Pengembangan Perangkat Kesadaran Keamanan Informasi Human Aspect Of Information Security Questionnaire (HAIS-Q) Dengan Menggunakan ISO/IEC 27001:2022 Dan NIST SP 800-53 Revision 5

Nuriyanti, Widyantari (2026) Pengembangan Perangkat Kesadaran Keamanan Informasi Human Aspect Of Information Security Questionnaire (HAIS-Q) Dengan Menggunakan ISO/IEC 27001:2022 Dan NIST SP 800-53 Revision 5. Other thesis, Institut Teknologi Sepuluh Nopember.

[thumbnail of 5026221137-Undergraduate_Thesis.pdf] Text
5026221137-Undergraduate_Thesis.pdf - Accepted Version
Restricted to Repository staff only

Download (6MB) | Request a copy

Abstract

Perkembangan teknologi informasi yang pesat membawa peningkatan ancaman keamanan siber. Kesadaran keamanan informasi (information security awareness/ISA) menjadi aspek fundamental yang perlu diukur secara sistematis, dan Human Aspects of Information Security Questionnaire (HAIS-Q) merupakan salah satu instrumen yang paling banyak digunakan untuk keperluan tersebut. Namun, satu dekade sejak dikembangkan, HAIS-Q belum sepenuhnya mengakomodasi kompleksitas ancaman keamanan informasi masa kini. Penelitian ini bertujuan mengembangkan perangkat penilaian kesadaran keamanan informasi HAIS-Q dengan mengintegrasikan kontrol dari ISO/IEC 27001:2022 dan NIST SP 800-53 Revisi 5 agar lebih relevan dengan kondisi terkini. Penelitian menggunakan pendekatan mixed method melalui tahapan identifikasi dan pemetaan kontrol, penyusunan item pertanyaan berdasarkan dimensi Knowledge, Attitude, dan Behavior (KAB), validasi oleh expert judgement melalui content validity dan face validity, serta pengujian empiris menggunakan Confirmatory Factor Analysis (CFA) dan uji reliabilitas. Penelitian ini menghasilkan 13 Sub-area yang telah melewati proses validasi, dengan nilai Cohen's Kappa sebesar 0,8276 yang menunjukkan reliabilitas kuat. Perangkat akhir memperluas HAIS-Q dari 7 menjadi 9 Fokus Area, dengan tambahan dua Fokus Area baru yaitu Keamanan Fisik (PS) dan Pengetahuan Keamanan Informasi (SL). Nilai Cronbach's Alpha berkisar antara 0,682–0,934 dan Composite Reliability antara 0,728–0,928, menunjukkan bahwa perangkat memiliki konsistensi internal yang memadai. Hal ini menunjukkan bahwa perangkat pengukuran HAIS-Q versi terbaru lebih komprehensif untuk menilai kesadaran keamanan informasi pada tingkat individu.
=====================================================================================================================================
The rapid development of information technology has brought about an increase in cybersecurity threats. Information security awareness (ISA) has become a fundamental aspect that needs to be measured systematically, and the Human Aspects of Information Security Questionnaire (HAIS-Q) is one of the most widely used instruments for this purpose. However, a decade after its development, HAIS-Q has not fully accommodated the complexity of today's information security threats. This research aims to develop an information security awareness assessment tool based on HAIS-Q by integrating controls from ISO/IEC 27001:2022 and NIST SP 800-53 Revision 5 to make it more relevant to current conditions. The research employs a mixed-method approach through several stages: identification and mapping of controls, formulation of questionnaire items based on the Knowledge, Attitude, and Behavior (KAB) dimensions, validation by expert judgement through content validity and face validity, as well as empirical testing using Confirmatory Factor Analysis (CFA) and reliability testing. This research produced 13 Sub-areas that have passed the validation process, with a Cohen's Kappa value of 0.8276, indicating strong reliability. The final instrument expands HAIS-Q from 7 to 9 Focus Areas, with two new Focus Areas added: Physical Security (PS) and Security Learning (SL). The Cronbach's Alpha values range from 0.682 to 0.934, and the Composite Reliability values range from 0.728 to 0.928, indicating that the instrument has adequate internal consistency. This demonstrates that the updated version of the HAIS-Q measurement tool is more comprehensive for assessing information security awareness at the individual level.

Item Type: Thesis (Other)
Uncontrolled Keywords: CFA, HAIS-Q, ISO/IEC 27001:2022, keamanan informasi, kesadaran keamanan informasi. CFA, HAIS-Q, ISO/IEC 27001:2022, information security, information security awareness.
Subjects: T Technology > T Technology (General)
T Technology > T Technology (General) > T58.5 Information technology. IT--Auditing
Divisions: Faculty of Intelligent Electrical and Informatics Technology (ELECTICS) > Information System > 57201-(S1) Undergraduate Thesis
Depositing User: Widyantari Nuriyanti
Date Deposited: 30 Jul 2026 06:47
Last Modified: 30 Jul 2026 06:47
URI: http://repository.its.ac.id/id/eprint/140195

Actions (login required)

View Item View Item