MODEL LAYERED MAPPING EVALUASI KEAMANAN SISTEM INFORMASI BERBASIS NIST CSF 2.0, COBIT 2019, DAN NIST SP 800-53

Authors

  • Fendi Setiabudi Universitas Amikom Yogyakarta
  • Alva Hendi Muhammad Universitas Amikom Yogyakarta
  • Sri Ngudi Wahyuni Universitas Amikom Yogyakarta

DOI:

https://doi.org/10.31539/0g2gqn02

Abstract

Cybersecurity evaluation is necessary to identify the security condition and gaps within an information system. The Forest Product Administration Information System (SIPUHH) is an information system used to support electronic recording and reporting in forest product administration processes. This study aims to develop a layered mapping approach for evaluating SIPUHH cybersecurity in a structured and traceable manner. The frameworks used are NIST CSF 2.0 as the cybersecurity outcome layer, COBIT 2019 APO13 – Managed Security as the management layer, and NIST SP 800-53 as the security control layer. This study employs a qualitative approach using an evaluative research design with a descriptive-analytical orientation. Data were collected through interviews with SIPUHH developers and responsible personnel, as well as through verification of technical and documentary evidence. The results of the layered mapping were operationalized into 27 indicators to establish the Current Profile, formulate the Target Profile, and identify SIPUHH cybersecurity gaps. The evaluation results show that 10 indicators are classified as High priority, 15 indicators as Medium priority, and 2 indicators as Maintenance. The findings indicate that SIPUHH has established several technical and operational security capabilities; however, these capabilities are not yet fully supported by formal and structured security governance, policies, procedures, documentation, and evaluation processes. The analysis of interrelationships among the findings resulted in six security improvement programs covering governance and risk management, third parties and interconnections, protection controls, monitoring and event analysis, incident response, and service resilience and recovery.

References

Bernardo, L., Malta, S., & Magalhães, J. (2025). An evaluation framework for cybersecurity maturity aligned with the NIST CSF. Electronics, 14(7), 1364. https://doi.org/10.3390/electronics14071364

Fadila, V., Mutiah, N., & Sari, R. P. (2023). Cyber security audit using CIS CSC, NIST CSF and COBIT 2019 framework. CESS (Journal of Computer Engineering, System and Science), 8(2), 271–283. https://doi.org/10.24114/cess.v8i2.43257

Fadya, M., & Utama, D. N. (2025). Towards secure information systems: Developing and implementing an information security evaluation model using NIST CSF and COBIT 2019. TEM Journal, 14(1), 182–191. https://doi.org/10.18421/TEM141-17

Irawan, H., Muhammad, A. H., & Nasiri, A. (2024). Design of cybersecurity maturity assessment framework using NIST CSF v1.1 and CIS Controls v8. INOVTEK Polbeng - Seri Informatika, 9(1), 126–139. https://doi.org/10.35314/isi.v9i1.3973

ISACA. (2018a). COBIT 2019 framework: Governance and management objectives. ISACA.

ISACA. (2018b). COBIT 2019 framework: Introduction and methodology. ISACA.

Joint Task Force. (2020). Security and privacy controls for information systems and organizations (NIST Special Publication 800-53 Rev. 5). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5

Liu, M., Shore, M., Yeoh, W., Jiang, F., & Zeadally, S. (2025). Toward effective cybersecurity management: A hierarchical process model with performance assessment. Journal of Cybersecurity, 11(1), tyaf020. https://doi.org/10.1093/cybsec/tyaf020

Mussmann, A., Brunner, M., & Breu, R. (2020). Mapping the state of security standards mappings. Proceedings of the 15th International Conference on Wirtschaftsinformatik (WI 2020), 1309–1324. https://doi.org/10.30844/WI_2020_L4-MUSSMANN

Pascoe, C., Quinn, S., & Scarfone, K. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST Cybersecurity White Paper 29). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29

Rambau, T. M., Munyoka, W., Phahlamohlaka, L. J., & Kadyamatimba, A. (2026). Evaluating cyber resilience frameworks for e-government: Applicability of NIST CSF, ISO/IEC 27001 and COBIT 2019 in developing country contexts. Information & Computer Security. https://doi.org/10.1108/ICS-09-2025-0376

Scarfone, K., Souppaya, M., & Fagan, M. (2024). Mapping relationships between documentary standards, regulations, frameworks, and guidelines: Developing cybersecurity and privacy concept mappings (NIST IR 8477). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.IR.8477

Sulistyowati, D., Handayani, F., & Suryanto, Y. (2020). Comparative analysis and design of cybersecurity maturity assessment methodology using NIST CSF, COBIT, ISO/IEC 27002 and PCI DSS. JOIV: International Journal on Informatics Visualization, 4(4), 225–230. https://doi.org/10.30630/joiv.4.4.482

Syafrizal, M., Selamat, S. R., & Zakaria, N. A. (2020). Analysis of cybersecurity standard and framework components. International Journal of Communication Networks and Information Security, 12(3), 417–432. https://doi.org/10.17762/ijcnis.v12i3.4817

Taherdoost, H. (2022). Understanding cybersecurity frameworks and information security standards—A review and comprehensive overview. Electronics, 11(14), 2181. https://doi.org/10.3390/electronics11142181

Downloads

Published

2026-09-06