Statistical data is a strategic asset for national development; its security and integrity are prerequisites for public trust. This study evaluates perceived capability of data security governance at a regional statistical agency using the COBIT 2019 framework across APO12 (Manage Risk), APO13 (Manage Security), and DSS05 (Manage Security Services). A census survey of 17 employees involved in information system management was conducted using a 45-item, 5-point Likert questionnaire (15 items per domain). The final measurement model retained 32 valid items (APO12 15, APO13 6, DSS05 11). All constructs showed high reliability (Cronbach's alpha 0.912–0.961; composite reliability 0.938–0.967) and adequate convergent validity (AVE 0.665–0.728). However, discriminant validity was not fully established: the HTMT value between APO12 and APO13 (0.908) exceeded the 0.90 threshold, and the Fornell-Larcker criterion was also violated for that pair. Response distribution was highly homogeneous (69.7% of all responses were scored 4 "Agree"; no score-1 responses; average per-respondent standard deviation of only 0.29), indicating a tendency toward acquiescence response style. All measured capability levels were rated Largely Achieved with achievement scores between 75.7% and 82.4%, yielding capability level L5 for APO12 and DSS05 and L3 for APO13, with no gap against the target level 3 (Defined). Owing to the perception-based instrument and small sample size, these results cannot be interpreted as actual maturity. The study recommends evidence-based capability assessment (documents, interviews, and observation), a more discriminative instrument, and further testing with a larger sample
Copyrights © 2026