The increasing complexity of cyber threats requires organizations, particularly information technology service providers, to implement effective security governance that ensures service continuity while complying with applicable regulatory requirements. As a company specializing in IT consulting, cybersecurity, and data protection, PT OGN requires a systematic evaluation of its managed security services to strengthen its governance practices. This study aims to evaluate the managed security services at PT OGN using the COBIT 2019 framework through design factors analysis, capability assessment, gap analysis, and the development of improvement recommendations. The design factors analysis identified DSS05 (Managed Security Services) as the most relevant domain based on the organization's characteristics, compliance requirements, and cybersecurity risk profile. The capability assessment revealed that DSS05.02 (Manage Network and Connectivity Security) and DSS05.03 (Manage Endpoint Security) remain at Capability Level 1, indicating that both practices have not yet achieved the organization's target of Capability Level 2. Based on these findings, improvement recommendations were formulated across the people, process, and technology dimensions and organized into a 12-month implementation roadmap. This study contributes governance recommendations aligned with business needs, organizational risk profiles, and compliance requirements, thereby supporting the improvement of managed security services governance at PT OGN. Keywords – COBIT 2019; capability assessment; design factors; managed security services; information security governance.
Copyrights © 2026