Capability Level Evaluation of Information Security Using COBIT 2019 APO13 and DSS05: A Case Study of the E-Mansinam Safety Patrol System

Authors

  • Asrawati Universitas Papua
  • Lorna Yertas Baisa Universitas Papua
  • Alex De Kweldju Kweldju Universitas Papua

DOI:

https://doi.org/10.32664/j-intech.v14i03.2435

Keywords:

APO13, COBIT 2019, Capability Level, DSS05, Information Security Governance, Root Cause Analysis

Abstract

The increasing reliance on digital information systems has made information security governance a critical requirement for maintaining secure and reliable organizational operations. PT Pertamina Patra Niaga Fuel Terminal Manokwari utilizes the Safety Patrol feature within the E-Mansinam Website to support Health, Safety, Security, and Environment (HSSE) activities, including hazard reporting, safety monitoring, and corrective action management. This study evaluates the information security governance capability of the Safety Patrol feature using the COBIT 2019 framework, focusing on the APO13 (Managed Security) and DSS05 (Managed Security Services) domains. A descriptive quantitative approach was employed through observations, interviews, questionnaires, and documentation. The collected data were analyzed using Capability Assessment, Gap Analysis, and Root Cause Analysis (RCA). The results show that the APO13 domain achieved an average capability level of 4.04, exceeding the organization's target of Level 4, whereas the DSS05 domain achieved an average capability level of 3.93, indicating that several operational security service processes require further improvement. The largest capability gap was identified in DSS05.07 with a gap value of 0.44. Root Cause Analysis revealed that inconsistent security monitoring, incomplete documentation, limited periodic evaluations, and varying levels of personnel awareness were the primary factors contributing to the identified capability gaps. Based on these findings, this study proposes practical recommendations to strengthen information security governance and support the continuous improvement of the Safety Patrol feature, particularly in operational security service management.

References

[1] S. Suroto and J. Friadi, “Evaluasi Tingkat Capability Keamanan Sistem Informasi PT. CPPI Menggunakan Framework COBIT 2019 (Evaluation of PT’s Information System Security Capability Level. CPPI uses the COBIT 2019 framework) Riwayat Artikel,” vol. 2, no. 1, pp. 45–60, 2023.

[2] Y. T. Sepis, “Analisa Keamanan Sistem Informasi Menggunakan Framework Cobit 5 Dengan Domain Dss05 Dan Apo13 Di Pt Xyz,” TeIKa, vol. 12, no. 01, pp. 35–42, 2022, doi: 10.36342/teika.v12i01.2821.

[3] E. Endrianto and A. Zaelani Adnan, “Sistem Manajemen Keselamatan Kesehatan Kerja (SMK3) Kontraktor Di PT Pertamina EP Asset 3 Jatibarang Field,” Jurnal Kesehatan Tambusai, vol. 4, pp. 345–350, 2023.

[4] A. dan N. Hulu, “Evaluation of the Implementation of the Occupational Safety and Health Management System (SMK3),” Journal of Community Health Provision, vol. 5, no. 3, pp. 145–162, 2025, doi: 10.55885/jchp.v5i3.773.

[5] Pertamina Patra Niaga, “Fuel Terminal Manokwari,” PT Pertamina Patra Niaga. Accessed: Jun. 08, 2026. [Online]. Available: https://ftmanokwari.emansinam.com/

[6] ISACA, COBIT 2019 Framework: Governance and Management Objectives. Schaumburg, IL: ISACA, 2018.

[7] Christiadi & Sutomo, “Measurement of IT Security Governance Capabilities Using COBIT 2019 at Indonesian Business Sector,” G-Tech : Jurnal Teknologi Terapan, vol. 7, no. 4, pp. 295–305, 2023.

[8] Yulita & Tambotoh, “Analisis Manajemen Risiko pada PT . XYZ Menggunakan Risk Management Analysis of PT XYZ Using COBIT 2019 with Domain,” Sistemasi: Jurnal Sistem Informasi, vol. 13, no. 5, pp. 2033–2047, 2024, doi: https://doi.org/10.32520/stmsi.v13i5.4430.

[9] Sugiyono, Metode Penelitian Kuantitatif, Kualitatif, dan R&D, Edisi Kedu. Bandung: Alfabeta, 2023.

[10] ISACA, COBIT® 2019 Implementation guide : implementing and optimizing an information and technology governance solution. 2020.

[11] M. Brian Hardjadinata and J. Wiratama, “Capability Assessment of IT Governance Using the 2019 COBIT Framework for the IT Business Consultant Industry,” International Journal of Science, Technology & Management, vol. 4, no. 4, pp. 1034–1039, 2023, doi: 10.46729/ijstm.v4i4.902.

[12] J. Yuan Mambu, Z. Todingdatu, and J. Kondo, “IT Governance Maturity Assessment Using COBIT 2019 for System Enhancement and Strategic Decision Support,” COGITO Smart Journal, vol. 11, no. 1, pp. 193–206, 2025.

[13] G. M. W. Tangka and E. Lompoliu, “Optimizing IT Governance in BTS.id: A COBIT 2019-Based Analysis of Design Factors,” MALCOM: Indonesian Journal of Machine Learning and Computer Science, vol. 5, no. 2, pp. 699–710, 2025, doi: 10.57152/malcom.v5i2.1997.

[14] Hidayat et al, “Evaluation of Information Technology Governance Maturity Using COBIT 2019: A Case Study on the IT Security Industry,” Journal La Multiapp, vol. 5, no. 4, pp. 286–303, 2024, doi: 10.37899/journallamultiapp.v5i4.1442.

[15] Y. N. Widasari and N. R. Oktadini, “Capability Level Assessment of IT Governance in the SIAP KOJA Application Using the COBIT 2019 Framework,” Journal of Applied Informatics and Computing, vol. 9, no. 6, pp. 3706–3715, 2025, doi: 10.30871/jaic.v9i6.11433.

[16] I. N. S. Saputra, “TEKNOLOGI INFORMASI BERDASARKAN KERANGKA KERJA COBIT 2019 DENGAN METODE SCOPING GOALS CASCADE DAN DESIGN FACTORS : STUDI KASUS PT . XYZ,” INSERT: Information System and Emerging Technology Journal., vol. 6, no. 2, pp. 266–280, 2025.

[17] M. Khairul Anam, S. D. Putri, D. Yuliana, E. Yumami, and T. P. Lestari, “Application of the COBIT 2019 Framework to Analyse the Security of Academic Information Systems.,” Decode: Jurnal Pendidikan Teknologi Informasi, vol. 3, no. 2, pp. 59–65, 2023, doi: https://doi.org/10.51454/decode.v3i2.192.

[18] A. P. Nugroho and A. Ambarwati, “Analisis Tata Kelola Teknologi Informasi Di Pt. Garam Menggunakan Framework Cobit 2019 Domain, Deliver, Services & Support,” Jurnal Tata Kelola dan Kerangka Kerja Teknologi Informasi, vol. 11, no. 1, pp. 48–55, 2025, doi: 10.34010/jtk3ti.v11i1.15782.

[19] & Y. G. S. Anshari Amry, Yekti Wirani, “Assessment of IT Governance Capability Level Using the COBIT 2019 Framework: A Case Study of XYZ Institution,” JEPIN (Jurnal Edukasi dan Penelitian …, vol. 11, no. 2, pp. 277–286, 2025.

[20] I. Zufria, “Maturity Assessment at a University IT Center Using COBIT 2019 EDM and APO Domains,” Information Technology Education Journal, vol. 5, no. 1, pp. 18–40, 2026.

[21] A. N. Ibrahim and E. Suryani, “Transform IT Governance and Management to Enhance Information Security using COBIT Framework 2019,” International Journal of Informatics, Information System and Computer Engineering (INJIISCOM), vol. 7, no. 2, 2026.

[22] P. Purwadi and H. Santoso, “Comparison of Information Technology Governance Maturity Levels Based on COBIT 2019 at PT Kereta Commuter Indonesia in 2023 and 2024,” Jurnal Teknik Informatika (Jutif), vol. 6, no. 5, pp. 2962–2974, 2025, doi: 10.52436/1.jutif.2025.6.5.5200.

[23] V. N. Juni, R. D. Amalia, and E. Krisnanik, “Evaluasi Capability Level Tata Kelola TI Berbasis COBIT 2019 untuk Mendukung Transformasi Digital Perguruan Tinggi pengadaan aplikasi atau infrastruktur , tetapi memerlukan tata kelola yang mampu organisasi menyesuaikan ruang lingkup evaluasi berdasarkan,” Jurnal Penelitian Teknologi Informasi Dan Sains, vol. 4, no. juni, pp. 17–33, 2026.

[24] M. Barsalou and B. Starzyńska, “Inquiry into the Use of Five Whys in Industry,” Quality Innovation Prosperity, vol. 27, no. 1, pp. 62–78, 2023, doi: 10.12776/QIP.V27I1.1771.

[25] A. Ito et al., “Improved root cause analysis supporting resilient production systems,” Journal of Manufacturing Systems, vol. 64, no. April, pp. 468–478, 2022, doi: 10.1016/j.jmsy.2022.07.015.

[26] M. D. S. Antariksa, M. P. Angin, and A. P. Widodo, “COBIT 2019 Framework in IT Governance: A Systematic Literature Review of Implementation Challenges and Benefits Across Various Industry Sectors,” Journal of Renewable Energy, Electrical, and Computer Engineering, vol. 5, no. 1, pp. 99–105, 2025, doi: 10.29103/jreece.v5i1.19501.

[27] I. P. S. Almantara, I. N. A. Prabawa, and I. N. A. Prabawa, “Evaluation of Information Technology Governance Using the COBIT Framework in Higher Education in Indonesia : A Literature Study,” NAICE Journal of Next Applied Informatics in Computer Engineering, vol. 1, no. 1, pp. 25–33, 2026.

[28] A. Zaki, M. R., & Tirtana, “Implementation of APO12, APO13 and DSS05 Sub-Domains in COBIT 2019 to Improve Information System Security at LAZIS Sabilillah Malang,” in Proceedings of the 1st International Conference on Business, Innovation, Technology & Science (ICoBITS), Universitas Bhinneka Nusantara, 2025, pp. 39–44.

[29] G. B. R. Francolla, G. R. Mandoya, M. D. Walangitan, E. Lompoliu, and J. Y. Mambu, “Information Technology Governance Audit Using the COBIT 2019 Framework at XYZ Institution,” Cogito Smart Journal, vol. 8, no. 2, pp. 346–358, 2022.

[30] R. F. Mubarak and M. I. Fianty, “Leveraging COBIT 2019 to Implement IT Governance in Mineral Mining Company,” Journal of Information Systems and Informatics, vol. 5, no. 3, pp. 1058–1071, 2023, doi: 10.51519/journalisi.v5i3.545.

[31] A. S. Mohammed, P. Reinecke, P. Burnap, O. Rana, and E. Anthi, “Cybersecurity Challenges in the Offshore Oil and Gas Industry: An Industrial Cyber-Physical Systems (ICPS) Perspective,” ACM Transactions on Cyber-Physical Systems, vol. 6, no. 3, pp. 1–27, 2022, doi: 10.1145/3548691.

[32] K. S. Cherilyn Pascoe, Stephen Quinn, “The NIST Cybersecurity Framework,” National Institute of Standards and Technology, p. 32, 2024, doi: https://doi.org/10.6028/NIST.CSWP.29.

Downloads

Published

2026-09-19