Jurnal Komputer, Informasi dan Teknologi
Vol. 6 No. 1 (2026): June

Implementation of ISO/IEC 27001:2013 for Information Security Management System at Information System Unit of PT. KAI Divre III Palembang

Irvan Ramadhan (Universitas Bina Darma)
Nyimas Sopiah (Universitas Bina Darma)



Article Info

Publish Date
03 Feb 2026

Abstract

The background of this research is the vulnerability of the Information System Unit of PT KAI Divre III Palembang to cyber threats such as malware, saved browser passwords, and weak physical asset management, amidst high dependence on IT for transportation operations. The purpose of the research is to analyze the condition of the ISO/IEC 27001:2013-based ISMS, identify gaps, and recommend controls through the PDCA cycle. This type of research is a qualitative descriptive study with a case study approach. The population is all unit personnel (15 people), a sample of 10 key informants via purposive sampling. Instruments include semi-structured interviews, checklist observations, and document analysis) (analysis techniques use the Miles and Huberman model with a gap and risk matrix. The results show that the implementation of PDCA is effective: high risks (malware, fire extinguishers) and medium risks are reduced to low through antivirus, device locking, inventory updates, and time synchronization audit corrections. The conclusion is that the ISMS has been structured, increasing operational resilience, although further quantitative evaluation is needed.

Copyrights © 2026






Journal Info

Abbrev

KOMITEK

Publisher

Subject

Computer Science & IT Education Languange, Linguistic, Communication & Media

Description

Jurnal Komputer, Informasi dan Teknologi aims to provide a highly readable and valuable addition to the literature that will serve as an indispensable reference tool for years to come. The scope of the journal includes all new theoretical and experimental findings in the field of Computers, ...