Evaluasi Persepsi Kapabilitas Tata Kelola Keamanan Data Pada Badan XYZ: Kajian Cobit 2019 (APO12, APO13, Dan DSS05)
Keywords
COBIT 2019, Capability, Data Security, APO12, APO13, DSS05, Perception BiasAbstract
Statistical data is a strategic asset for national development; its security and integrity are prerequisites for public trust. This study evaluates perceived capability of data security governance at a regional statistical agency using the COBIT 2019 framework across APO12 (Manage Risk), APO13 (Manage Security), and DSS05 (Manage Security Services). A census survey of 17 employees involved in information system management was conducted using a 45-item, 5-point Likert questionnaire (15 items per domain). The final measurement model retained 32 valid items (APO12 15, APO13 6, DSS05 11). All constructs showed high reliability (Cronbach's alpha 0.912–0.961; composite reliability 0.938–0.967) and adequate convergent validity (AVE 0.665–0.728). However, discriminant validity was not fully established: the HTMT value between APO12 and APO13 (0.908) exceeded the 0.90 threshold, and the Fornell-Larcker criterion was also violated for that pair. Response distribution was highly homogeneous (69.7% of all responses were scored 4 "Agree"; no score-1 responses; average per-respondent standard deviation of only 0.29), indicating a tendency toward acquiescence response style. All measured capability levels were rated Largely Achieved with achievement scores between 75.7% and 82.4%, yielding capability level L5 for APO12 and DSS05 and L3 for APO13, with no gap against the target level 3 (Defined). Owing to the perception-based instrument and small sample size, these results cannot be interpreted as actual maturity. The study recommends evidence-based capability assessment (documents, interviews, and observation), a more discriminative instrument, and further testing with a larger sample
References
Badan Pusat Statistik. (2021). Statistik Indonesia 2021. Badan Pusat Statistik.
Chin, W. W. (1998). The partial least squares approach to structural equation modeling. In G. A. Marcoulides (Ed.), Modern Methods for Business Research (pp. 295–336). Lawrence Erlbaum Associates.
Christiadi, R. N., & Sutomo, R. (2023). Measurement of IT security governance capabilities using COBIT 2019 at Indonesian business sector. G-Tech: Jurnal Teknologi Terapan, 7(4), 1498–1508. https://doi.org/10.33379/gtech.v7i4.3170
De Haes, S., Van Grembergen, W., Joshi, A., & Huygh, T. (2020). Enterprise Governance of Information Technology: Achieving Alignment and Value in Digital Organizations (3rd ed.). Springer.
Gartner. (2019). IT Score for Digital Business. Gartner.
Hair, J. F., Black, W. C., Babin, B. J., & Anderson, R. E. (2019). Multivariate Data Analysis (8th ed.). Cengage.
Hair, J. F., Hult, G. T. M., Ringle, C. M., & Sarstedt, M. (2022). A Primer on Partial Least Squares Structural Equation Modeling (PLS-SEM) (3rd ed.). Sage.
Henseler, J., Ringle, C. M., & Sarstedt, M. (2015). A new criterion for assessing discriminant validity in variance-based structural equation modeling. Journal of the Academy of Marketing Science, 43(1), 115–135. https://doi.org/10.1007/s11747-014-0403-8
ISACA. (2018). COBIT 2019 Framework: Introduction and Methodology. ISACA.
ISACA. (2019). COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution. ISACA.
ISACA. (2020). COBIT 2019: Assessor Guide: Using COBIT 2019. ISACA.
Nisri, A. (2023). Evaluasi tingkat kapabilitas keamanan sistem informasi menggunakan kerangka kerja COBIT 2019. Jurnal Tata Kelola dan Kerangka Kerja Teknologi Informasi, 9(1), 34–41.
Parera, N. M., & Tambotoh, J. J. C. (2024). Pengukuran kapabilitas tata kelola teknologi informasi pada DISKOMINFO Salatiga menggunakan COBIT 2019. SISTEMASI: Jurnal Sistem Informasi, 13(1), 324–334. https://doi.org/10.32520/stmsi.v13i1.3669
Paulhus, D. L. (1991). Measurement and control of response bias. In J. P. Robinson, P. R. Shaver, & L. S. Wrightsman (Eds.), Measures of Personality and Social Psychological Attitudes (pp. 17–59). Academic Press.
Podsakoff, P. M., MacKenzie, S. B., Lee, J.-Y., & Podsakoff, N. P. (2003). Common method biases in behavioral research: A critical review of the literature and recommended remedies. Journal of Applied Psychology, 88(5), 879–903. https://doi.org/10.1037/0021-9010.88.5.879
Radjulan, J. C., Iriani, A., & Tambotoh, J. (2024). Evaluation of IT governance computer network at Central Bureau of Statistics (BPS) Maluku Province using COBIT 2019 DSS01 and DSS05 domains. BAREKENG: Jurnal Ilmu Matematika dan Terapan, 18(4), 2779–2794. https://doi.org/10.30598/barekengvol18iss4pp2779-2794
Sekaran, U., & Bougie, R. (2016). Research Methods for Business: A Skill-Building Approach (7th ed.). Wiley.
Sugiyono. (2019). Metode Penelitian Kuantitatif, Kualitatif, dan R&D. Alfabeta.
Suroto, S., & Friadi, J. (2024). Evaluasi tingkat capability keamanan sistem informasi PT. CPPI menggunakan framework COBIT 2019. Jurnal Ilmu Siber dan Teknologi Digital, 2(1), 45–60. https://doi.org/10.35912/jisted.v2i1.2945




