Digital transformation in the university environment requires good information security management to protect academic, administrative, and personal data. This study aims to evaluate the implementation of information security governance in the ICT unit of Universitas Sari Mulia (UNISM) using the COBIT 5 framework, especially the EDM03 (Ensure Risk Optimization) and APO13 (Manage Security) domains. The research methods used were semi-structured interviews and surveys to relevant stakeholders. The results of the evaluation show that the maturity level of the two domains is at level 3 (Established), while the expected maturity level is level 5 (Optimizing), so there is a gap of two levels. Based on these findings, strategic recommendations were prepared to improve the effectiveness of information security governance in a sustainable manner in ICT UNISM. This research also contributes to the development of IT governance practices in the higher education sector in Indonesia.