Information Security Governance Model for Higher Education Based on ISO/IEC 27001:2022 and COBIT 2019
DOI:
https://doi.org/10.59395/ijadis.v7i2.1538Keywords:
COBIT 2019, Higher Education, Information Security, IT Governance, ISO/IEC 27001:2022Abstract
Higher education institutions manage large volumes of sensitive information, including personal data of students and staff, research data, financial records, and operational information. The increasing number of cyber incidents affecting universities, both globally and in Indonesia, indicated the need for a more structured approach to information security governance. This study aimed to develop an information security governance design model through the integration of ISO/IEC 27001:2022 and COBIT 2019. The research adopted a design science research methodology. The proposed model integrated ISO/IEC 27001:2022 information security controls with COBIT 2019 governance and management objectives and determined the expected capability level using COBIT design factors. The model was demonstrated through a case study at an Indonesian higher education institution, where the current capability levels were assessed using the Not, Partially, Largely, and Fully achieved rating scale. The results showed that all eight evaluated objectives were at Capability Level 2, with scores ranging from 37.40% to 62.56%, indicating that governance processes had been implemented but were not yest consistently documented and managed. The evaluation demonstrated that the proposed model can serve as a practical reference for assessing and improving information security governance in higher education institutions.
Downloads
References
[1] Higher Education Has A Lot To Learn About Data Breaches. Accessed: Dec. 01, 2025. [Online]. Available: https://www.forbes.com/sites/steveweisman/2025/08/23/higher-education-has-a-lot-to-learn-about-data-breaches/
[2] J. Li, W. Xiao, and C. Zhang, Data security crisis in universities: identification of key factors affecting data breach incidents, Humanit. Soc. Sci. Commun., vol. 10, no. 1, p. 270, Dec. 2023, doi: 10.1057/S41599-023-01757-0. DOI: https://doi.org/10.1057/s41599-023-01757-0
[3] BUKU STATISTIK PENDIDIKAN TINGGI 2024 - PUSDATIN KEMDIKTISAINTEK.pdf - Google Drive. Accessed: Nov. 09, 2025. [Online]. Available: https://drive.google.com/file/d/1RcIDvDRs1VNcNAvPCOHeBxBzY3NgXizN/view
[4] D. L. Putri and I. E. Pratiwi, Ramai soal Data Universitas Indonesia Dilaporkan Bocor, Ini Kata Kampus, Kumparan.com. Accessed: Mar. 18, 2025. [Online]. Available: https://www.kompas.com/tren/read/2024/07/19/163000865/ramai-soal-data-universitas-indonesia-dilaporkan-bocor-ini-kata-kampus
[5] D. Setya, Data Mahasiswa UPI Diduga Bocor, Apa Langkah Pihak Kampus?, detikEdu. Accessed: Mar. 18, 2025. [Online]. Available: https://www.detik.com/edu/perguruan-tinggi/d-6247009/data-mahasiswa-upi-diduga-bocor-apa-langkah-pihak-kampus
[6] A. Evandio, Data 125.000 Mahasiswa Undip Bocor! Begini Seharusnya, Bisnis.com. Accessed: Mar. 18, 2025. [Online]. Available: https://teknologi.bisnis.com/read/20210106/84/1339353/data-125000-mahasiswa-undip-bocor-begini-seharusnya
[7] L. Sikman, T. Latinovic, N. Sarajlic, and G. Sikanjic, A model of sustainable information security management system in higher education institutions, J. Phys. Conf. Ser., vol. 2540, no. 1, 2023, doi: 10.1088/1742-6596/2540/1/012003. DOI: https://doi.org/10.1088/1742-6596/2540/1/012003
[8] P. P. Roy, A High-Level Comparison between the NIST Cyber Security Framework and the ISO 27001 Information Security Standard, 2020 National Conference on Emerging Trends on Sustainable Technology and Engineering Applications, NCETSTEA 2020, Feb. 2020, doi: 10.1109/NCETSTEA48365.2020.9119914. DOI: https://doi.org/10.1109/NCETSTEA48365.2020.9119914
[9] M. B. Pohlman, Compliance Frameworks, Oracle Identity Management, pp. 5570, Dec. 2020, doi: 10.1201/9781420072488-9/COMPLIANCE-FRAMEWORKS-MARLIN-POHLMAN.
[10] A. Alexei, CYBER SECURITY STRATEGIES FOR HIGHER EDUCATION INSTITUTIONS , Journal of Engineering Science, vol. XXVIII, no. 4, pp. 7492, 2021, doi: 10.52326/jes.utm.2021.28(4).07. DOI: https://doi.org/10.52326/jes.utm.2021.28(4).07
[11] N. Mohd Nordin, A. Mat Isa, A. Z. H. Samsudin, and A. R. Ahmad, Information Governance for Enhancing the Performance of Higher Education Institutions, Environment-Behaviour Proceedings Journal, vol. 7, no. SI10, pp. 135139, Nov. 2022, doi: 10.21834/EBPJ.V7ISI10.4115. DOI: https://doi.org/10.21834/ebpj.v7iSI10.4115
[12] C. W. Liu, P. Huang, and H. C. Lucas, Centralized IT Decision Making and Cybersecurity Breaches: Evidence from U.S. Higher Education Institutions, Journal of Management Information Systems, vol. 37, no. 3, pp. 758787, Jul. 2020, doi: 10.1080/07421222.2020.1790190. DOI: https://doi.org/10.1080/07421222.2020.1790190
[13] Do. Dr. A. EFE, A Comparison of Key Risk Management Frameworks: COSO-ERM, NIST RMF, ISO 31.000, COBIT, Denetim ve Gvence Hizmetleri Dergisi, Jan. 2023, Accessed: Mar. 18, 2025. [Online]. Available: https://www.academia.edu/105144901/A_Comparison_of_Key_Risk_Management_Frameworks_COSO_ERM_NIST_RMF_ISO_31_000_COBIT
[14] T. R. McIntosh et al., From COBIT to ISO 42001: Evaluating cybersecurity frameworks for opportunities, risks, and regulatory compliance in commercializing large language models, Comput. Secur., vol. 144, p. 103964, Sep. 2024, doi: 10.1016/J.COSE.2024.103964. DOI: https://doi.org/10.1016/j.cose.2024.103964
[15] H. Setiawan, N. A. Hana, and R. R. Hanaputra, Mapping ISO 27001:2013 and COBIT 2019 Framework to STRIDE Threat Modeling Using Qualitative Descriptive Research, Journal of Computer Engineering, Electronics and Information Technology, vol. 3, no. 2, pp. 101110, Nov. 2024, doi: 10.17509/COELITE.V3I2.73228.
[16] S. U. Adamu, M. A. Ahmad, and M. Ibrahim, A systematic literature review on the adoption and effectiveness of cybersecurity frameworks in higher education institutions, Information and Computer Security, pp. 116, 2025, doi: 10.1108/ICS-10-2025-0403/1339707. DOI: https://doi.org/10.1108/ICS-10-2025-0403
[17] N. K. Gunawan, R. B. Hadiprakoso, and H. Kabetta, Comparative study between the integration of ITIL and ISO / IEC 27001 with the integration of COBIT and ISO / IEC 27001, IOP Conf. Ser. Mater. Sci. Eng., vol. 852, no. 1, Jul. 2020, doi: 10.1088/1757-899X/852/1/012128. DOI: https://doi.org/10.1088/1757-899X/852/1/012128
[18] E. Aflakhah and B. Soewito, Assessing Information Security using COBIT 2019 and ISO 27001:2013 for Developing a Mitigation Plan, International Journal of Engineering Trends and Technology, vol. 71, no. 10, pp. 223237, 2023, doi: 10.14445/22315381/IJETT-V71I10P221. DOI: https://doi.org/10.14445/22315381/IJETT-V71I10P221
[19] M. Yasin, A. Akhmad Arman, I. J. M. Edward, and W. Shalannanda, Designing information security governance recommendations and roadmap using COBIT 2019 Framework and ISO 27001:2013 (Case Study Ditreskrimsus Polda XYZ), Proceeding of 14th International Conference on Telecommunication Systems, Services, and Applications, TSSA 2020, Nov. 2020, doi: 10.1109/TSSA51342.2020.9310875. DOI: https://doi.org/10.1109/TSSA51342.2020.9310875
[20] M. Gandhi, A. Gaur, A. Kumar Kar, and Y. K. Dwivedi, Crafting user experiences in the metaverse: A design science study, 2024, doi: 10.1016/j.techfore.2024.123759. DOI: https://doi.org/10.1016/j.techfore.2024.123759
[21] K. Peffers, T. Tuunanen, M. A. Rothenberger, and S. Chatterjee, A Design Science Research Methodology for Information Systems Research, Journal of Management Information Systems, vol. 24, no. 3, pp. 4577, Dec. 2007, doi: 10.2753/MIS0742-1222240302. DOI: https://doi.org/10.2753/MIS0742-1222240302
[22] S. Nasional Indonesia, SNI ISO/IEC 27001:2022 (Ditetapkan oleh BSN tahun 2023), 2023. [Online]. Available: www.bsn.go.id
[23] P. Nurmi, Enhancing ISO 27001:2022 Implementation Through Project Management, 2024.
[24] N. Andriani, R. Mulyana, and Rd. R. Saedudin, Ambidextrous Cloud Governance Approach to Enhance TelCos Digital Transformation Using COBIT 2019 Traditional and DevOps, International Journal of Advances in Data and Information Systems, vol. 6, no. 2, pp. 357~375-357~375, Jul. 2025, doi: 10.59395/ijadis.v6i2.1398.
[25] ISACA, COBIT 2019 Framework Governance and Management Objectives.
[26] C. C. Anoruo, The Governance Game of Chess: Mapping ISO/IEC 27001:2022 to COBIT , ISACA Journal, vol. 2, Apr. 2025, [Online]. Available: www.isaca.org
[27] S. De Haes, W. Van Grembergen, A. Joshi, and T. Huygh, Enterprise Governance of Information Technology, in Management for Professionals (MANAGPROF), in Management for Professionals. , Cham: Springer International Publishing, 2020. doi: 10.1007/978-3-030-25918-1. DOI: https://doi.org/10.1007/978-3-030-25918-1
[28] N. M. Parera and J. J. C. Tambotoh, Measuring IT Governance Capability at DISKOMINFO Salatiga using COBIT 2019, Sistemasi: Jurnal Sistem Informasi, vol. 13, no. 1, pp. 324334, Jan. 2024, doi: 10.32520/stmsi.v13i1.3669. DOI: https://doi.org/10.32520/stmsi.v13i1.3669
[29] L. Gorgona, Building a Maturity Model for COBIT 2019 Based on CMMI, 2021. [Online]. Available: https://www.isaca.org/resources/cobit
[30] P. Widharto, Z. Suhatman, and R. F. Aji, Measurement of information technology governance capability level: a case study of PT Bank BBS, Telkomnika (Telecommunication Computing Electronics and Control), vol. 20, no. 2, pp. 296306, 2022, doi: 10.12928/TELKOMNIKA.v20i2.21668. DOI: https://doi.org/10.12928/telkomnika.v20i2.21668
[31] ISACA, COBIT 2019 Framework: introduction and methodology.
[32] F. N. Sormin, Analisis Tingkat Kemampuan (Capability Level) Teknologi Informasi Pada Pt.Pos (Persero) Indonesia Cabang Perdagangan Menggunakan Framework Cobit 5 Domain Apo (Align, Plan, And Organise), SISFO: Jurnal Ilmiah Sistem Informasi, vol. 7, no. 1, 2023. DOI: https://doi.org/10.29103/sisfo.v7i1.12127
[33] ISACA, COBIT 2019 Design guide designing an information and technology governance solution.
[34] A. Safitri, I. Syafii, and K. Adi, Identifikasi Level Pengelolaan Tata Kelola SIPERUMKIM Kota Salatiga berdasarkan COBIT 2019, Jurnal RESTI, vol. 5, no. 3, pp. 429438, Jun. 2021, doi: 10.29207/RESTI.V5I3.3060. DOI: https://doi.org/10.29207/resti.v5i3.3060
[35] Rahmat Rian Hidayat and D. Jatikusumo, IMPLEMENTATION OF COBIT 2019 TO MEASURE IT MATURITY LEVELS IN DIGITAL BANKS, Jurnal Teknik Informatika (Jutif), vol. 5, no. 4, pp. 497504, Aug. 2024, doi: 10.52436/1.jutif.2024.5.4.2135. DOI: https://doi.org/10.52436/1.jutif.2024.5.4.2135
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Neonatal March Parera, Wiwin Sulistyo, Johan Jimmy Carter Tambotoh

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
How to Cite
Share
Plum Analytics