Cybersecurity evaluation is necessary to identify the security condition and gaps within an information system. The Forest Product Administration Information System (SIPUHH) is an information system used to support electronic recording and reporting in forest product administration processes. This study aims to develop a layered mapping approach for evaluating SIPUHH cybersecurity in a structured and traceable manner. The frameworks used are NIST CSF 2.0 as the cybersecurity outcome layer, COBIT 2019 APO13 – Managed Security as the management layer, and NIST SP 800-53 as the security control layer. This study employs a qualitative approach using an evaluative research design with a descriptive-analytical orientation. Data were collected through interviews with SIPUHH developers and responsible personnel, as well as through verification of technical and documentary evidence. The results of the layered mapping were operationalized into 27 indicators to establish the Current Profile, formulate the Target Profile, and identify SIPUHH cybersecurity gaps. The evaluation results show that 10 indicators are classified as High priority, 15 indicators as Medium priority, and 2 indicators as Maintenance. The findings indicate that SIPUHH has established several technical and operational security capabilities; however, these capabilities are not yet fully supported by formal and structured security governance, policies, procedures, documentation, and evaluation processes. The analysis of interrelationships among the findings resulted in six security improvement programs covering governance and risk management, third parties and interconnections, protection controls, monitoring and event analysis, incident response, and service resilience and recovery.
Copyrights © 2026