在印度尼西亚商业部门使用COBIT 2019测量IT安全治理能力

G-Tech Pub Date : 2023-10-05 DOI:10.33379/gtech.v7i4.3170
Robertus Nanda Christiadi, Rudi Sutomo
{"title":"在印度尼西亚商业部门使用COBIT 2019测量IT安全治理能力","authors":"Robertus Nanda Christiadi, Rudi Sutomo","doi":"10.33379/gtech.v7i4.3170","DOIUrl":null,"url":null,"abstract":"IT governance implementation in companies has occurred in the enterprise sector up to the BUMN scale. As stated in the Regulation of the Minister of Foreign Affairs Number 2 of 2013, Article 2(1) binds the business world. In the corporate sector, there are IT security issues. The measurement process uses the COBIT 2019 framework. The measurements taken will provide an analysis of the capacity level and gaps. Data was collected using quantitative (questionnaire) and qualitative (documentary studies and interviews) methods. The three relevant subdomains to measure are APO12 – Risk Management, APO13 – Managed Security, and DSS05 – Managed Security Services. The results of the capacity measurement show that the APO12 subdomain is at level 2, APO13 is at level 2, and DSS05 is stopped at level 2. These results indicate that there is a gap in the DSS05 subdomain. The results obtained show recommendations for improvement and level increase, especially in the DSS05 subdomain. The enterprise sector needs improvements in endpoint security policies, access policies, and event logs in IT incidents.","PeriodicalId":486638,"journal":{"name":"G-Tech","volume":"55 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-10-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Measurement of IT Security Governance Capabilities Using COBIT 2019 at Indonesian Business Sector\",\"authors\":\"Robertus Nanda Christiadi, Rudi Sutomo\",\"doi\":\"10.33379/gtech.v7i4.3170\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"IT governance implementation in companies has occurred in the enterprise sector up to the BUMN scale. As stated in the Regulation of the Minister of Foreign Affairs Number 2 of 2013, Article 2(1) binds the business world. In the corporate sector, there are IT security issues. The measurement process uses the COBIT 2019 framework. The measurements taken will provide an analysis of the capacity level and gaps. Data was collected using quantitative (questionnaire) and qualitative (documentary studies and interviews) methods. The three relevant subdomains to measure are APO12 – Risk Management, APO13 – Managed Security, and DSS05 – Managed Security Services. The results of the capacity measurement show that the APO12 subdomain is at level 2, APO13 is at level 2, and DSS05 is stopped at level 2. These results indicate that there is a gap in the DSS05 subdomain. The results obtained show recommendations for improvement and level increase, especially in the DSS05 subdomain. The enterprise sector needs improvements in endpoint security policies, access policies, and event logs in IT incidents.\",\"PeriodicalId\":486638,\"journal\":{\"name\":\"G-Tech\",\"volume\":\"55 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-10-05\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"G-Tech\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.33379/gtech.v7i4.3170\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"G-Tech","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.33379/gtech.v7i4.3170","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

公司中的IT治理实现已经发生在企业部门,达到了企业管理系统的规模。正如2013年第2号外交部长条例所述,第2(1)条对商界具有约束力。在企业部门,存在IT安全问题。测量过程使用COBIT 2019框架。所采取的测量将提供对能力水平和差距的分析。采用定量(问卷调查)和定性(文献研究和访谈)方法收集数据。要度量的三个相关子域是APO12—风险管理,APO13—托管安全,以及DSS05—托管安全服务。容量测量结果显示,APO12子域处于2级,APO13子域处于2级,DSS05子域处于2级停止。这些结果表明在DSS05子域中存在一个缺口。所得结果显示了改进和水平提高的建议,特别是在DSS05子域。企业部门需要改进端点安全策略、访问策略和IT事件中的事件日志。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Measurement of IT Security Governance Capabilities Using COBIT 2019 at Indonesian Business Sector
IT governance implementation in companies has occurred in the enterprise sector up to the BUMN scale. As stated in the Regulation of the Minister of Foreign Affairs Number 2 of 2013, Article 2(1) binds the business world. In the corporate sector, there are IT security issues. The measurement process uses the COBIT 2019 framework. The measurements taken will provide an analysis of the capacity level and gaps. Data was collected using quantitative (questionnaire) and qualitative (documentary studies and interviews) methods. The three relevant subdomains to measure are APO12 – Risk Management, APO13 – Managed Security, and DSS05 – Managed Security Services. The results of the capacity measurement show that the APO12 subdomain is at level 2, APO13 is at level 2, and DSS05 is stopped at level 2. These results indicate that there is a gap in the DSS05 subdomain. The results obtained show recommendations for improvement and level increase, especially in the DSS05 subdomain. The enterprise sector needs improvements in endpoint security policies, access policies, and event logs in IT incidents.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信