ISO/IEC 27001:2022 is one of the certifications for Information Security Management Systems (ISMS). The study employs a mixed descriptive approach, analyzing maturity using the KAMI Index 5.0, ISO/IEC 27001:2022 clause implementation as a gap assessment, and user awareness of the ISMS, examined through socio-technical system theory at a university in Semarang. The results reveal a gap between the two subsystems: the technical subsystem shows high overall readiness but is not fully optimal, with weaker domain in Personal Data Protection (level II). The KAMI Index places the university's overall maturity at level V, while the ISO/IEC 27001:2022 gap assessment shows several clauses still unimplemented. Meanwhile, the social subsystem for user awareness revealed that the ISMS was less than optimal according to user interviews, even though the test achieved a score of 81.2% and was rated Very Worthy. Suitable standard operating procedures (SOPs) were also found lacking for several clauses and indicators. Socio-technical systems theory emphasizes joint consideration of social and technical elements in designing and implementing complex organizational systems such as information security; applying it here shows both subsystems must be evaluated holistically rather than separately.
Copyrights © 2026