Juvinal Ximenes Guterres
Universidade Oriental, Dili, Timor Leste

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Mitigating Access Control Vulnerabilities through ISO/IEC 27001-Based Granular Role-Based Access Control Rights Mapping M. Hadi Prayitno; Abrar Hiswara; Juvinal Ximenes Guterres
MATRIK : Jurnal Manajemen, Teknik Informatika dan Rekayasa Komputer Vol. 25 No. 3 (2026)
Publisher : Universitas Bumigora

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.30812/matrik.v25i3.6653

Abstract

Safeguarding information assets is increasingly critical due to rising technology reliance and data breach risks. Currently, many organizations face critical security gaps in asset management, such as insufficient audit logging and inadequate access protocols, which lead to passive risk identification and compliance drift. The objective of this study is to eliminate these access control vulnerabilities by bridging organizational practices with international standards through a structured security framework. The research method employs a qualitative descriptive approach structured across three sequential and highly interdependent phases: baseline analysis of access management, an ISO/IEC 27001 compliance gap assessment utilizing Clause 5 and Annex A metrics, and strategic Role-Based Access Control (RBAC) framework mapping. Existing information assets are benchmarked against these international requirements to systematically expose operational risks and policy deficiencies. The findings of this study are operationalized into a comprehensive and granular RBAC architecture based on the principle of least privilege. The proposed framework establishes precise access-rights mapping, enabling the organization to transition from passive vulnerability identification to proactive risk mitigation across critical information assets, including security logs, backup systems, and Identity and Access Management (IAM) procedures. The contribution of this study lies in the development of a dynamic, technology-agnostic RBAC implementation framework that extends enforceable and fine-grained security controls across diverse infrastructure environments. Unlike conventional static compliance assessments, the proposed approach transforms ISO/IEC 27001 governance requirements into an audit-ready operational blueprint, thereby strengthening organizational security governance, improving regulatory compliance, and providing a practical reference for implementing standardized access control in modern information systems.