MATRIK : Jurnal Manajemen, Teknik Informatika, dan Rekayasa Komputer
Vol. 25 No. 3 (2026)

Mitigating Access Control Vulnerabilities through ISO/IEC 27001-Based Granular Role-Based Access Control Rights Mapping

M. Hadi Prayitno (Universitas Bhayangkara Jakarta Raya, Jakarta, Indonesia)
Abrar Hiswara (Universitas Bhayangkara Jakarta Raya, Jakarta, Indonesia)
Juvinal Ximenes Guterres (Universidade Oriental, Dili, Timor Leste)



Article Info

Publish Date
31 Jul 2026

Abstract

Safeguarding information assets is increasingly critical due to rising technology reliance and data breach risks. Currently, many organizations face critical security gaps in asset management, such as insufficient audit logging and inadequate access protocols, which lead to passive risk identification and compliance drift. The objective of this study is to eliminate these access control vulnerabilities by bridging organizational practices with international standards through a structured security framework. The research method employs a qualitative descriptive approach structured across three sequential and highly interdependent phases: baseline analysis of access management, an ISO/IEC 27001 compliance gap assessment utilizing Clause 5 and Annex A metrics, and strategic Role-Based Access Control (RBAC) framework mapping. Existing information assets are benchmarked against these international requirements to systematically expose operational risks and policy deficiencies. The findings of this study are operationalized into a comprehensive and granular RBAC architecture based on the principle of least privilege. The proposed framework establishes precise access-rights mapping, enabling the organization to transition from passive vulnerability identification to proactive risk mitigation across critical information assets, including security logs, backup systems, and Identity and Access Management (IAM) procedures. The contribution of this study lies in the development of a dynamic, technology-agnostic RBAC implementation framework that extends enforceable and fine-grained security controls across diverse infrastructure environments. Unlike conventional static compliance assessments, the proposed approach transforms ISO/IEC 27001 governance requirements into an audit-ready operational blueprint, thereby strengthening organizational security governance, improving regulatory compliance, and providing a practical reference for implementing standardized access control in modern information systems.

Copyrights © 2026






Journal Info

Abbrev

matrik

Publisher

Subject

Computer Science & IT

Description

MATRIK adalah salah satu Jurnal Ilmiah yang terdapat di Universitas Bumigora Mataram (eks STMIK Bumigora Mataram) yang dikelola dibawah Lembaga Penelitian dan Pengabadian kepada Masyarakat (LPPM). Jurnal ini bertujuan untuk memberikan wadah atau sarana publikasi bagi para dosen, peneliti dan ...