MANAJERIAL
Vol 22, No 2 (2023): MANAJERIAL Volume 22 No. 2

INTEGRASI FRAMEWORK DALAM MENYUSUNAN PROSEDUR PENGELOLAAN KEAMANAN INFORMASI

Hanifah, Syarifah Norahanum (Unknown)
Izzuddin, Muhammad Andik (Unknown)
Yalina, Nita (Unknown)



Article Info

Publish Date
03 Dec 2023

Abstract

Improving the quality of services today is played by the adoption of ICT in various scopes, so that the aspect that emerges is the issue of information security in the administration of governance. This study aims to develop information security management guidelines with the integration of 3 frameworks which include COBIT 5, ITIL V3 and ISO/IEC 27001:2013. The object of research is the Jombang District Communication and Information Service. There are 3 stages of research, namely the preparation of guidelines, verification, validation and improvement. The results of the first stage were obtained from each framework starting from COBIT 5 using APO13 with 10 activities, ITIL V3 service design sub domain Information Security Management with 7 activities, and ISO/IEC 27001:2013 clause A.11 15 activities. COBIT sub domain 5 APO13.01 mapped with 9 clauses ISO/IEC 27001:2013 and 3 activities ITIL, APO13.02 mapped with 4 clauses ISO/IEC 27001:2013 and 1 activity ITIL, APO13.03 mapped with 2 clauses ISO/IEC 27001:2013 and 3 ITIL activities. The results of the verification showed that 66.7% of the interviewees rated the guidelines in language and terms as being quite clear, easy to understand and implement. Meanwhile, 100% of the interviewees considered that the division of roles was appropriate and able to answer agency needs. The results of the guideline expert judgment validation were declared valid.

Copyrights © 2023