• Home
  • Search
  • Towards Secure Information Systems: Developing and Implementing an Information Security Evaluation Model Using NIST CSF and COBIT 2019
  • Cite Icon1
  • https://doi.org/10.18421/tem141-17Copy DOI Icon

Towards Secure Information Systems: Developing and Implementing an Information Security Evaluation Model Using NIST CSF and COBIT 2019

Show More
  • Abstract
  • Literature Map
  • Citations
  • Similar Papers
Abstract

Ensuring information security in public sector information systems is now more important than ever. Advances in technology and information have not only made daily life easier, but also made the opportunities for cybercrimes vast and inevitable. This study aims to create a framework for evaluation that measure the maturity level of information security in information systems by integrating existing frameworks, NIST Cybersecurity Framework (CSF) and COBIT 2019. The result of this framework development is implemented in a public sector organization called PT XYZ, which has an information system as a tool to assist in the implementation of public services. The Capability Maturity Model Integration (CMMI) method is used to calculate the maturity level. The implemented approach resulted in information security maturity evaluation framework for information systems. This framework includes 118 activities which are divided into 23 categories. The distribution of the integration of the two frameworks contributes 61% activities, the NIST CSF contributes 8% and the COBIT 2019 framework contributes 31% activities. The measurement result of the information security maturity level in the information system at PT XYZ shows that all functions are at level 1 or the initial level. PT XYZ's low information security maturity reveals the critical need for stronger data protection and system resilience. This study introduces a novel approach to demonstrating a practical methodology for integrating two frameworks. The resulting framework enables public sector organizations to assess their security posture, identify areas for improvement, and enhance resilience against cyber threats, strengthening public service and safeguarding data.

Similar Papers
  • Research Article
  • Citations8

Maturity Framework Analysis ISO 27001: 2013 on Indonesian Higher Education

  • Apr 18, 2020
  • International Journal of Engineering & Technology
  • Ign Mantra +2
  • PDF
  • Research Article
  • Citations2

Examining the Boundary Effect of Information Systems Security Behavior Under Different Usage Purposes

  • Jan 01, 2019
  • IEEE Access
  • Ying Li +2
  • Research Article

HOW MUCH ICT SECURITY HAS IMPROVED DURING THE LAST DECADE

  • Apr 08, 2022
  • SOCIETY. TECHNOLOGY. SOLUTIONS. Proceedings of the International Scientific Conference
  • Mefat Shabani +3
  • Research Article
  • Citations63

Protection Motivation Theory in Information Systems Security Research

  • Apr 26, 2021
  • ACM SIGMIS Database: the DATABASE for Advances in Information Systems
  • Steffi Haag +2
  • Research Article
  • Citations4

Capturing industry experience for an effective information security assessment

  • Jan 01, 2006
  • International Journal of Information Systems and Change Management
  • Shu Chuan Chao +2
  • Research Article

Информационная безопасность предприятия как технология обеспечения защиты информации

  • Jan 01, 2024
  • Innovative Economics and Law
  • I.V Shamrina +1
  • Research Article
  • Citations1

Правові механізми забезпечення інформаційної безпеки в Україні

  • Jun 24, 2024
  • Visnik Nacional’nogo universitetu «Lvivska politehnika». Seria: Uridicni nauki
  • Olha Skochylias-Pavliv
  • Book Chapter
  • Citations4

Strategic Planning for IS Security: Designing Objectives

  • Jan 01, 2018
  • Gurpreet Dhillon +2
  • Research Article
  • Citations8

Analyzing Information Systems Security Research to Find Key Topics, Trends, and Opportunities

  • Jul 01, 2012
  • Journal of Information Privacy and Security
  • Roger Blake +1
  • Research Article

Maturity Level of Information Systems Security and Control: A Survey of Companies in Thailand

  • Dec 30, 2018
  • Journal of Applied Business and Economics
  • Chamaiporn Theerakarn +2
  • Research Article
  • Citations3

Review of Interoperability Practices for Enterprise Information System (EIS) in Public Sector

  • Dec 31, 2019
  • Asia-Pacific Journal of Information Technology & Multimedia
  • Zanora Zainon +1
  • Research Article
  • Citations63

Critical analysis of different approaches to minimizing user‐related faults in information systems security: implications for research and practice

  • Dec 01, 2000
  • Information Management & Computer Security
  • Mikko T Siponen
  • Research Article
  • Citations1

The Applied Aproach Impact Information Security For Government and Company (A Review)

  • Mar 21, 2022
  • Data Science: Journal of Computing and Applied Informatics
  • Henny Febriana +3
  • Research Article
  • Citations13

Interpreting Deep Structures of Information Systems Security

  • Nov 30, 2011
  • The Computer Journal
  • M Thomas +1
  • PDF
  • Research Article
  • Citations6

Balancing software and training requirements for information security

  • Sep 02, 2023
  • Computers & Security
  • Damjan Fujs +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.