBIT 2019 Governance System Design Workflow, with APO13–Managed Security as the primary focus. Ten Design Factors were analyzed based on institutional conditions through interviews, observation, and document review. The results identified 17 priority objectives among the 40 COBIT 2019 governance and management objectives, led by BAI10–Managed Configuration (score 100), APO13–Managed Security (90), and APO12–Managed Risk (85). Capability level 4 was targeted for the nine highest-priority objectives, including APO13, driven by logical attack risks (DF3), a High threat landscape (DF5), and High compliance requirements (DF6). Operational recommendations include strengthening information security policies (ISMS), security incident and risk management, and access controls. This study is limited to priority determination and target capability levels; therefore, future research should assess actual capability levels and conduct gap analysis.

Downloads

Download data is not yet available.

References

M. A. Saputra and M. R. Redo, “Penerapan framework COBIT 2019 untuk perancangan tata kelola teknologi informasi pada perguruan tinggi,” J. Sci. Soc. Res., vol. 4, no. 3, pp. 352–358, 2021, doi: 10.54314/jssr.v4i3.715.

A. S. Sukamto, H. Novriando, and A. Reynaldi, “Tata kelola teknologi informasi menggunakan framework COBIT 2019 (studi kasus: UPT TIK Universitas Tanjungpura Pontianak),” JEPIN (J. Edukasi dan Penelit. Inform.), vol. 7, no. 2, pp. 214–220, 2021, doi: 10.26418/jp.v7i2.47859.

M. A. Algiffary, M. I. Herdiansyah, and Y. N. Kunang, “Audit keamanan sistem informasi manajemen rumah sakit dengan framework COBIT 2019 pada RSUD Palembang BARI,” J. Appl. Comput. Sci. Technol., vol. 4, no. 1, pp. 19–26, 2023, doi: 10.52158/jacost.v4i1.505.

R. Moryanda, “Evaluasi sistem informasi manajemen rumah sakit menggunakan framework COBIT 2019 (studi kasus: Semen Padang Hospital),” J. Nas. Teknol. dan Sist. Inf., vol. 9, no. 3, pp. 299–306, 2023, doi: 10.25077/TEKNOSI.v9i3.2023.299-306.

International Organization for Standardization, ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements. Geneva, Switzerland: ISO/IEC, 2022.

R. Sinaga, “Pengembangan model penilaian kepatuhan salah satu perguruan tinggi terhadap standar ISO 27001:2022,” J. Tek. Inform. dan Sist. Inf., vol. 9, no. 3, pp. 381–394, 2024, doi: 10.28932/jutisi.v9i3.6850.

H. M. Melaku, “A dynamic and adaptive cybersecurity governance framework,” J. Cybersecur. Priv., vol. 3, no. 3, pp. 327–350, 2023, doi: 10.3390/jcp3030017.

R. Setyadi and A. A. Rahman, “Enhancing IT governance based on risk and security analysis in a private school: a COBIT 2019 approach,” JOIV Int. J. Informatics Vis., vol. 9, no. 5, pp. 2148–2156, 2025, doi: 10.62527/joiv.9.5.3414.

D. Herlinudinkhaji and L. K. Ramadhani, “Tata kelola layanan teknologi informasi dengan ITIL V4 untuk estimasi layanan,” REMIK Ris. dan E-Jurnal Manaj. Inform. Komput., vol. 7, no. 1, pp. 452–457, 2023, doi: 10.33395/remik.v7i1.12058.

Y. Darmi, S. Fernandez, M. Y. Fathoni, and S. Wijayanto, “Evaluation of governance in information systems security to minimize information technology risks,” INTENSIF J. Ilm. Penelit. dan Penerap. Tek. Sist. Inf., vol. 8, no. 1, pp. 41–52, 2024, doi: 10.29407/intensif.v8i1.21221.

M. R. Katili, L. N. Amali, and S. Suhada, “Design factors in evaluating and formulating IT governance systems in public organizations,” J. RESTI (Rekayasa Sist. dan Teknol. Inf.), vol. 7, no. 5, pp. 1182–1191, 2023, doi: 10.29207/resti.v7i5.4939.

ISACA, COBIT 2019 Framework: Introduction and Methodology. Schaumburg, IL, USA: ISACA, 2018.

ISACA, COBIT 2019 Framework: Governance and Management Objectives. Schaumburg, IL, USA: ISACA, 2018.

ISACA, COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution. Schaumburg, IL, USA: ISACA, 2018.

D. Utomo, M. Wijaya, Suzanna, Efendi, and N. T. M. Sagala, “Leveraging COBIT 2019 to implement IT governance in SME context: a case study of higher education in Campus A,” CommIT J., vol. 16, no. 2, pp. 129–141, 2022, doi: 10.21512/commit.v16i2.8172.

A. B. Sipayung, R. Yunis, and E. Elly, “Evaluation of information technology governance at Mikroskil University using COBIT 2019 framework with BAI11 domain,” Int. J. Res. Appl. Technol., vol. 2, no. 2, pp. 128–143, 2022, doi: 10.34010/injuratech.v2i2.8085.

D. Darmawan and A. F. Wijaya, “Analisis dan desain tata kelola teknologi informasi menggunakan framework COBIT 2019 pada PT XYZ,” J. Comput. Inf. Syst. Ampera, vol. 3, no. 1, pp. 1–17, 2022, doi: 10.51519/journalcisa.v3i1.139.

E. Wulandari, L. H. Atrinawati, and M. G. L. Putra, “Perancangan tata kelola teknologi informasi dengan menggunakan framework COBIT 2019 pada PT XYZ Balikpapan,” DoubleClick J. Comput. Inf. Technol., vol. 5, no. 2, pp. 96–104, 2022, doi: 10.25273/doubleclick.v5i2.10067.

A. Zai, A. H. Muhammad, and A. Nasiri, “Tinjauan literatur audit teknologi informasi pada COBIT 2019 fokus domain APO14,” JINTEKS (J. Inform. Teknol. dan Sains), vol. 5, no. 4, pp. 607–611, 2023, doi: 10.51401/jinteks.v5i4.3507.

R. Prasetya, A. H. Muhammad, and A. Nasiri, “Perancangan model manajemen (tata kelola) data menggunakan domain APO14 COBIT 2019,” JIP (J. Inform. Polinema), vol. 10, no. 3, pp. 389–396, 2024, doi: 10.33795/jip.v10i3.5135.

R. N. Christiadi and R. Sutomo, “Measurement of IT security governance capabilities using COBIT 2019 at Indonesian business sector,” G-Tech J. Teknol. Terap., vol. 7, no. 4, pp. 1498–1508, 2023, doi: 10.33379/gtech.v7i4.3170.

A. Angelina and M. I. Fianty, “Capability level assessments of information security controls: an empirical analysis of practitioners assessment capabilities,” G-Tech J. Teknol. Terap., vol. 8, no. 1, pp. 91–103, 2024, doi: 10.33379/gtech.v8i1.3509.

Downloads

Published

30-09-2026

How to Cite

Evaluasi Keamanan Informasi Menggunakan COBIT 2019 APO13 dalam Mendukung Kualitas Layanan TI. (2026). FAHMA : Jurnal Informatika Komputer, Bisnis Dan Manajemen, 24(3), 337-348. https://doi.org/10.61805/fahma.v24i3.247

Similar Articles

41-50 of 144

You may also start an advanced similarity search for this article.

Most read articles by the same author(s)

1 2 3 4 5 6 7 8 9 10 > >>