Pamungkas, Aditya Aji (2026) Evaluasi Kematangan Keamanan Sistem Informasi Berbasis COBIT 2019 (DSS05) Dan SSE-CMM (Studi Kasus DPTSI - Institut Teknologi Sepuluh Nopember). Other thesis, Institut Teknologi Sepuluh Nopember.
|
Text
5026221061-Undergraduate_Thesis.pdf - Accepted Version Restricted to Repository staff only Download (3MB) | Request a copy |
Abstract
Transformasi digital di lingkungan perguruan tinggi telah meningkatkan ketergantungan institusi terhadap sistem informasi dalam mendukung layanan akademik dan administratif. Kondisi tersebut menjadikan keamanan sistem informasi sebagai aspek strategis dalam menjaga keberlangsungan layanan, perlindungan data, serta stabilitas operasional institusi. Direktorat Pengembangan Teknologi dan Sistem Informasi (DPTSI) Institut Teknologi Sepuluh Nopember (ITS) sebagai unit pengelola layanan teknologi informasi menghadapi berbagai tantangan keamanan, baik dari sisi tata kelola maupun implementasi teknis pengamanan sistem. Oleh karena itu, diperlukan pendekatan evaluasi untuk menilai tingkat kematangan keamanan sistem informasi secara komprehensif dan kontekstual. Penelitian ini bertujuan untuk mengevaluasi tingkat kematangan keamanan sistem informasi pada DPTSI ITS dengan mengintegrasikan COBIT 2019 domain DSS05 (Managed Security Services) dan Systems Security Engineering Capability Maturity Model (SSE-CMM) ISO/IEC 21827:2008. COBIT 2019 DSS05 digunakan untuk mengevaluasi pengelolaan layanan keamanan dari perspektif tata kelola dan operasional, sedangkan SSE-CMM digunakan untuk menilai kapabilitas proses rekayasa keamanan dari sisi teknis. Penelitian diawali dengan governance system design menggunakan COBIT 2019 Design Factors Toolkit yang mencakup Enterprise Strategy, Enterprise Goals, Risk Profile, IT-Related Issues, Role of IT, Sourcing Model, IT Implementation Method, dan Technology Adoption Strategy. Hasil design factor menunjukkan bahwa DPTSI ITS memiliki tingkat ketergantungan tinggi terhadap layanan teknologi informasi sehingga domain DSS05 memperoleh agreed target capability level pada level 4. Metodologi penelitian dilakukan melalui wawancara, observasi, studi dokumentasi, perancangan assessment sheet terintegrasi DSS05 dan SSE-CMM, analisis capability level, gap analysis, serta penyusunan rekomendasi strategis dan roadmap peningkatan keamanan sistem informasi. Hasil penelitian menunjukkan bahwa domain DSS05 memperoleh capaian Fully Achieved pada Level 1 dan Level 2 sebesar 100%, serta nilai 89% pada Level 3 dengan kategori Fully Achieved. Namun, pada Level 4 diperoleh nilai sebesar 80% dengan kategori Largely Achieved sehingga tingkat kapabilitas keamanan sistem informasi DPTSI ITS berada pada Capability Level 3 (Defined Process). Hasil tersebut menunjukkan bahwa proses keamanan informasi telah terdefinisi dan diterapkan secara cukup konsisten, namun belum sepenuhnya didukung oleh monitoring, pengukuran kinerja, evaluasi berkelanjutan, serta integrasi kontrol keamanan secara menyeluruh. Berdasarkan hasil evaluasi tersebut, penelitian menghasilkan rekomendasi strategis yang berfokus pada penguatan tata kelola keamanan, implementasi Identity and Access Management (IAM), secure configuration baseline, incident response, monitoring keamanan terintegrasi, serta roadmap peningkatan keamanan sistem informasi secara bertahap.
======================================================================================================================================
Digital transformation in higher education institutions has increased institutional dependence on information systems to support academic and administrative services. This condition has made information system security a strategic aspect in maintaining service continuity, data protection, and institutional operational stability. The Directorate of Information Technology and Systems Development (DPTSI) at Institut Teknologi Sepuluh Nopember (ITS), as the unit responsible for managing information technology services, faces various security challenges from both governance and technical security implementation perspectives. Therefore, an evaluation approach is required to comprehensively and contextually assess the maturity level of information system security. This study aims to evaluate the maturity level of information system security at DPTSI ITS by integrating the COBIT 2019 DSS05 (Managed Security Services) domain and the Systems Security Engineering Capability Maturity Model (SSE-CMM) ISO/IEC 21827:2008. COBIT 2019 DSS05 was used to evaluate security service management from governance and operational perspectives, while SSE-CMM was utilized to assess the capability of security engineering processes from a technical perspective. The study began with a governance system design process using the COBIT 2019 Design Factors Toolkit, which includes Enterprise Strategy, Enterprise Goals, Risk Profile, IT Related Issues, Role of IT, Sourcing Model, IT Implementation Method, and Technology Adoption Strategy. The design factor results indicated that DPTSI ITS has a high dependency on information technology services, resulting in the DSS05 domain obtaining an agreed target capability level of Level 4. The research methodology involved interviews, observations, documentation studies, the development of an integrated DSS05 and SSE-CMM assessment sheet, capability level analysis, gap analysis, as well as the formulation of strategic recommendations and an information system security improvement roadmap. The results showed that the DSS05 domain achieved Fully Achieved status at Level 1 and Level 2 with a score of 100%, and a score of 89% at Level 3 categorized as Fully Achieved. However, at Level 4, the domain obtained a score of 80% categorized as Largely Achieved, indicating that the information system security capability level at DPTSI ITS is currently at Capability Level 3 (Defined Process). These results indicate that information security processes have been defined and implemented relatively consistently, although they are not yet fully supported by monitoring, performance measurement, continuous evaluation, and comprehensive integration of security controls. Based on these findings, this study proposes strategic recommendations focusing on strengthening security governance, implementing Identity and Access Management (IAM), secure configuration baselines, incident response mechanisms, integrated security monitoring, and a phased information system security improvement roadmap.
| Item Type: | Thesis (Other) |
|---|---|
| Uncontrolled Keywords: | Information System Security, COBIT 2019, DSS05, SSE-CMM, Capability Level, Security Governance, DPTSI ITS. |
| Subjects: | T Technology > T Technology (General) > T58.5 Information technology. IT--Auditing |
| Divisions: | Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Information System > 57201-(S1) Undergraduate Thesis |
| Depositing User: | Aditya Aji Pamungkas |
| Date Deposited: | 28 Jul 2026 01:00 |
| Last Modified: | 28 Jul 2026 01:00 |
| URI: | http://repository.its.ac.id/id/eprint/138241 |
Actions (login required)
![]() |
View Item |
