Journal of Embedded Systems, Security and Intelligent Systems
Vol 7 No 3 (2026): September 2026

IT-Informed ISO/IEC 27001:2022 Readiness Assessment in a Psychiatric Hospital

Ihotbaen Parulian Manalu (Bina Nusantara University)
Gunawan Wang (Bina Nusantara University)



Article Info

Publish Date
05 Sep 2026

Abstract

Purpose – This study assesses the readiness of a psychiatric hospital to strengthen its Information Security Management System (ISMS) using an IT-informed evaluation aligned with ISO/IEC 27001:2022, ISO/IEC 27002:2022, and Indeks KAMI, while translating assessment evidence into preliminary implementation priorities and governance artifacts. Methods – A case-based organizational readiness assessment was conducted using purposive informants from the hospital’s information technology unit. Evidence was collected through structured checklist assessment, interviews, document review, and observation. Annex A controls were evaluated through maturity scoring, aggregation sensitivity analysis, evidence-confidence assessment, and an author-developed implementation-priority heuristic. The findings were subsequently mapped into proposed standard operating procedures and a phased implementation roadmap. Findings – The assessment revealed an uneven security-readiness profile across organizational, people, physical, and technological controls. Organizational controls showed comparatively stronger institutionalization, while people-related controls represented the most substantial readiness gap. Physical and technological controls demonstrated recurring practices but remained inconsistently documented, monitored, and integrated. The findings also indicate that maturity scores alone are insufficient for determining implementation priorities because service impact, compliance urgency, control dependencies, feasibility, and evidence confidence must also be considered. Research Implications – The study provides a practical basis for hospitals to structure cross-functional ISMS improvement, although the findings remain limited by the single-site, IT-informed assessment scope and require broader organizational validation. Originality – The study contributes a transparent evidence-to-score-to-priority-to-artifact approach that links ISMS readiness assessment with preliminary SOP design, ownership, validation gates, and phased implementation planning.

Copyrights © 2026






Journal Info

Abbrev

JESSI

Publisher

Subject

Computer Science & IT

Description

The Journal of Embedded System Security and Intelligent System (JESSI), ISSN/e-ISSN 2745-925X/2722-273X covers all topics of technology in the field of embedded system, computer and network security, and intelligence system as well as innovative and productive ideas related to emerging technology ...