Evaluasi Tingkat Kematangan Keamanan Informasi Berbasis ISO/IEC 27001:2022 pada Perusahaan Manufaktur (Studi Kasus: PT XYZ)

Repository Analytics

Statistic Details

Updated data
13Viewes
0Downloaded
13Accessed per month
3Countries

Abstract

The manufacturing sector has been the most frequently targeted by ransomware for three consecutive years, with most attacks directed at production systems. This study evaluates the information security maturity of PT XYZ, a manufacturing company in Batam, based on ISO/IEC 27001:2022 using the COBIT 2019 Process Capability Model (PCM). A mixed-methods explanatory sequential design was employed. Quantitative data were first collected through a structured questionnaire covering Clauses 4–10 and 93 Annex A controls, each scored on the COBIT 2019 PCM scale, and were then deepened through guided interviews and document analysis to explain the quantitative results. Following a separated assessment approach, capability indices for Clauses 4–10 and Annex A were calculated independently rather than merged into a single overall score. Results show four of seven clauses at Level 1 (Performed), two clauses (Planning and Support) reaching Level 2 (Managed), and Clause 5 Leadership recording the lowest level, Level 0 (Incomplete). Within Annex A, three of four domains sit at Level 1 (Performed), while Domain A.6 People controls is the only domain meeting the Level 3 (Established) target. Qualitative findings confirm that the primary weakness lies in governance, namely the absence of a formal information security policy, internal audit, and a designated ISMS role, rather than technical capacity. The study recommends establishing a formal policy and ISMS role, documenting currently ad-hoc controls as SOPs, and conducting periodic internal audits to support certification readiness.

Description

Citation

IEEE

Endorsement

Review

Supplemented By

Referenced By