Security Infrastructure Service and Information Security Management Capability Audit to Improve System Security in Preventing Cyber Attacks using COBIT 2019
DOI:
https://doi.org/10.70609/gtech.v9i1.6319Keywords:
COBIT 2019, Cyber Attack, Cyber Security, IT Audit, IT GovernanceAbstract
Cyber-attacks have become a serious concern in recent years, as hackers can attack systems, databases, and even steal personal data from a particular organization's database and sell it on the dark web. The individual identity data will be used to carry out various financially profitable activities such as online fraud, selling data containing detailed account information, and asking for ransom from data owners. The failure of an organization to protect data assets from cyber-attacks stems from several internal factors such as the vulnerability of the information security system it has, the less than optimal awareness of users in the organization of the importance of maintaining safe behavior in cyberspace, and routine processes related to information security that are missed. COBIT 2019 can be used as an audit framework to assess the level of maturity of the governance. Network infrastructure services in an organization can be measured in terms of the level of capability in terms of the application of technology assets and their configuration using the DSS05 and APO13 domains. This study aims to provide guidelines in assessing system security infrastructure in IT governance by assessing areas that are still not comply with the framework used, and providing recommendations for improving these inconsistencies so that the level of infrastructure capability will be maximized then.
References
Adrian, F. X., & Wang, G. (2023). Measure the Level Capability IT Governance in Effectiveness Internal Control for Cybersecurity Using the COBIT 2019 in Organization: Banking Company. Journal of Theoretical and Applied Information Technology, 15(5). www.jatit.org
Angelina, A., & Fianty, M. (2023). Capability Level Assessments of Information Security Controls: An Empirical Analysis of Practitioners Assessment Capabilities. G-Tech: Jurnal Teknologi Terapan, 8(1), 91–103. https://doi.org/10.33379/gtech.v8i1.3509
Aslan, Ö., Aktuğ, S. S., Ozkan-Okay, M., Yilmaz, A. A., & Akin, E. (2023). A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions. In Electronics (Switzerland) (Vol. 12, Issue 6). MDPI. https://doi.org/10.3390/electronics12061333
BSSN. (2023). Landskap Keamanan Siber Indonesia 2022.
BSSN. (2024). Landskap Keamanan Siber Indonesia 2023.
Christiadi, R. N., & Sutomo, R. (2023). Measurement of IT Security Governance Capabilities Using COBIT 2019 at Indonesian Business Sector. G-Tech: Jurnal Teknologi Terapan, 7(4), 1498–1508. https://doi.org/10.33379/gtech.v7i4.3170
Darmi, Y., Fernandez, S., Fathoni, M. Y., & Wijayanto, S. (2024). Evaluation of Governance in Information Systems Security to Minimize Information Technology Risks. INTENSIF: Jurnal Ilmiah Penelitian Dan Penerapan Teknologi Sistem Informasi, 8(1), 40–51. https://doi.org/10.29407/intensif.v8i1.21221
Hadi, D., Jentama, G., Adisty, M., & Sutabri, T. (2023). Transformasi Teknologi Digital dalam Keamanan dan Privasi pada Institusi BUMN. Kohesi: Jurnal Multidisiplin Saintek, 01, 97–104.
I Nyoman Rai Widartha Kesuma, Irman Hermadi, Y. N. (2023). Evaluasi Tata Kelola Teknologi Informasi di Dinas Pertanian Gianyar Menggunakan COBIT 2019. Jurnal Teknologi Informasi Dan Ilmu Komputer (JTIIK), 10, 513–522.
ISACA. (2019a). COBIT 2019 Design guide designing an information and technology governance solution. ISACA.
ISACA. (2019b). COBIT 2019 Framework Governance and Management Objectives.
Katili, M. R., Amali, L. N., & Suhada, S. (2023). Design Factors in Evaluating and Formulating IT Governance Systems in Public Organizations. Jurnal RESTI (Rekayasa Sistem Dan Teknologi Informasi), 7(5), 1182–1191. https://doi.org/10.29207/resti.v7i5.4939
Melaku, H. M. (2023). A Dynamic and Adaptive Cybersecurity Governance Framework. Journal of Cybersecurity and Privacy, 3(3), 327–350. https://doi.org/10.3390/jcp3030017
Modisane, P. (2023). Assessing Information Security Maturity Levels in ISP Organizations Using COBIT 2019. ResearchGate. https://www.researchgate.net/publication/373295617
Mubarak, R. F., & Fianty, M. I. (2023). Leveraging COBIT 2019 to Implement IT Governance in Mineral Mining Company. Journal of Information Systems and Informatics, 5(3), 1058–1071. https://doi.org/10.51519/journalisi.v5i3.545
Nugroho, A., & Ginardi, H. (2024). Information Technology Governance Analysis to Reduce Information Security Risks Using Cobit 2019: A Case Study of Manufacturing Companies. Jurnal Indonesia Sosial Teknologi, 5(8), 3722. http://jist.publikasiindonesia.id/
Oluwasanmi Richard Arogundade. (2023). Network Security Concepts, Dangers, and Defense Best Practical. Computer Engineering and Intelligent Systems. https://doi.org/10.7176/ceis/14-2-03
Schmitz, C., Schmid, M., Harborth, D., & Pape, S. (2021). Maturity level assessments of information security controls: An empirical analysis of practitioners assessment capabilities. Computers and Security, 108. https://doi.org/10.1016/j.cose.2021.102306
Shaikh, F. A., & Siponen, M. (2023). Information security risk assessments following cybersecurity breaches: The mediating role of top management attention to cybersecurity. Computers and Security, 124. https://doi.org/10.1016/j.cose.2022.102974
Tulus, B. V., & Tanaamah, A. R. (2023). Design of Information Technology Governance in Educational Institutions Using COBIT 2019 Framework. Journal of Information Systems and Informatics, 5(1), 31–43. https://doi.org/10.51519/journalisi.v5i1.408
Ulrich, P. S., & Stockert, F. (2023). IT Governance and IT Compliance in Family Firms - the Special Case of Cyber Security. Procedia Computer Science, 225, 2781–2789. https://doi.org/10.1016/j.procs.2023.10.270
Viamianni, A., Mulyana, R., & Dewi, F. (2023). COBIT 2019 Information Security Focus Area Implementation for Reinsurco Digital Transformation. JIKO (Jurnal Informatika Dan Komputer), 6(2). https://doi.org/10.33387/jiko.v6i2.6366
Yeoh, W., Liu, M., Shore, M., & Jiang, F. (2023). Zero trust cybersecurity: Critical success factors and A maturity assessment framework. Computers and Security, 133. https://doi.org/10.1016/j.cose.2023.103412
Downloads
Published
Issue
Section
License
Copyright (c) 2025 Salim Salim, Alva Hendi Muhammad

This work is licensed under a Creative Commons Attribution 4.0 International License.









