Information Security Maturity Assessment Using the KAMI Index 5.0 Based on ISO/IEC 27001:2022: A Case Study of a Government Agency Under the Ministry of Finance of the Republic of Indonesia

Authors

  • M. Ihsan Alfani Putera Institut Teknologi Kalimantan
  • Nana Aulia Tabita Institut Teknologi Kalimantan
  • Dwi Nur Amalia Institut Teknologi Kalimantan

DOI:

https://doi.org/10.59261/jequi.v8i2.322

Keywords:

Information Security Index (KAMI) 5.0, ISO/IEC 27701:2022, Information Security, XYZ Agency

Abstract

Background: XYZ Agency has adopted information technology but faces phishing attacks, spam, unclear information security roles, and a lack of prior security evaluation. Therefore, its readiness and maturity must be assessed using the KAMI Index 5.0 and ISO/IEC 27001:2022.

Objective: This study aims to evaluate the level of information security readiness and maturity at Institution XYZ, a government agency under the Ministry of Finance of the Republic of Indonesia, using the KAMI Index Version 5.0 aligned with ISO/IEC 27001:2022, and to formulate structured improvement recommendations.

Methods: This study employed a qualitative descriptive case study approach through interviews, observation, and document review. Data were assessed using KAMI 5.0, validated through triangulation and member-checking, with coder reliability confirmed by Cohen’s Kappa.

Results: The assessment results obtained for the Electronic Systems Category were 29 points, indicating a high level of dependency, with a total score of 347 points across the six evaluation areas. The maturity level falls within the range of I–II, corresponding to a status of basic framework compliance. Subsequently, 97 recommendations for improvement were provided, referring to ISO/IEC 27001:2022.

Conclusion: The formulation of these recommendations is expected to assist XYZ Agency in enhancing information security management and mitigating identified risks.

Downloads

Download data is not yet available.

References

Afiansyah, H. G., & Kadarwati, F. N. A. (2023). Penyusunan Kebijakan Pengamanan Dan Pengelolaan Infrastruktur Operasi Keamanan Siber Menggunakan NIST CSF 2.0 Dan ISO/IEC 27001:2022. Info Kripto, 17(3). https://doi.org/10.56706/Ik.V17i3.81

Alrehili, A. A., & Alhazmi, O. H. (2023). ISO/IEC 27001 Standard: Analytical And Comparative Overview. International Conference On Advances In Data-Driven Computing And Intelligent Systems, 143–156.

Anteng, S. L. A. (2026). Peran ISO 9001 Dan ISO 27001 Dalam Meningkatkan Customer Satisfaction & Trust Di Perusahaan IT PT XYZ. Prosiding Seminar Praktik Keinsinyuran VII Tema Peran Insinyur Profesional Dalam Reka Cipta Solusi Berkelanjutan Berbasis Environmental, Social, And Governance (ESG), 32.

Bahary, M. Syaiful, & Sugiantoro, B. (2024). Evaluasi Tingkat Keamanan Indeks Kami (Studi Kasus : Universitas X). Cyber Security Dan Forensik Digital, 7(2), 90–94. https://doi.org/10.14421/Csecurity.2024.7.2.4634

Beri, N. (2022). Paper_Beri Novriyadi - Beri Novriyadi.

Diva R. N., Hayuhardhika N. P. W., & Dwi, H. A. (2020). Evaluasi Keamanan Informasi Pada Dinas Komunikasi Dan Informatika Kabupaten Malang Menggunakan Indeks Kami (Keamanan Informasi). 4(5). http://J-Ptiik.Ub.ac.id

Firmansyah, F., & Nugroho, A. (2024). Analisis Keamanan Informasi Menggunakan Indeks Keamanan Informasi (KAMI) Versi 5.0. Jurnal Borneo Informatika Dan Teknik Komputer, 4(2), 13–21.

Gupta, A., Gupta, S., Sharma, S., Singh, J., Ali, F., & Kwak, D. (2026). A Privacy Preserving Optimized Intelligent Security Framework For Smart Homes Using Zero Trust Architecture And Explainability. Scientific Reports.

Harahap, A. H. H., Andani, C. D., Christie, A., Nurhaliza, D., & Fauzi, A. (2023). Pentingnya Peranan Cia Triad Dalam Keamanan Informasi Dan Data Untuk Pemangku Kepentingan Atau Stakholder. Jurnal Manajemen Dan Pemasaran Digital, 1(2), 73–83. https://doi.org/10.38035/Jmpd.V1i2.34

Hidayat, F. S., & Bakhtiar, A. (2023). Evaluasi Sistem Manajemen Keamanan Informasi Berdasarkan Penilaian Indeks Kami V. 4.2 Pada Dinas Xyz Provinsi Jawa Tengah. Industrial Engineering Online Journal, 12(4).

Jelita, L. D. A., Al Azam, M. N., & Nugroho, A. (2024). Evaluasi Keamanan Teknologi Informasi Menggunakan Indeks Keamanan Informasi 5.0 Dan ISO/EIC 27001:2022. Jurnal Saintekom, 14(1), 84–94. https://doi.org/10.33020/Saintekom.V14i1.623

Leme, R. Da S., De Souza Pinto, J., Zanon, L. G., Sigahi, T. F. A. C., Moraes, G. H. S. M. De, Moro, S. R., & Anholon, R. (2026). Information Security Management: A Fuzzy Dematel Analysis Of The New Iso/Iec 27001:2022 Controls. Information & Computer Security, 34(3), 413–434. https://doi.org/10.1108/Ics-10-2024-0269

Magnusson, L., Iqbal, S., Elm, P., & Dalipi, F. (2025). Information Security Governance In The Public Sector: Investigations, Approaches, Measures, And Trends. International Journal Of Information Security, 24(4), 177.

Pathirana, A. I. W., & Wilenius, M. (2025). ISO 27001 And Global Privacy Compliance.

Puspitasari, D., & Sutabri, T. (2023). Analisis Kejahatan Phising Pada Sektor E-Commerce Di Marketplace Shopee. Jurnal Digital Teknologi Informasi, 6(2). https://doi.org/10.32502/Digital.V6i2.5653

Putra, Y. V. F. (2021). Modus Operandi Tindak Pidana Phising Menurut UU ITE. Jurist-Diction, 4(6), 2525. https://doi.org/10.20473/Jd.V4i6.31857

Putri, T. S., Mutiah, N. M., & Prawira, D. P. (2022). Analisis Manajemen Risiko Keamanan Informasi Menggunakan Nist Cybersecurity Framework Dan Iso/Iec 27001:2013 (Studi Kasus: Badan Pusat Statistik Kalimantan Barat). Coding Jurnal Komputer Dan Aplikasi, 10(02), 237. https://doi.org/10.26418/Coding.V10i02.54972

Rojabi, M. A. (2025). Jejak Evolusi Iso 27001: Dari Awal Hingga Versi 2022. Afdan Rojabi Publisher.

Souhoka, B. A., Fadillah, R. A., Fathan, M., Meldiansah, R., Mutakin, M. I., & Fauziyah. (2025). Analisis Strategi Pencegahan Phising Studi Kasus Pada Media Sosial Facebook. Jurnal Sistem Informasi Galuh, 3(1), 10–22. https://doi.org/10.25157/Jsig.V3i1.4117

Sugiantoro, B. (2025). Evaluasi Tingkat Sistem Keamanan Teknologi Informasi Menggunakan Indeks Kami Dan Cobit 5 (Studi Kasus : Ponpes Demak). Jurnal Media Informatika [Jumin]. https://doi.org/10.55338/Jumin.V6i4.6492

Suyahman, S. (2025). Manajemen Dan Kebijakan Keamanan Informasi. PT Solusi Administrasi Hukum.

Wibawa, I. N. A. A., Susila, A. A. N. H., & Pasirulloh, M. A. (2024). Information Security Evaluation At Hospital Using Index Kami 5.0 And Recommendations Based On ISO/IEC 27001:2022. Journal Of Information Systems And Informatics, 6(4), 3070–3086. https://doi.org/10.51519/Journalisi.V6i4.949

Wijaya, Y. D. (2021). Evaluasi Kemananan Sistem Informasi Pasdeal Berdasarkan Indeks Keamanan Informasi (KAMI) ISO/IEC 27001:2013. Jurnal Sistem Informasi Dan Informatika (SIMIKA), 4(2), 115–130. https://doi.org/10.47080/Simika.V4i2.1178

Downloads

Published

2026-06-12