One of the vulnerabilities organizations face against cyberattacks arises from the absence of standardized governance for information system security.This encompasses insufficient security policies and a lack of consistent security updates and monitoring.This study aims to evaluate and gauge the information system security governance of the Directorate General of Human Settlements.COBIT 2019 and ISO 27001:2013 frameworks are employed to bolster the administration and safeguarding of information assets, while also establishing more robust and secure IT governance.The research methodology encompasses gathering data through interviews, observations, and analysis of pertinent security policy documents and information management practices.From this study, 12 specific information security domains are identified: EDM03, APO11, APO12, APO13, BAI06, BAI10, DSS02, DSS03, DSS04, DSS05, DSS06, and MEA03.Evaluating the present analysis, it is evident that the Directorate General of Human Settlements has not yet attained the targeted maturity level, set at level 5.This underscores the existing gaps in the organization's information system security governance.Based on the research findings, recommendations and a roadmap are proposed to rectify these deficiencies in information system security governance.This initiative aims to elevate information security measures and curtail risks arising from various threats like cyberattacks, data breaches, and unauthorized access.Additionally, the organization's overall average maturity level achieved, calculated at 3.07, further emphasizes the need for comprehensive enhancements in its information system security governance practices.
No takes yet. Share an insight, caveat, or question.
Aflakhah et al. (2024) studied this question.
Synapse has enriched 3 closely related papers on similar clinical questions. Consider them for comparative context: