Information system security is a critical aspect in supporting the continuity of information tech-nology services, particularly in educational institutions that heavily rely on digital systems. This study aims to evaluate the maturity level of information system security risk management using the Information Technology Infrastructure Library (ITIL) V3 framework within the Service Oper-ation domain. This research employs a quantitative approach with total sampling, involving 13 respondents who are directly engaged in information system management at the research site. Data were collected through questionnaires and interviews. The research instrument was devel-oped based on four subdomains of ITIL V3 Service Operation: Event Management, Incident Man-agement, Problem Management, and Access Management. Instrument validity was tested using the Pearson productmoment correlation, and reliability was measured using Cronbach's Alpha. The results indicate that the overall maturity level is 3.44, which falls into the Defined Process category (Level 3), approaching Managed and Measurable (Level 4). Event Management obtained the highest value at 3.88 (Level 4), followed by Access Management at 3.37 (Level 3), Incident Management at 3.32 (Level 3), and Problem Management at 3.21 (Level 3). Gap analysis reveals a discrepancy of 1.56 from the expected optimized condition at Level 5. These findings suggest that although processes have been implemented and documented, improvements are still required par-ticularly in root cause analysis (Problem Management), access control (Access Management), and continuous performance evaluation. This study is expected to serve as a reference for enhancing IT service governance and information system security management based on ITIL practices.
Copyrights © 2026