The advancement of Information Technology (IT) has driven the use of cloud-based core banking systems as the primary infrastructure in banking operations. PT Bank BPR NTB Perseroda's reliance on this system necessitates IT governance that ensures service availability, system reliability, and information security. Observations and interviews reveal issues such as cloud service network disruptions, power supply interruptions, and potential cybersecurity threats impacting the timeliness of credit processes and customer transactions. This study aims to evaluate the effectiveness of IT governance using COBIT 5 and identify the implementation of information security controls based on ISO/IEC 27001:2022. The COBIT 5 domains utilized include EDM01, APO12, DSS01, and MEA03, while the ISO/IEC 27001:2022 controls encompass A.5.1, A.5.23, and A.5.30. A mixed methods approach was employed through interviews, observations, document studies, and questionnaires involving 32 respondents. Data analysis was conducted using the Process Assessment Model (PAM) of COBIT 5. The results indicate average capability levels ranging from 3.30 to 3.38, suggesting that governance processes have been implemented but that risk management and operational monitoring require enhancement. This study concludes that the integration of COBIT 5 and ISO/IEC 27001:2022 provides a comprehensive evaluation of governance and information security.
Copyrights © 2026