Information Security Governance Model for Higher Education Based on ISO/IEC 27001:2022 and COBIT 2019
Abstract
Higher education institutions manage large volumes of sensitive information, including personal data of students and staff, research data, financial records, and operational information. The increasing number of cyber incidents affecting universities, both globally and in Indonesia, indicated the need for a more structured approach to information security governance. This study aimed to develop an information security governance design model through the integration of ISO/IEC 27001:2022 and COBIT 2019. The research adopted a design science research methodology. The proposed model integrated ISO/IEC 27001:2022 information security controls with COBIT 2019 governance and management objectives and determined the expected capability level using COBIT design factors. The model was demonstrated through a case study at an Indonesian higher education institution, where the current capability levels were assessed using the Not, Partially, Largely, and Fully achieved rating scale. The results showed that all eight evaluated objectives were at Capability Level 2, with scores ranging from 37.40% to 62.56%, indicating that governance processes had been implemented but were not yest consistently documented and managed. The evaluation demonstrated that the proposed model can serve as a practical reference for assessing and improving information security governance in higher education institutions.