使用COBIT 2019框架和ISO 27001:2013设计信息安全治理建议和路线图(案例研究Ditreskrimsus Polda XYZ)

Muhammad Yasin, Arry Akhmad Arman, I. J. M. Edward, W. Shalannanda
{"title":"使用COBIT 2019框架和ISO 27001:2013设计信息安全治理建议和路线图(案例研究Ditreskrimsus Polda XYZ)","authors":"Muhammad Yasin, Arry Akhmad Arman, I. J. M. Edward, W. Shalannanda","doi":"10.1109/TSSA51342.2020.9310875","DOIUrl":null,"url":null,"abstract":"The use of technology has applied in all areas of Polri's duties. However, the use of this technology does not yet have a level of capability in information security management. For this reason, it is necessary to design recommendations and an ideal information governance roadmap based on COBIT 2019 and ISO/IEC 27001: 2013 concerning Information Security Management Systems (ISMS). The design is carried out based on six stages in the Design Science Research Methodology (DSRM) in the form of identify problems and motivate, define objects of a solution, design and development, demonstration, evaluation, and communication. By mapping ISO/IEC 27001: 2013 into COBIT 2019, 29 domains of the 2019 COBIT core model selected which became the basis for designing and assessing the level of information security management capability at Ditreskrimsus Polda XYZ. The formulation of recommendations considered the assessment results. It produced the model of organizational structure, human resources, and policies and procedures that must be applied to Ditreskrimsus Polda XYZ in the form of a roadmap starting in 2021-2025 in managing information security. This research contributes to producing an information security governance design.","PeriodicalId":166316,"journal":{"name":"2020 14th International Conference on Telecommunication Systems, Services, and Applications (TSSA","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-04","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"10","resultStr":"{\"title\":\"Designing Information Security Governance Recommendations and Roadmap Using COBIT 2019 Framework and ISO 27001:2013 (Case Study Ditreskrimsus Polda XYZ)\",\"authors\":\"Muhammad Yasin, Arry Akhmad Arman, I. J. M. Edward, W. Shalannanda\",\"doi\":\"10.1109/TSSA51342.2020.9310875\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The use of technology has applied in all areas of Polri's duties. However, the use of this technology does not yet have a level of capability in information security management. For this reason, it is necessary to design recommendations and an ideal information governance roadmap based on COBIT 2019 and ISO/IEC 27001: 2013 concerning Information Security Management Systems (ISMS). The design is carried out based on six stages in the Design Science Research Methodology (DSRM) in the form of identify problems and motivate, define objects of a solution, design and development, demonstration, evaluation, and communication. By mapping ISO/IEC 27001: 2013 into COBIT 2019, 29 domains of the 2019 COBIT core model selected which became the basis for designing and assessing the level of information security management capability at Ditreskrimsus Polda XYZ. The formulation of recommendations considered the assessment results. It produced the model of organizational structure, human resources, and policies and procedures that must be applied to Ditreskrimsus Polda XYZ in the form of a roadmap starting in 2021-2025 in managing information security. This research contributes to producing an information security governance design.\",\"PeriodicalId\":166316,\"journal\":{\"name\":\"2020 14th International Conference on Telecommunication Systems, Services, and Applications (TSSA\",\"volume\":\"1 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-11-04\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"10\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 14th International Conference on Telecommunication Systems, Services, and Applications (TSSA\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/TSSA51342.2020.9310875\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 14th International Conference on Telecommunication Systems, Services, and Applications (TSSA","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/TSSA51342.2020.9310875","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 10

摘要

技术的使用已应用于Polri职责的所有领域。然而,这种技术的使用在信息安全管理方面还没有达到一定的水平。因此,有必要基于COBIT 2019和ISO/IEC 27001: 2013设计关于信息安全管理系统(ISMS)的建议和理想的信息治理路线图。设计以设计科学研究方法论(DSRM)中的六个阶段为基础,以识别问题和激励、确定解决对象、设计和开发、演示、评估和沟通的形式进行。通过将ISO/IEC 27001: 2013映射到COBIT 2019,选择了2019 COBIT核心模型的29个领域,这些领域成为设计和评估Ditreskrimsus Polda XYZ信息安全管理能力水平的基础。建议的拟订考虑了评估结果。它产生了组织结构、人力资源、政策和程序的模型,这些模型必须以2021-2025年管理信息安全的路线图的形式应用于Ditreskrimsus Polda XYZ。本研究有助于生成信息安全治理设计。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Designing Information Security Governance Recommendations and Roadmap Using COBIT 2019 Framework and ISO 27001:2013 (Case Study Ditreskrimsus Polda XYZ)
The use of technology has applied in all areas of Polri's duties. However, the use of this technology does not yet have a level of capability in information security management. For this reason, it is necessary to design recommendations and an ideal information governance roadmap based on COBIT 2019 and ISO/IEC 27001: 2013 concerning Information Security Management Systems (ISMS). The design is carried out based on six stages in the Design Science Research Methodology (DSRM) in the form of identify problems and motivate, define objects of a solution, design and development, demonstration, evaluation, and communication. By mapping ISO/IEC 27001: 2013 into COBIT 2019, 29 domains of the 2019 COBIT core model selected which became the basis for designing and assessing the level of information security management capability at Ditreskrimsus Polda XYZ. The formulation of recommendations considered the assessment results. It produced the model of organizational structure, human resources, and policies and procedures that must be applied to Ditreskrimsus Polda XYZ in the form of a roadmap starting in 2021-2025 in managing information security. This research contributes to producing an information security governance design.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信