Purpose – This study assesses the readiness of a psychiatric hospital to strengthen its Information Security Management System (ISMS) using an IT-informed evaluation aligned with ISO/IEC 27001:2022, ISO/IEC 27002:2022, and Indeks KAMI, while translating assessment evidence into preliminary implementation priorities and governance artifacts. Methods – A case-based organizational readiness assessment was conducted using purposive informants from the hospital’s information technology unit. Evidence was collected through structured checklist assessment, interviews, document review, and observation. Annex A controls were evaluated through maturity scoring, aggregation sensitivity analysis, evidence-confidence assessment, and an author-developed implementation-priority heuristic. The findings were subsequently mapped into proposed standard operating procedures and a phased implementation roadmap. Findings – The assessment revealed an uneven security-readiness profile across organizational, people, physical, and technological controls. Organizational controls showed comparatively stronger institutionalization, while people-related controls represented the most substantial readiness gap. Physical and technological controls demonstrated recurring practices but remained inconsistently documented, monitored, and integrated. The findings also indicate that maturity scores alone are insufficient for determining implementation priorities because service impact, compliance urgency, control dependencies, feasibility, and evidence confidence must also be considered. Research Implications – The study provides a practical basis for hospitals to structure cross-functional ISMS improvement, although the findings remain limited by the single-site, IT-informed assessment scope and require broader organizational validation. Originality – The study contributes a transparent evidence-to-score-to-priority-to-artifact approach that links ISMS readiness assessment with preliminary SOP design, ownership, validation gates, and phased implementation planning.
Copyrights © 2026