A Socio-Technical Assessment of Information Security Management Using KAMI Index, ISO/IEC 27001:2022, and User Awareness
DOI:
https://doi.org/10.63158/journalisi.v8i4.1746Keywords:
KAMI Index, ISO 27001:2022, IT Awareness, Socio-Technical System, ISMSAbstract
ISO/IEC 27001:2022 is one of the certifications for Information Security Management Systems (ISMS). The study employs a mixed descriptive approach, analyzing maturity using the KAMI Index 5.0, ISO/IEC 27001:2022 clause implementation as a gap assessment, and user awareness of the ISMS, examined through socio-technical system theory at a university in Semarang. The results reveal a gap between the two subsystems: the technical subsystem shows high overall readiness but is not fully optimal, with weaker domain in Personal Data Protection (level II). The KAMI Index places the university's overall maturity at level V, while the ISO/IEC 27001:2022 gap assessment shows several clauses still unimplemented. Meanwhile, the social subsystem for user awareness revealed that the ISMS was less than optimal according to user interviews, even though the test achieved a score of 81.2% and was rated Very Worthy. Suitable standard operating procedures (SOPs) were also found lacking for several clauses and indicators. Socio-technical systems theory emphasizes joint consideration of social and technical elements in designing and implementing complex organizational systems such as information security; applying it here shows both subsystems must be evaluated holistically rather than separately.
Downloads
References
[1] BSSN, “Lanskap Keamanan Siber Indonesia 2024,” BSSN, 2024.
[2] A. A. Ipungkarti, “Penerapan IT Security Awareness Standar Keamanan ISO 27001 di BPJS Ketenagakerjaan Kantor Cabang,” J. Media Infotama, vol. 19, no. 1, pp. 103–110, 2023, doi: 10.37676/jmi.v19i1.3481.
[3] Yurindra, Keamanan Sistem Informasi. Yogyakarta: Deepublish Publisher, 2014.
[4] IBISA, Keamanan Sistem Informasi. Yogyakarta: Penerbit Andi, 2011.
[5] ISO/IEC, “International Standard ISO 27001:2022,” 2022
[6] L. N. Amali, M. R. Katili, S. N. Lahay, and M. H. Koniyo, Audit of Information System. Banyumas: Arta Media Nusantara, 2023.
[7] E. Ceko, “A Quality Managerial Approach on The Relationship Between The Digital Development,” CIT Rev. J., vol. May, no. 2024, pp. 10–19, 2024, doi: 10.59380/crj.vi5.5106.
[8] B. Ahmedi and A. Ibrahimi, “Mastering Information Security Through Standard Implementation,” Int. J. Informatics Commun. Technol., vol. 13, no. 3, pp. 428–435, 2024, doi: 10.11591/ijict.v13i3.pp428-435.
[9] A. de F. Fernandes, F. C. Santiago de Brito, F. F. Priard, G. A. V. Matias, M. S. Goncalves, and R. G. B. Filho, “The ISO 27000 Family and its Applicability in LGPD Adaptation Projects for Small and Medium-Sized Enterprises,” in ICSEA 2021 : The Sixteenth International Conference on Software Engineering Advances, 2021, pp. 43–49.
[10] IKU, “Telkom University Raih Sertifikasi ISO 27001:2022 untuk Data Center dan LMS,” 2025.
[11] UMBY, “UMBY, Satu-satunya Perguruan Tinggi Tersertifikasi Keamanan Informasi,” 2024.
[12] F. Wijayanti, D. I. Sensuse, A. A. Putera, and A. Syahrizal, “Assessment of Information Security Management System: A Case Study of Data Recovery Center in Ministry XYZ,” in 2020 3rd International Conference on Computer and Informatics Engineering, IC2IE 2020, 2020, pp. 393–398. doi: 10.1109/IC2IE50715.2020.9274574.
[13] F. N. Shakti and A. N. Hidayanto, “Measurement of Employee Information Security Awareness: Case Study at Financial Institution,” JITK (Jurnal Ilmu Pengetah. dan Teknol. Komputer), vol. 9, no. 2, pp. 172–179, 2024, doi: 10.33480/jitk.v9i2.4163.
[14] R. Savitri and M. S. Hasibuan, “Information Security Measurement using KAMI Index at Metro City,” J. Appl. Data Sci., vol. 5, no. 1, pp. 33–45, 2024, doi: 10.47738/jads.v5i1.152.
[15] BSSN, “Indeks Keamanan Informasi (KAMI) versi 5.0,” 2023
[16] W. A. Prabowo, “Developing Compliant Audit Information System for Information Security Index: a Study on Enhancing Institutional and Organizational Audits Using Web-Based Technology and ISO 25010:2011 Total Quality of Use Evaluation,” Int. J. Informatics Vis., vol. 8, no. 1, pp. 343–351, 2024, doi: 10.62527/joiv.8.1.1845.
[17] T. T. Wulansari and D. Novandi, “Evaluation of Information Security Management Using the KAMI Index Framework,” in 2022 International Conference of Science and Information Technology in Smart Administration, ICSINTESA 2022, 2022, pp. 173–177. doi: 10.1109/ICSINTESA56431.2022.10041714.
[18] N. Elsayed, “Socio-technical risks of clinical speech-to-text systems: Transparency , privacy , and reliability challenges in AI-driven documentation Nelly Elsayed iD,” Int. J. Med. Inform., vol. 214, no. March, pp. 1–6, 2026, doi: 10.1016/j.ijmedinf.2026.106419.
[19] N. Ebert, T. Schaltegger, B. Ambuehl, L. Schöni, V. Zimmermann, and M. Knieps, “Learning from safety science: A way forward for studying cybersecurity incidents in organizations,” Comput. Secur., vol. 134, p. 103435, 2023, doi: 10.1016/j.cose.2023.103435.
[20] C. Münch, E. Marx, L. Benz, E. Hartmann, and M. Matzner, “Capabilities of digital servitization: Evidence from the socio-technical systems theory,” Technol. Forecast. Soc. Chang., vol. 176, no. December 2021, pp. 1–16, 2022, doi: 10.1016/j.techfore.2021.121361.
[21] Ø. Toftegaard, G. Grøtterud, and B. Hämmerli, “Operational Technology resilience in the 2023 draft delegated act on cybersecurity for the power sector—An EU policy process analysis,” Comput. Law Secur. Rev., vol. 54, no. August, pp. 1–12, 2024, doi: 10.1016/j.clsr.2024.106034.
[22] D. Hertati, I. Arundinasari, A. Faroqi, and V. I. Pertiwi, “Tata Kelola Sosio-Teknologi dalam Mempromosikan Transparansi Informasi Publik di Pemerintahan Daerah,” Cakrawala J. Litbang Kebijak., vol. 19, no. 2, pp. 201–215, 2025, doi: 10.32781/cakrawala.v19i2.889.
[23] R. Fadlika, Y. Ruldeviyani, Z. T. Butarbutar, R. A. Istiqomah, and A. A. Fariz, “Employee Information Security Awareness in the Power Generation Sector of PT ABC,” Int. J. Adv. Comput. Sci. Appl., vol. 14, no. 4, pp. 594–603, 2023, doi: 10.14569/IJACSA.2023.0140465.
[24] M. Suorsa and P. Helo, “Information Security Failures Identified and Measured – ISO/IEC 27001:2013 Controls Ranked Based on GDPR Penalty Case Analysis,” Inf. Secur. J. A Glob. Perspect., vol. 33, no. 3, pp. 285–306, 2024, doi: 10.1080/19393555.2023.2270984.
[25] B. Ahmedi and A. Ibrahimi, “Mastering information security through standard implementation,” Int. J. Informatics Commun. Technol., vol. 13, no. 3, pp. 428–435, 2024, doi: 10.11591/ijict.v13i3.pp428-435.
[26] A. Supriyanto, A. Jananto, J. A. Razaq, B. Hartono, and F. Damaryanti, “Alignment of KAMI Index with Global Security Standards in Information Security Risk Maturity Evaluation,” Cybern. Inf. Technol., vol. 25, no. 2, pp. 173–192, 2025, doi: 10.2478/cait-2025-0018.
[27] K. M. Sari, Y. Saintika, and W. A. Prabowo, “Penyusunan Manajemen Risiko Keamanan Informasi dengan Standar ISO 27001 Studi Kasus Institut Teknologi Telkom Purwokerto,” J. Sist. dan Teknol. Inf., vol. 10, no. 4, pp. 423–428, 2022, doi: 10.26418/justin.v10i4.48977.
[28] M. Carter, “ISO 27001 Toolkit,” ISO27k Forum, 2024. https://www.iso27001security.com/toolkit (accessed Oct. 25, 2025).
[29] IBISA, Komputer Audit dan Sekuriti. Yogyakarta: Penerbit Andi, 2023.
[30] A. M. S. Ø. Jakobsen and W. Vanhaverbeke, “A socio-technical perspective on product configuration systems: Insights from Grundfos,” Technol. Forecast. Soc. Chang., vol. 225, no. December 2025, pp. 1–19, 2026, doi: 10.1016/j.techfore.2026.124564.
[31] Sugiyono, Metode Penelitian Kuantitatif, Kualitatif, dan R&D. Yogyakarta: Alfabeta, 2019.
[32] N. W. Hidayatulloh and P. Dellia, “Evaluasi Sistem Informasi Terintegrasi Instagram dan WhatsApp Berdasarkan Pengujian ISO 25010,” JSI J. Sist. Inf., vol. 15, no. 2, pp. 3330–3342, 2023, doi: 10.18495/jsi.v15i2.134.
[33] P. Dellia, S. D. Saputro, R. Faisal, L. Rosidah, and N. W. Hidayatulloh, “Kualitas Perpustakaan Berdasarkan ISO 25010,” J. Teknol. dan Inf., vol. 15, no. 1, pp. 54–65, 2025, doi: 10.34010/jati.v15i1.15092.
[34] H. Setiawan and H. Jati, “Analisis Kualitas Sistem Informasi Pantauan Pembentukan Karakter Siswa di SMKN 2 Depok Sleman,” Elinvo (Electronics, Informatics, Vocat. Educ., vol. 2, no. 1, pp. 102–109, 2017, doi: 10.21831/elinvo.v2i1.16427.
[35] R. E. Indrajit, “Kebijakan Keamanan Informasi,” Universitas Telkom, 2021.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Information Systems and Informatics

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors Declaration
- The Authors certify that they have read, understood, and agreed to the Journal of Information Systems and Informatics (JournalISI) submission guidelines, policies, and submission declaration. The submission has been prepared using the provided template.
- The Authors certify that all authors have approved the publication of this manuscript and that there is no conflict of interest.
- The Authors confirm that the manuscript is their original work, has not received prior publication, is not under consideration for publication elsewhere, and has not been previously published.
- The Authors confirm that all authors listed on the title page have contributed significantly to the work, have read the manuscript, attest to the validity and legitimacy of the data and its interpretation, and agree to its submission.
- The Authors confirm that the manuscript is not copied from or plagiarized from any other published work.
- The Authors declare that the manuscript will not be submitted for publication in any other journal or magazine until a decision is made by the journal editors.
- If the manuscript is finally accepted for publication, the Authors confirm that they will either proceed with publication immediately or withdraw the manuscript in accordance with the journal’s withdrawal policies.
- The Authors agree that, upon publication of the manuscript in this journal, they transfer copyright or assign exclusive rights to the publisher, including commercial rights














