Security Infrastructure Service and Information Security Management Capability Audit to Improve System Security in Preventing Cyber Attacks using COBIT 2019

Authors

  • Salim Salim Universitas Amikom Yogyakarta, Indonesia
  • Alva Hendi Muhammad Universitas Amikom Yogyakarta, Indonesia

DOI:

https://doi.org/10.70609/gtech.v9i1.6319

Keywords:

COBIT 2019, Cyber Attack, Cyber Security, IT Audit, IT Governance

Abstract

Cyber-attacks have become a serious concern in recent years, as hackers can attack systems, databases, and even steal personal data from a particular organization's database and sell it on the dark web. The individual identity data will be used to carry out various financially profitable activities such as online fraud, selling data containing detailed account information, and asking for ransom from data owners. The failure of an organization to protect data assets from cyber-attacks stems from several internal factors such as the vulnerability of the information security system it has, the less than optimal awareness of users in the organization of the importance of maintaining safe behavior in cyberspace, and routine processes related to information security that are missed. COBIT 2019 can be used as an audit framework to assess the level of maturity of the governance. Network infrastructure services in an organization can be measured in terms of the level of capability in terms of the application of technology assets and their configuration using the DSS05 and APO13 domains. This study aims to provide guidelines in assessing system security infrastructure in IT governance by assessing areas that are still not comply with the framework used, and providing recommendations for improving these inconsistencies so that the level of infrastructure capability will be maximized then.

References

Adrian, F. X., & Wang, G. (2023). Measure the Level Capability IT Governance in Effectiveness Internal Control for Cybersecurity Using the COBIT 2019 in Organization: Banking Company. Journal of Theoretical and Applied Information Technology, 15(5). www.jatit.org

Angelina, A., & Fianty, M. (2023). Capability Level Assessments of Information Security Controls: An Empirical Analysis of Practitioners Assessment Capabilities. G-Tech: Jurnal Teknologi Terapan, 8(1), 91–103. https://doi.org/10.33379/gtech.v8i1.3509

Aslan, Ö., Aktuğ, S. S., Ozkan-Okay, M., Yilmaz, A. A., & Akin, E. (2023). A Comprehensive Review of Cyber Security Vulnerabilities, Threats, Attacks, and Solutions. In Electronics (Switzerland) (Vol. 12, Issue 6). MDPI. https://doi.org/10.3390/electronics12061333

BSSN. (2023). Landskap Keamanan Siber Indonesia 2022.

BSSN. (2024). Landskap Keamanan Siber Indonesia 2023.

Christiadi, R. N., & Sutomo, R. (2023). Measurement of IT Security Governance Capabilities Using COBIT 2019 at Indonesian Business Sector. G-Tech: Jurnal Teknologi Terapan, 7(4), 1498–1508. https://doi.org/10.33379/gtech.v7i4.3170

Darmi, Y., Fernandez, S., Fathoni, M. Y., & Wijayanto, S. (2024). Evaluation of Governance in Information Systems Security to Minimize Information Technology Risks. INTENSIF: Jurnal Ilmiah Penelitian Dan Penerapan Teknologi Sistem Informasi, 8(1), 40–51. https://doi.org/10.29407/intensif.v8i1.21221

Hadi, D., Jentama, G., Adisty, M., & Sutabri, T. (2023). Transformasi Teknologi Digital dalam Keamanan dan Privasi pada Institusi BUMN. Kohesi: Jurnal Multidisiplin Saintek, 01, 97–104.

I Nyoman Rai Widartha Kesuma, Irman Hermadi, Y. N. (2023). Evaluasi Tata Kelola Teknologi Informasi di Dinas Pertanian Gianyar Menggunakan COBIT 2019. Jurnal Teknologi Informasi Dan Ilmu Komputer (JTIIK), 10, 513–522.

ISACA. (2019a). COBIT 2019 Design guide designing an information and technology governance solution. ISACA.

ISACA. (2019b). COBIT 2019 Framework Governance and Management Objectives.

Katili, M. R., Amali, L. N., & Suhada, S. (2023). Design Factors in Evaluating and Formulating IT Governance Systems in Public Organizations. Jurnal RESTI (Rekayasa Sistem Dan Teknologi Informasi), 7(5), 1182–1191. https://doi.org/10.29207/resti.v7i5.4939

Melaku, H. M. (2023). A Dynamic and Adaptive Cybersecurity Governance Framework. Journal of Cybersecurity and Privacy, 3(3), 327–350. https://doi.org/10.3390/jcp3030017

Modisane, P. (2023). Assessing Information Security Maturity Levels in ISP Organizations Using COBIT 2019. ResearchGate. https://www.researchgate.net/publication/373295617

Mubarak, R. F., & Fianty, M. I. (2023). Leveraging COBIT 2019 to Implement IT Governance in Mineral Mining Company. Journal of Information Systems and Informatics, 5(3), 1058–1071. https://doi.org/10.51519/journalisi.v5i3.545

Nugroho, A., & Ginardi, H. (2024). Information Technology Governance Analysis to Reduce Information Security Risks Using Cobit 2019: A Case Study of Manufacturing Companies. Jurnal Indonesia Sosial Teknologi, 5(8), 3722. http://jist.publikasiindonesia.id/

Oluwasanmi Richard Arogundade. (2023). Network Security Concepts, Dangers, and Defense Best Practical. Computer Engineering and Intelligent Systems. https://doi.org/10.7176/ceis/14-2-03

Schmitz, C., Schmid, M., Harborth, D., & Pape, S. (2021). Maturity level assessments of information security controls: An empirical analysis of practitioners assessment capabilities. Computers and Security, 108. https://doi.org/10.1016/j.cose.2021.102306

Shaikh, F. A., & Siponen, M. (2023). Information security risk assessments following cybersecurity breaches: The mediating role of top management attention to cybersecurity. Computers and Security, 124. https://doi.org/10.1016/j.cose.2022.102974

Tulus, B. V., & Tanaamah, A. R. (2023). Design of Information Technology Governance in Educational Institutions Using COBIT 2019 Framework. Journal of Information Systems and Informatics, 5(1), 31–43. https://doi.org/10.51519/journalisi.v5i1.408

Ulrich, P. S., & Stockert, F. (2023). IT Governance and IT Compliance in Family Firms - the Special Case of Cyber Security. Procedia Computer Science, 225, 2781–2789. https://doi.org/10.1016/j.procs.2023.10.270

Viamianni, A., Mulyana, R., & Dewi, F. (2023). COBIT 2019 Information Security Focus Area Implementation for Reinsurco Digital Transformation. JIKO (Jurnal Informatika Dan Komputer), 6(2). https://doi.org/10.33387/jiko.v6i2.6366

Yeoh, W., Liu, M., Shore, M., & Jiang, F. (2023). Zero trust cybersecurity: Critical success factors and A maturity assessment framework. Computers and Security, 133. https://doi.org/10.1016/j.cose.2023.103412

Downloads

Published

2025-01-16

How to Cite

Security Infrastructure Service and Information Security Management Capability Audit to Improve System Security in Preventing Cyber Attacks using COBIT 2019. (2025). G-Tech: Jurnal Teknologi Terapan, 9(1), 400-409. https://doi.org/10.70609/gtech.v9i1.6319

Most read articles by the same author(s)