Information Security Maturity Assessment Using the KAMI Index 5.0 Based on ISO/IEC 27001:2022: A Case Study of a Government Agency Under the Ministry of Finance of the Republic of Indonesia
DOI:
https://doi.org/10.59261/jequi.v8i2.322Keywords:
Information Security Index (KAMI) 5.0, ISO/IEC 27701:2022, Information Security, XYZ AgencyAbstract
Background: XYZ Agency has adopted information technology but faces phishing attacks, spam, unclear information security roles, and a lack of prior security evaluation. Therefore, its readiness and maturity must be assessed using the KAMI Index 5.0 and ISO/IEC 27001:2022.
Objective: This study aims to evaluate the level of information security readiness and maturity at Institution XYZ, a government agency under the Ministry of Finance of the Republic of Indonesia, using the KAMI Index Version 5.0 aligned with ISO/IEC 27001:2022, and to formulate structured improvement recommendations.
Methods: This study employed a qualitative descriptive case study approach through interviews, observation, and document review. Data were assessed using KAMI 5.0, validated through triangulation and member-checking, with coder reliability confirmed by Cohen’s Kappa.
Results: The assessment results obtained for the Electronic Systems Category were 29 points, indicating a high level of dependency, with a total score of 347 points across the six evaluation areas. The maturity level falls within the range of I–II, corresponding to a status of basic framework compliance. Subsequently, 97 recommendations for improvement were provided, referring to ISO/IEC 27001:2022.
Conclusion: The formulation of these recommendations is expected to assist XYZ Agency in enhancing information security management and mitigating identified risks.Downloads
References
Afiansyah, H. G., & Kadarwati, F. N. A. (2023). Penyusunan Kebijakan Pengamanan Dan Pengelolaan Infrastruktur Operasi Keamanan Siber Menggunakan NIST CSF 2.0 Dan ISO/IEC 27001:2022. Info Kripto, 17(3). https://doi.org/10.56706/Ik.V17i3.81
Alrehili, A. A., & Alhazmi, O. H. (2023). ISO/IEC 27001 Standard: Analytical And Comparative Overview. International Conference On Advances In Data-Driven Computing And Intelligent Systems, 143–156.
Anteng, S. L. A. (2026). Peran ISO 9001 Dan ISO 27001 Dalam Meningkatkan Customer Satisfaction & Trust Di Perusahaan IT PT XYZ. Prosiding Seminar Praktik Keinsinyuran VII Tema Peran Insinyur Profesional Dalam Reka Cipta Solusi Berkelanjutan Berbasis Environmental, Social, And Governance (ESG), 32.
Bahary, M. Syaiful, & Sugiantoro, B. (2024). Evaluasi Tingkat Keamanan Indeks Kami (Studi Kasus : Universitas X). Cyber Security Dan Forensik Digital, 7(2), 90–94. https://doi.org/10.14421/Csecurity.2024.7.2.4634
Beri, N. (2022). Paper_Beri Novriyadi - Beri Novriyadi.
Diva R. N., Hayuhardhika N. P. W., & Dwi, H. A. (2020). Evaluasi Keamanan Informasi Pada Dinas Komunikasi Dan Informatika Kabupaten Malang Menggunakan Indeks Kami (Keamanan Informasi). 4(5). http://J-Ptiik.Ub.ac.id
Firmansyah, F., & Nugroho, A. (2024). Analisis Keamanan Informasi Menggunakan Indeks Keamanan Informasi (KAMI) Versi 5.0. Jurnal Borneo Informatika Dan Teknik Komputer, 4(2), 13–21.
Gupta, A., Gupta, S., Sharma, S., Singh, J., Ali, F., & Kwak, D. (2026). A Privacy Preserving Optimized Intelligent Security Framework For Smart Homes Using Zero Trust Architecture And Explainability. Scientific Reports.
Harahap, A. H. H., Andani, C. D., Christie, A., Nurhaliza, D., & Fauzi, A. (2023). Pentingnya Peranan Cia Triad Dalam Keamanan Informasi Dan Data Untuk Pemangku Kepentingan Atau Stakholder. Jurnal Manajemen Dan Pemasaran Digital, 1(2), 73–83. https://doi.org/10.38035/Jmpd.V1i2.34
Hidayat, F. S., & Bakhtiar, A. (2023). Evaluasi Sistem Manajemen Keamanan Informasi Berdasarkan Penilaian Indeks Kami V. 4.2 Pada Dinas Xyz Provinsi Jawa Tengah. Industrial Engineering Online Journal, 12(4).
Jelita, L. D. A., Al Azam, M. N., & Nugroho, A. (2024). Evaluasi Keamanan Teknologi Informasi Menggunakan Indeks Keamanan Informasi 5.0 Dan ISO/EIC 27001:2022. Jurnal Saintekom, 14(1), 84–94. https://doi.org/10.33020/Saintekom.V14i1.623
Leme, R. Da S., De Souza Pinto, J., Zanon, L. G., Sigahi, T. F. A. C., Moraes, G. H. S. M. De, Moro, S. R., & Anholon, R. (2026). Information Security Management: A Fuzzy Dematel Analysis Of The New Iso/Iec 27001:2022 Controls. Information & Computer Security, 34(3), 413–434. https://doi.org/10.1108/Ics-10-2024-0269
Magnusson, L., Iqbal, S., Elm, P., & Dalipi, F. (2025). Information Security Governance In The Public Sector: Investigations, Approaches, Measures, And Trends. International Journal Of Information Security, 24(4), 177.
Pathirana, A. I. W., & Wilenius, M. (2025). ISO 27001 And Global Privacy Compliance.
Puspitasari, D., & Sutabri, T. (2023). Analisis Kejahatan Phising Pada Sektor E-Commerce Di Marketplace Shopee. Jurnal Digital Teknologi Informasi, 6(2). https://doi.org/10.32502/Digital.V6i2.5653
Putra, Y. V. F. (2021). Modus Operandi Tindak Pidana Phising Menurut UU ITE. Jurist-Diction, 4(6), 2525. https://doi.org/10.20473/Jd.V4i6.31857
Putri, T. S., Mutiah, N. M., & Prawira, D. P. (2022). Analisis Manajemen Risiko Keamanan Informasi Menggunakan Nist Cybersecurity Framework Dan Iso/Iec 27001:2013 (Studi Kasus: Badan Pusat Statistik Kalimantan Barat). Coding Jurnal Komputer Dan Aplikasi, 10(02), 237. https://doi.org/10.26418/Coding.V10i02.54972
Rojabi, M. A. (2025). Jejak Evolusi Iso 27001: Dari Awal Hingga Versi 2022. Afdan Rojabi Publisher.
Souhoka, B. A., Fadillah, R. A., Fathan, M., Meldiansah, R., Mutakin, M. I., & Fauziyah. (2025). Analisis Strategi Pencegahan Phising Studi Kasus Pada Media Sosial Facebook. Jurnal Sistem Informasi Galuh, 3(1), 10–22. https://doi.org/10.25157/Jsig.V3i1.4117
Sugiantoro, B. (2025). Evaluasi Tingkat Sistem Keamanan Teknologi Informasi Menggunakan Indeks Kami Dan Cobit 5 (Studi Kasus : Ponpes Demak). Jurnal Media Informatika [Jumin]. https://doi.org/10.55338/Jumin.V6i4.6492
Suyahman, S. (2025). Manajemen Dan Kebijakan Keamanan Informasi. PT Solusi Administrasi Hukum.
Wibawa, I. N. A. A., Susila, A. A. N. H., & Pasirulloh, M. A. (2024). Information Security Evaluation At Hospital Using Index Kami 5.0 And Recommendations Based On ISO/IEC 27001:2022. Journal Of Information Systems And Informatics, 6(4), 3070–3086. https://doi.org/10.51519/Journalisi.V6i4.949
Wijaya, Y. D. (2021). Evaluasi Kemananan Sistem Informasi Pasdeal Berdasarkan Indeks Keamanan Informasi (KAMI) ISO/IEC 27001:2013. Jurnal Sistem Informasi Dan Informatika (SIMIKA), 4(2), 115–130. https://doi.org/10.47080/Simika.V4i2.1178
Downloads
Published
Issue
Section
License
Copyright (c) 2026 M. Ihsan Alfani Putera, Nana Aulia Tabita, Dwi Nur Amalia

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.



