Skip to content
Open access

“Development of an Integrated Information Security Governance Maturity Assessment Framework for Higher Education Institutions Using COBIT 2019 and ISO/IEC 27001: A Design Science Research Approach”

Jul 2026 · International Journal of Latest Technology in Engineering Management & Applied Science · Vol 15, pp. 202-224 · 0 citations · 17 references

TL;DR

An Integrated Information Security Governance Maturity Assessment Framework for Higher Education Institutions is developed by merging the governance principles of COBIT 2019 with the information security management demands of ISO/IEC 27001 and lays the groundwork for further implementation, testing, and empirical validation in real university settings.

Abstract

The adoption of digital technologies, online learning platforms, and electronic services has significantly changed the functioning of higher education institutions. Universities and colleges now rely extensively on digital platforms for teaching, learning, research, and administrative functions. As a result, these institutions manage large quantities of sensitive data, including student records, financial information, research findings, and other vital assets. In parallel, the rise in cybersecurity threats has underscored the necessity for enhanced information security governance to protect these resources and ensure secure and efficient technology use across campuses. Although established frameworks such as COBIT 2019 and ISO/IEC 27001 offer valuable guidance on governance and information security management, they are often implemented independently. This separation can cause gaps, overlaps, and inconsistencies in governance practices. To address this issue, this study developed an Integrated Information Security Governance Maturity Assessment Framework specifically for Higher Education Institutions by merging the governance principles of COBIT 2019 with the information security management demands of ISO/IEC 27001. The research employed a Design Science Research (DSR) methodology to develop a framework that is robust in theory and applicable to the higher education sector. This framework was built through a comprehensive analysis of COBIT 2019, ISO/IEC 27001:2022, relevant academic sources, and existing governance maturity models. The resulting framework encompasses five assessment dimensions: Governance and Leadership, Risk and Compliance Management, Security Operations and Control Management, Monitoring and Performance Evaluation, and Continuous Improvement and Governance Optimization. Additionally, a five-level maturity model was crafted to enable institutions to evaluate their current governance capability and identify areas needing further development. Findings indicate that integrating COBIT 2019 and ISO/IEC 27001 results in a more systematic and thorough approach to information security governance. The framework provides higher education institutions with a practical tool for assessing governance maturity, planning improvement efforts, and enhancing cybersecurity governance. It also lays the groundwork for further implementation, testing, and empirical validation in real university settings.

Read PDF

Similar papers

Open access Jul 2026

Information Security Governance Model for Higher Education Based on ISO/IEC 27001:2022 and COBIT 2019

Higher education institutions manage large volumes of sensitive information, including personal data of students and staff, research data, financial records, and operational information. The increasing number of cyber incidents affecting universities, both globally and in Indonesia, indicated the need for a more structured approach to information security governance. This study aimed to develop an information security governance design model through the integration of ISO/IEC 27001:2022 and COBIT 2019. The research adopted a design science research methodology. The proposed model integrated ISO/IEC 27001:2022 information security controls with COBIT 2019 governance and management objectives and determined the expected capability level using COBIT design factors. The model was demonstrated through a case study at an Indonesian higher education institution, where the current capability levels were assessed using the Not, Partially, Largely, and Fully achieved rating scale. The results showed that all eight evaluated objectives were at Capability Level 2, with scores ranging from 37.40% to 62.56%, indicating that governance processes had been implemented but were not yest consistently documented and managed. The evaluation demonstrated that the proposed model can serve as a practical reference for assessing and improving information security governance in higher education institutions.

Neonatal March Parera, Wiwin Sulistyo, J. Tambotoh · 0 citations
Open access Aug 2026

An Integrated University Digital Transformation Model Combining IT Governance, Interoperability, Cloud Security Assessment and Data Analytics: The UTMACH Case in Ecuador

The case indicates that university digital transformation is strengthened when technological implementation is integrated with formal governance, systematic assessment, evidence-based planning, and institutional accountability.

Jennifer Célleri-Pacheco, Fernanda Tusa Jumbo, Oswaldo Chuquirima Camacho et al. · 0 citations
Review Open access Jul 2026

Assessment of Information Security Maturity Using the KAMI Index 5.0 Aligned with ISO/IEC 27001

The advancement of digital government initiatives has led to a wider deployment of IT systems for public service delivery. Consequently, public sector agencies must establish robust cyber defenses to safeguard critical information and infrastructure. This research evaluates the information security posture of the Padang City Communication and Informatics Office, focusing on its readiness to sustain digital transformation. The assessment aligns with the ISO/IEC 27001 framework and utilizes the KAMI Index 5.0 as the primary diagnostic tool. Employing a qualitative descriptive methodology, the study collected empirical data through field observations, stakeholder interviews, and comprehensive policy reviews. The diagnostic results revealed a compliance score of 518, demonstrating that the organization has established the baseline requirements of the ISO/IEC 27001 standard. Nonetheless, the overall maturity remains at Level II, showing that while several protective processes are active, they lack formal documentation and optimal coordination. To bridge these gaps, structured action plans are formulated across seven key assessment domains: governance (5 actions), risk mitigation (14 actions), security policy framework (5 actions), asset classification (13 actions), technical infrastructure (6 actions), data privacy (11 actions), and third-party control (6 actions). These actionable steps provide a strategic roadmap to enhance the mature of city's electronic administration security.

Fitri Safnita, Putri Ramdani, Maisan Dewi Puspa Khairani et al. · 0 citations
Review Open access Aug 2026

DIGITAL INFRASTRUCTURE GOVERNANCE IN U.S. HIGHER EDUCATION: A PRACTITIONER FRAMEWORK FOR SYSTEM SELECTION

The article proposes the Digital Infrastructure Governance and Selection (DIGS) framework, which combines seven decision domains with six stage gates spanning problem definition, mandatory assurance, comparative assessment, controlled piloting, contracting and implementation, and lifecycle review and is a transparent decision aid rather than a statistically validated prediction model.

Fatema Akter · 0 citations
Review Open access Jul 2026

Evaluating Security Challenges in Digital Access Systems for Technology-Enabled Vocational Education: A Systematic Literature Review

The rapid expansion of technology-enabled vocational education has increased reliance on digital access systems that regulate entry to learning platforms, simulations, and assessment environments. This study examines how security challenges in these systems affect learning continuity in vocational education and identifies factors that intensify disruption risks. A systematic review of peer-reviewed studies published between 2020 and 2025 was conducted using five academic databases, applying predefined inclusion criteria and synthesizing findings through descriptive and thematic analysis. Results show that weaknesses in data confidentiality, integrity, and especially system availability frequently interrupt instructional activities, particularly practice-based learning dependent on digital laboratories and assessment tools. Disruptions are often amplified by misalignment between technical infrastructure, user practices, and institutional governance, with institutions lacking governance capacity and user training facing higher risks of learning interruption. Although technical and administrative mitigation strategies exist, they are often implemented without sufficient alignment to pedagogical needs. The study concludes that digital access security should be treated not merely as a technical concern but as a prerequisite for equitable and resilient vocational learning, calling for integrated socio-technical and pedagogically informed security strategies.

K. Agyeibi, Budi Mulyanti, Agus Setiawan et al. · 0 citations
Open access Aug 2026

A Structured NIS2–ISO/IEC 27001:2022 Alignment Framework for Higher Education Institutions

Higher education institutions operate complex digital environments that combine administrative services, research infrastructures, learning platforms, identity systems, and heterogeneous departmental IT. In the European Union, the NIS2 Directive increases the need for structured cybersecurity governance, while ISO/IEC 27001:2022 provides a mature information security management system standard that can support implementation. This paper proposes a design science artefact for aligning NIS2 obligations with ISO/IEC 27001:2022 clauses and Annex A controls in the context of higher education institutions. The framework organizes cybersecurity governance, asset and service scoping, risk management, incident handling, business continuity, supplier and cloud dependencies, access control, awareness, monitoring, and continual improvement into a staged maturity model. The artefact is instantiated for a Romanian public university context and assessed through internal traceability analysis, including mappings between NIS2 Articles 20, 21, and 23, Romanian NIS2 transposition requirements, and ISO/IEC 27001:2022 control areas. The institutional illustration identifies candidate assessment domains and evidence requirements but does not assign maturity levels because the internal records required by the scoring protocol were unavailable; it therefore does not constitute an audit, verified institutional measurement, or empirical validation. The contribution is therefore a structured and reusable compliance design artefact, together with a transparent mapping method that can support future expert validation, institutional pilots, and audit-oriented refinement.

Alexandru Iovanovici, L. Prodan · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.