Model Konseptual Penguatan Instrumen Penilaian Kematangan Keamanan Siber (IKAS) menggunakan Pendekatan Sosioteknis melalui Pemetaan Keselarasan terhadap NIST CSF 2.0 dan ISO/IEC 27001:2022


  • Muhammad Arif Ali Wasi * Mail Universitas Pamulang, Tangerang Selatan, Indonesia
  • Agung Budi Susanto Universitas Pamulang, Tangerang Selatan, Indonesia
  • Winarni Winarni Universitas Pamulang, Tangerang Selatan, Indonesia
  • (*) Corresponding Author
Keywords: Cybersecurity Maturity; Gap Analysis; ISO/IEC 27001:2022; Leavitt's Diamond; NIST CSF 2.0; Sociotechnical

Abstract

The Cybersecurity Maturity Assessment Instrument (IKAS) underpins the protection roadmap of Vital Information Infrastructure in Indonesia, so any weakness in its design propagates directly into national policy. Its alignment with international frameworks and the balance of its sociotechnical composition, however, have never been examined academically. This study maps the alignment of IKAS version 1.2.1 against NIST CSF 2.0 and ISO/IEC 27001:2022 bidirectionally, diagnoses the gaps through Leavitt’s Diamond, and designs a conceptual strengthening model named IKAS-ST. A descriptive qualitative content analysis was applied to 181 IKAS items, 106 NIST CSF 2.0 subcategories, and 93 ISO/IEC 27001:2022 Annex A controls. The instrument proves substantially aligned, with an average forward coverage of 81.2% (Largely Achieved), yet 12 white spots remain, concentrated in the governance and recovery functions. The decisive finding is that Task is the only under-represented scope, with an extreme deficit in the Detection domain where items measure the ownership of detection technology rather than the procedures that operate it. The merit of IKAS-ST lies not in adding items but in three testable properties: every added item is traceable to an identified white spot, so no addition is speculative; the restructuring addresses the root cause, namely the absence of an explicit procedural scope; and all 181 original items are retained, preserving the comparability of historical assessment results. The model is conceptual and awaits expert validation and field testing.

Downloads

Download data is not yet available.

References

Ani, U. D., Watson, J. M., Tuptuk, N., Hailes, S., & Jawar, A. (2022). Socio-technical security modelling: Analysis of state-of-the-art, application, and maturity in critical industrial infrastructure environments/domains. PETRAS National Centre of Excellence in IoT Systems Cybersecurity. https://shura.shu.ac.uk/32206/1/2305.05108.pdf.

Apriany, A., & Wibowo, A. (2024). Analysis of the implementation of ISO 27001:2022 and KAMI index in enhancing the information security management system in consulting firms. Indonesian Journal of Computing and Cybernetics Systems, 18, 417-428. https://doi.org/10.22146/ijccs.100385.

Badan Siber dan Sandi Negara. (2023). Peraturan Badan Siber dan Sandi Negara Nomor 8 Tahun 2023 tentang Kerangka Kerja Pelindungan Infrastruktur Informasi Vital. Jakarta. https://peraturan.bpk.go.id/Details/291265/peraturan-bssn-no-8-tahun-2023

Badan Siber dan Sandi Negara. (2023). Peraturan Badan Siber dan Sandi Negara Nomor 10 Tahun 2023 tentang Pengukuran Tingkat Kematangan Keamanan Siber. Jakarta. https://peraturan.bpk.go.id/Details/291280/peraturan-bssn-no-10-tahun-2023.

Badan Siber dan Sandi Negara. (2026). Lanskap keamanan siber Indonesia 2025. Jakarta. https://www.bssn.go.id/layanan/

Balafif, S. (2023). Penyesuaian model ketahanan siber UMKM di Indonesia dengan NIST cybersecurity framework (CSF). Jurnal Informatika: Jurnal Pengembangan IT, 8(3), 291-301. Retrieved from https://doi.org/10.30591/jpit.v8i3.5662

Bernardo, L., Malta, S., & Magalhães, J. (2025). An evaluation framework for cybersecurity maturity aligned with the NIST CSF. Electronics, 14, 1-20. https://doi.org/10.3390/electronics14071364.

Elo, S., & Kyngäs, H. (2008). The qualitative content analysis process. Journal of Advanced Nursing, 62(1), 107-115. https://doi.org/10.1111/j.1365-2648.2007.04569.x.

Ewoh, P., Vartiainen, T., & Mantere, T. (2025). Sociotechnical cybersecurity framework for securing health care from vulnerabilities and cyberattacks: Scoping review. Journal of Medical Internet Research, 27, e75584. Retrieved from https://doi.org/10.2196/75584

Hardiana, T., & Suhardi. (2025). Desain instrumen pengukuran tingkat kematangan keamanan siber sektor pemerintahan. Jurnal Pendidikan dan Teknologi Indonesia, 5(11), 3288-3305. https://doi.org/10.52436/1.jpti.1124

International Organization for Standardization & International Electrotechnical Commission. (2019). ISO/IEC 33020:2019 Information technology — Process assessment — Process measurement framework for assessment of process capability. Geneva, Switzerland. https://www.iso.org/standard/78526.html

International Organization for Standardization & International Electrotechnical Commission. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Geneva, Switzerland. https://www.iso.org/standard/27001

Irawan, H., Muhammad, A. H., & Nasiri, A. (2024). Design of cybersecurity maturity assessment framework using NIST CSF v1.1 and CIS Controls v8. Jurnal Inovtek Polbeng — Seri Informatika, 9, 126-139. DOI:10.35314/isi.v9i1.3973.

Jelita, L. D., Al Azam, M. N., & Nugroho, A. (2024). Evaluasi keamanan teknologi informasi menggunakan indeks keamanan informasi 5.0 dan ISO/IEC 27001:2022. Jurnal Saintekom, 14(1), 84-94. https://doi.org/10.33020/saintekom.v14i1.623.

Krippendorff, K. (2018). Content analysis: An introduction to its methodology (4th ed.). SAGE Publications. https://methods.sagepub.com/book/mono/content-analysis-4e/toc#_

Kurii, Y., & Opirskyy, I. (2022). Analysis and comparison of the NIST SP 800-53 and ISO/IEC 27001:2013. CEUR Workshop Proceedings, 3288, pp. 21-32. https://ceur-ws.org/Vol-3288/paper3.pdf.

Leavitt, H. J. (1965). Applied organizational change in industry: Structural, technological and humanistic approaches. Rand McNally. https://openlibrary.org/books/OL19794500M/Applied_organizational_change_in_industry.

NIST. (2024). The NIST cybersecurity framework (CSF) 2.0. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29

Presiden Republik Indonesia. (2022). Peraturan Presiden Nomor 82 Tahun 2022 tentang Pelindungan Infrastruktur Informasi Vital. Jakarta. https://peraturan.bpk.go.id/Details/211029/perpres-no-

Salam, M., Bakar, K. A., & Aman, A. H. (2025). Building cyber-resilient universities: A tailored maturity model for strengthening cybersecurity in higher education. International Journal of Advanced Computer Science and Applications, 16, 95-104. https://doi.org/10.14569/IJACSA.2025.0160510.

Salas-Riega, J. L., Viru, Y. R., Soto, M. N., & Salas-Riega, J. M. (2025). Cybersecurity and the NIST framework: A systematic review of its implementation and effectiveness against cyber threats. International Journal of Advanced Computer Science and Applications, 16, 723-735. https://doi.org/10.14569/IJACSA.2025.0160672.

Supriyanto, A., Jananto, A., Razaq, J. A., Hartono, B., & Damaryanti, F. (2025). Alignment of KAMI index with global security standards in information security risk maturity evaluation. Cybernetics and Information Technologies, 25(2), 173-192. Retrieved from https://doi.org/10.2478/cait-2025-0018

Trist, E. L., & Bamforth, K. W. (1951). Some social and psychological consequences of the longwall method of coal-getting. Human Relations, 4(1), 3-38. Retrieved from https://doi.org/10.1177/001872675100400101

United Nations Conference on Trade and Development. (2021). Digital economy report 2021: Cross-border data flows and development. United Nations. https://unctad.org/system/files/official-document/der2021_en.pdf.

Vestad, A., & Yang, B. (2025). From security frameworks to sustainable municipal cybersecurity capabilities. Journal of Cybersecurity and Privacy, 5, 1-28. https://doi.org/10.3390/jcp5020019.

Wani, T. A., Mendoza, A., & Gray, K. (2025). A sociotechnical approach to bring-your-own-device security in hospitals: Development and pilot testing of a maturity model using mixed methods action research. JMIR Human Factors, 12, e71912. Retrieved from https://doi.org/10.2196/71912

Wibawa, I. A., Susila, A. A., & Pasirullah, M. A. (2024). Information security evaluation at hospital using index KAMI 5.0 and recommendations based on ISO/IEC 27001:2022. Journal of Information Systems and Informatics, 6(4), 3070-3086. https://doi.org/10.51519/journalisi.v6i4.949

Zakiy, F. W., & Angresti, N. D. (2024). Comparative analysis of cybersecurity maturity frameworks: NIST-CSF and C2M2. JOISTECH: Journal of Information System and Technology, 1, 82-87. https://ejournal.darunnajah.ac.id/index.php/joistech/article/view/317.


Bila bermanfaat silahkan share artikel ini

Berikan Komentar Anda terhadap artikel Model Konseptual Penguatan Instrumen Penilaian Kematangan Keamanan Siber (IKAS) menggunakan Pendekatan Sosioteknis melalui Pemetaan Keselarasan terhadap NIST CSF 2.0 dan ISO/IEC 27001:2022

Dimensions Badge
Article History
Published: 2026-08-23
Abstract View: 105 times
PDF Download: 65 times
Issue
Section
Articles