Jurnal Locus Penelitian dan Pengabdian
Vol. 4 No. 11 (2025): JURNAL LOCUS: Penelitian dan Pengabdian

Analisis Kesiapan PT. XYZ Sebagai Penyedia Layanan TI Dalam Mengadopsi Standar Nist CSF dan ISO 27001

Sea, Rona Aulia Wangsa (Unknown)
Fatonah, Nenden Siti (Unknown)



Article Info

Publish Date
15 Nov 2025

Abstract

This study aims to analyze the readiness level of PT. XYZ, an information technology service provider, in adopting technology security frameworks, specifically NIST Cybersecurity Framework (CSF) and ISO 27001. A qualitative approach was applied through interviews with five informants from the executive level and technical teams. The data were analyzed using thematic analysis. Findings indicate that the company is still at an early stage of readiness and lacks a systematic approach to managing information security. The main inhibiting factors include the absence of formal policies, limited resources, and a low level of understanding of international standards. However, the management’s awareness and desire to enhance client trust serve as important driving factors. Recommended improvement strategies include conducting training, establishing formal security policies, forming dedicated security teams, and integrating security into business processes. This study provides a preliminary overview for the company in designing a standardized security strategy and serves as a reference for similar studies in the IT services sector.

Copyrights © 2025






Journal Info

Abbrev

jl

Publisher

Subject

Aerospace Engineering Automotive Engineering Decision Sciences, Operations Research & Management Electrical & Electronics Engineering Mathematics

Description

Jurnal Locus: Jurnal Ilmiah Penelitian dan Pengabdian, double-blind and open-access academic journal in the Multidisiplin. This journal is published once a month by CV. Riviera ...