Information security management governance is needed to maintain the confidentiality, integrity and availability of information in the company. This research requires an understanding of information security that is ongoing in the company to conduct a capability assessment and provide recommendations for improvements using COBIT 5 at Graha Kirana College. In the process, the five COBIT frameworks are used to increase the effectiveness of agency security. The selection of the COBIT domain was carried out by reviewing the business documents of Graha Kirana College and interviews with IT managers. Good news security can be achieved through the implementation of a number of technical measures supported by appropriate management policies and procedures. As an activity carried out to guide and manage the company in the context of facing risks. Risk management can be understood as a process that is carried out rationally and systematically arranged to guide, identify, monitor, prepare solutions, and report hazards.