Model Konseptual Penguatan Instrumen Penilaian Kematangan Keamanan Siber (IKAS) menggunakan Pendekatan Sosioteknis melalui Pemetaan Keselarasan terhadap NIST CSF 2.0 dan ISO/IEC 27001:2022
Abstract
The Cybersecurity Maturity Assessment Instrument (IKAS) underpins the protection roadmap of Vital Information Infrastructure in Indonesia, so any weakness in its design propagates directly into national policy. Its alignment with international frameworks and the balance of its sociotechnical composition, however, have never been examined academically. This study maps the alignment of IKAS version 1.2.1 against NIST CSF 2.0 and ISO/IEC 27001:2022 bidirectionally, diagnoses the gaps through Leavitt’s Diamond, and designs a conceptual strengthening model named IKAS-ST. A descriptive qualitative content analysis was applied to 181 IKAS items, 106 NIST CSF 2.0 subcategories, and 93 ISO/IEC 27001:2022 Annex A controls. The instrument proves substantially aligned, with an average forward coverage of 81.2% (Largely Achieved), yet 12 white spots remain, concentrated in the governance and recovery functions. The decisive finding is that Task is the only under-represented scope, with an extreme deficit in the Detection domain where items measure the ownership of detection technology rather than the procedures that operate it. The merit of IKAS-ST lies not in adding items but in three testable properties: every added item is traceable to an identified white spot, so no addition is speculative; the restructuring addresses the root cause, namely the absence of an explicit procedural scope; and all 181 original items are retained, preserving the comparability of historical assessment results. The model is conceptual and awaits expert validation and field testing.
Downloads
References
Ani, U. D., Watson, J. M., Tuptuk, N., Hailes, S., & Jawar, A. (2022). Socio-technical security modelling: Analysis of state-of-the-art, application, and maturity in critical industrial infrastructure environments/domains. PETRAS National Centre of Excellence in IoT Systems Cybersecurity. https://shura.shu.ac.uk/32206/1/2305.05108.pdf.
Apriany, A., & Wibowo, A. (2024). Analysis of the implementation of ISO 27001:2022 and KAMI index in enhancing the information security management system in consulting firms. Indonesian Journal of Computing and Cybernetics Systems, 18, 417-428. https://doi.org/10.22146/ijccs.100385.
Badan Siber dan Sandi Negara. (2023). Peraturan Badan Siber dan Sandi Negara Nomor 8 Tahun 2023 tentang Kerangka Kerja Pelindungan Infrastruktur Informasi Vital. Jakarta. https://peraturan.bpk.go.id/Details/291265/peraturan-bssn-no-8-tahun-2023
Badan Siber dan Sandi Negara. (2023). Peraturan Badan Siber dan Sandi Negara Nomor 10 Tahun 2023 tentang Pengukuran Tingkat Kematangan Keamanan Siber. Jakarta. https://peraturan.bpk.go.id/Details/291280/peraturan-bssn-no-10-tahun-2023.
Badan Siber dan Sandi Negara. (2026). Lanskap keamanan siber Indonesia 2025. Jakarta. https://www.bssn.go.id/layanan/
Balafif, S. (2023). Penyesuaian model ketahanan siber UMKM di Indonesia dengan NIST cybersecurity framework (CSF). Jurnal Informatika: Jurnal Pengembangan IT, 8(3), 291-301. Retrieved from https://doi.org/10.30591/jpit.v8i3.5662
Bernardo, L., Malta, S., & Magalhães, J. (2025). An evaluation framework for cybersecurity maturity aligned with the NIST CSF. Electronics, 14, 1-20. https://doi.org/10.3390/electronics14071364.
Elo, S., & Kyngäs, H. (2008). The qualitative content analysis process. Journal of Advanced Nursing, 62(1), 107-115. https://doi.org/10.1111/j.1365-2648.2007.04569.x.
Ewoh, P., Vartiainen, T., & Mantere, T. (2025). Sociotechnical cybersecurity framework for securing health care from vulnerabilities and cyberattacks: Scoping review. Journal of Medical Internet Research, 27, e75584. Retrieved from https://doi.org/10.2196/75584
Hardiana, T., & Suhardi. (2025). Desain instrumen pengukuran tingkat kematangan keamanan siber sektor pemerintahan. Jurnal Pendidikan dan Teknologi Indonesia, 5(11), 3288-3305. https://doi.org/10.52436/1.jpti.1124
International Organization for Standardization & International Electrotechnical Commission. (2019). ISO/IEC 33020:2019 Information technology — Process assessment — Process measurement framework for assessment of process capability. Geneva, Switzerland. https://www.iso.org/standard/78526.html
International Organization for Standardization & International Electrotechnical Commission. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Geneva, Switzerland. https://www.iso.org/standard/27001
Irawan, H., Muhammad, A. H., & Nasiri, A. (2024). Design of cybersecurity maturity assessment framework using NIST CSF v1.1 and CIS Controls v8. Jurnal Inovtek Polbeng — Seri Informatika, 9, 126-139. DOI:10.35314/isi.v9i1.3973.
Jelita, L. D., Al Azam, M. N., & Nugroho, A. (2024). Evaluasi keamanan teknologi informasi menggunakan indeks keamanan informasi 5.0 dan ISO/IEC 27001:2022. Jurnal Saintekom, 14(1), 84-94. https://doi.org/10.33020/saintekom.v14i1.623.
Krippendorff, K. (2018). Content analysis: An introduction to its methodology (4th ed.). SAGE Publications. https://methods.sagepub.com/book/mono/content-analysis-4e/toc#_
Kurii, Y., & Opirskyy, I. (2022). Analysis and comparison of the NIST SP 800-53 and ISO/IEC 27001:2013. CEUR Workshop Proceedings, 3288, pp. 21-32. https://ceur-ws.org/Vol-3288/paper3.pdf.
Leavitt, H. J. (1965). Applied organizational change in industry: Structural, technological and humanistic approaches. Rand McNally. https://openlibrary.org/books/OL19794500M/Applied_organizational_change_in_industry.
NIST. (2024). The NIST cybersecurity framework (CSF) 2.0. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29
Presiden Republik Indonesia. (2022). Peraturan Presiden Nomor 82 Tahun 2022 tentang Pelindungan Infrastruktur Informasi Vital. Jakarta. https://peraturan.bpk.go.id/Details/211029/perpres-no-
Salam, M., Bakar, K. A., & Aman, A. H. (2025). Building cyber-resilient universities: A tailored maturity model for strengthening cybersecurity in higher education. International Journal of Advanced Computer Science and Applications, 16, 95-104. https://doi.org/10.14569/IJACSA.2025.0160510.
Salas-Riega, J. L., Viru, Y. R., Soto, M. N., & Salas-Riega, J. M. (2025). Cybersecurity and the NIST framework: A systematic review of its implementation and effectiveness against cyber threats. International Journal of Advanced Computer Science and Applications, 16, 723-735. https://doi.org/10.14569/IJACSA.2025.0160672.
Supriyanto, A., Jananto, A., Razaq, J. A., Hartono, B., & Damaryanti, F. (2025). Alignment of KAMI index with global security standards in information security risk maturity evaluation. Cybernetics and Information Technologies, 25(2), 173-192. Retrieved from https://doi.org/10.2478/cait-2025-0018
Trist, E. L., & Bamforth, K. W. (1951). Some social and psychological consequences of the longwall method of coal-getting. Human Relations, 4(1), 3-38. Retrieved from https://doi.org/10.1177/001872675100400101
United Nations Conference on Trade and Development. (2021). Digital economy report 2021: Cross-border data flows and development. United Nations. https://unctad.org/system/files/official-document/der2021_en.pdf.
Vestad, A., & Yang, B. (2025). From security frameworks to sustainable municipal cybersecurity capabilities. Journal of Cybersecurity and Privacy, 5, 1-28. https://doi.org/10.3390/jcp5020019.
Wani, T. A., Mendoza, A., & Gray, K. (2025). A sociotechnical approach to bring-your-own-device security in hospitals: Development and pilot testing of a maturity model using mixed methods action research. JMIR Human Factors, 12, e71912. Retrieved from https://doi.org/10.2196/71912
Wibawa, I. A., Susila, A. A., & Pasirullah, M. A. (2024). Information security evaluation at hospital using index KAMI 5.0 and recommendations based on ISO/IEC 27001:2022. Journal of Information Systems and Informatics, 6(4), 3070-3086. https://doi.org/10.51519/journalisi.v6i4.949
Zakiy, F. W., & Angresti, N. D. (2024). Comparative analysis of cybersecurity maturity frameworks: NIST-CSF and C2M2. JOISTECH: Journal of Information System and Technology, 1, 82-87. https://ejournal.darunnajah.ac.id/index.php/joistech/article/view/317.
Bila bermanfaat silahkan share artikel ini
Berikan Komentar Anda terhadap artikel Model Konseptual Penguatan Instrumen Penilaian Kematangan Keamanan Siber (IKAS) menggunakan Pendekatan Sosioteknis melalui Pemetaan Keselarasan terhadap NIST CSF 2.0 dan ISO/IEC 27001:2022
Pages: 1413-1424
Copyright (c) 2026 Muhammad Arif Ali Wasi, Agung Budi Susanto, Winarni Winarni

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under Creative Commons Attribution 4.0 International License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (Refer to The Effect of Open Access).













