Nur Wachid Hidayatulloh
Diponegoro University

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

A Socio-Technical Assessment of Information Security Management Using KAMI Index, ISO/IEC 27001:2022, and User Awareness Nur Wachid Hidayatulloh; Dinar Mutiara Kusumo Nugraheni; Oky Dwi Nurhayati
Journal of Information System and Informatics Vol 8 No 4 (2026): August
Publisher : Asosiasi Doktor Sistem Informasi Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.63158/journalisi.v8i4.1746

Abstract

ISO/IEC 27001:2022 is one of the certifications for Information Security Management Systems (ISMS). The study employs a mixed descriptive approach, analyzing maturity using the KAMI Index 5.0, ISO/IEC 27001:2022 clause implementation as a gap assessment, and user awareness of the ISMS, examined through socio-technical system theory at a university in Semarang. The results reveal a gap between the two subsystems: the technical subsystem shows high overall readiness but is not fully optimal, with weaker domain in Personal Data Protection (level II). The KAMI Index places the university's overall maturity at level V, while the ISO/IEC 27001:2022 gap assessment shows several clauses still unimplemented. Meanwhile, the social subsystem for user awareness revealed that the ISMS was less than optimal according to user interviews, even though the test achieved a score of 81.2% and was rated Very Worthy. Suitable standard operating procedures (SOPs) were also found lacking for several clauses and indicators. Socio-technical systems theory emphasizes joint consideration of social and technical elements in designing and implementing complex organizational systems such as information security; applying it here shows both subsystems must be evaluated holistically rather than separately.