The quality of information technology services in higher education institutions depends on well-designed information security governance. Poltekkes Kemenkes Bengkulu manages academic and health-related data exposed to cybersecurity threats but has not implemented a standardized IT governance framework to determine information security priorities. This study aims to design an IT governance system and prioritize governance and management objectives using the COBIT 2019 Governance System Design Workflow, with APO13–Managed Security as the primary focus. Ten Design Factors were analyzed based on institutional conditions through interviews, observation, and document review. The results identified 17 priority objectives among the 40 COBIT 2019 governance and management objectives, led by BAI10–Managed Configuration (score 100), APO13–Managed Security (90), and APO12–Managed Risk (85). Capability level 4 was targeted for the nine highest-priority objectives, including APO13, driven by logical attack risks (DF3), a High threat landscape (DF5), and High compliance requirements (DF6). Operational recommendations include strengthening information security policies (ISMS), security incident and risk management, and access controls. This study is limited to priority determination and target capability levels; therefore, future research should assess actual capability levels and conduct gap analysis.