Jurnal Sains dan Teknologi
Vol. 6 No. 2 (2026): Mei - Agustus

Evaluasi Tata Kelola TI Menggunakan COBIT 5 Domain DSS05 pada PT Pos Indonesia Regional Kalimantan

Muhammad Khairul (Teknologi Informasi, Fakultas Ilmu Komputer, Universitas Mulia)
Muhammad Fadilah (Teknologi Informasi, Fakultas Ilmu Komputer, Universitas Mulia)
Yustian Servanda (Teknologi Informasi, Fakultas Ilmu Komputer, Universitas Mulia)



Article Info

Publish Date
05 Jul 2026

Abstract

IT security governance has become an urgent organizational concern, as government agencies and state-owned enterprises managing sensitive data face escalating cybersecurity threats and stricter obligations under Indonesia's Personal Data Protection Law. PT Pos Indonesia, a long-established state-owned enterprise now processing personal data and financial transactions of millions of customers daily, has never had its IT security governance evaluated against an internationally recognized framework, leaving its actual capability level unknown despite operating with a notably limited internal IT team. This study aims to evaluate the capability level of IT security governance at PT Pos Indonesia Regional Kalimantan using the COBIT 5 framework, specifically the DSS05 (Manage Security Services) domain, to identify gaps against the targeted maturity level and formulate structured improvement recommendations. A descriptive quantitative approach was employed, with primary data collected through a 35-item Likert-scale questionnaire administered to twenty cross-divisional respondents via purposive sampling, complemented by semi-structured interviews with four key informants; capability levels were determined by converting average scores to the COBIT 5 Process Assessment Model scale and analyzed through gap analysis against the targeted Level 3 (Established). Results show an overall average score of 3.74, placing governance at Level 3, with five of seven sub-domains meeting the target while DSS05.02 (Network Security) and DSS05.03 (Endpoint Security) remained at Level 2 and DSS05.04 (Identity Management) exceeded expectations at Level 4. Recommended improvements include network segmentation, formal endpoint control policy, and sustained security awareness training.

Copyrights © 2026