Designing Information Security Governance Recommendations and Roadmap Using COBIT 2019 Framework and ISO 27001:2013 (Case Study Ditreskrimsus Polda XYZ) | IEEE Conference Publication | IEEE Xplore

Designing Information Security Governance Recommendations and Roadmap Using COBIT 2019 Framework and ISO 27001:2013 (Case Study Ditreskrimsus Polda XYZ)


Abstract:

The use of technology has applied in all areas of Polri's duties. However, the use of this technology does not yet have a level of capability in information security mana...Show More

Abstract:

The use of technology has applied in all areas of Polri's duties. However, the use of this technology does not yet have a level of capability in information security management. For this reason, it is necessary to design recommendations and an ideal information governance roadmap based on COBIT 2019 and ISO/IEC 27001: 2013 concerning Information Security Management Systems (ISMS). The design is carried out based on six stages in the Design Science Research Methodology (DSRM) in the form of identify problems and motivate, define objects of a solution, design and development, demonstration, evaluation, and communication. By mapping ISO/IEC 27001: 2013 into COBIT 2019, 29 domains of the 2019 COBIT core model selected which became the basis for designing and assessing the level of information security management capability at Ditreskrimsus Polda XYZ. The formulation of recommendations considered the assessment results. It produced the model of organizational structure, human resources, and policies and procedures that must be applied to Ditreskrimsus Polda XYZ in the form of a roadmap starting in 2021-2025 in managing information security. This research contributes to producing an information security governance design.
Date of Conference: 04-05 November 2020
Date Added to IEEE Xplore: 07 January 2021
ISBN Information:
Conference Location: Bandung, Indonesia
References is not available for this document.

I. Introduction

The utilization of information technology has a pivotal role in supporting the Indonesian National Police in performing its duties. Presidential Instruction No. 3 of 2003 concerning national policies and strategies of the development of e-government claims that the utilization of communication and information technology in the governance process will increase efficiency, effectivity, transparency, and government administration accountability. Besides, President Regulation No. 95 of 2018 concerning the electronic-based government system (SPBE) also regulates information technology utilization to create an open, participative, innovative, and accountable government. It will improve the quality and the reach of public service to the community and decrease the abuse of power in collusion, corruption, and nepotism through the implementation of an electronic-based community monitoring and reporting system.

References is not available for this document.

Contact IEEE to Subscribe

References

References is not available for this document.