Proceedings of The International Conference on Computer Science, Engineering, Social Sciences, and Multidisciplinary Studies
Vol. 1 (2025)

Integrating COBIT 2019 and ISO/IEC 27001 for Strengthening IT Governance and Information Security

Hendry (Unknown)
Siregar, Muhammad Noor Hasan (Unknown)
Apriadi, Deni (Unknown)
Alfiarini (Unknown)
Nuranisah (Unknown)



Article Info

Publish Date
03 Nov 2025

Abstract

This study aims to develop and evaluate an integrated framework combining COBIT 2019 and ISO/IEC 27001 to enhance IT governance and information security management. Using a qualitative-descriptive approach, the research involved document analysis, expert interviews, and a case-based validation within a government institution. The integration process consisted of three phases: mapping, harmonization, and synthesis, which resulted in the development of the Integrated IT Governance and Security Framework (IGSF). The findings reveal a high degree of alignment between COBIT 2019’s governance domains and ISO/IEC 27001’s security control structures, forming a unified model that strengthens strategic alignment, risk management, and compliance. Expert validation confirmed that the IGSF facilitates better communication between governance and security teams, reduces redundancy, and enhances operational efficiency. The practical case study demonstrated improved coordination, documentation, and audit readiness following implementation. This study contributes to IT governance and information security literature by presenting a structured, adaptable framework that organizations can adopt to achieve both governance excellence and security resilience. The results also suggest potential for future quantitative evaluation to measure the impact of this integration on organizational performance and compliance outcomes.

Copyrights © 2025






Journal Info

Abbrev

cessmuds

Publisher

Subject

Religion Computer Science & IT Decision Sciences, Operations Research & Management Education Electrical & Electronics Engineering Engineering

Description

The International Conference on Computer Science, Engineering, Social Science, and Multi-Disciplinary Studies (CESSMUDS) with ISSN No. 3123-2507 (online) is one of the activities organized by Raskha Media Group Publisher. The International Conference on Computer Science, Engineering, Social Science, ...