Evaluasi Tata Kelola Teknologi Informasi pada Bank PT BPR NTB Persero dengan Menggunakan COBIT 5 dan ISO/IEC 27001
Main Article Content
Abstract
Article Summary
The advancement of Information Technology (IT) has driven the use of cloud-based core banking systems as the primary infrastructure in banking operations. PT Bank BPR NTB Perseroda's reliance on this system necessitates IT governance that ensures service availability, system reliability, and information security. Observations and interviews reveal issues such as cloud service network disruptions, power supply interruptions, and potential cybersecurity threats impacting the timeliness of credit processes and customer transactions. This study aims to evaluate the effectiveness of IT governance using COBIT 5 and identify the implementation of information security controls based on ISO/IEC 27001:2022. The COBIT 5 domains utilized include EDM01, APO12, DSS01, and MEA03, while the ISO/IEC 27001:2022 controls encompass A.5.1, A.5.23, and A.5.30. A mixed methods approach was employed through interviews, observations, document studies, and questionnaires involving 32 respondents. Data analysis was conducted using the Process Assessment Model (PAM) of COBIT 5. The results indicate average capability levels ranging from 3.30 to 3.38, suggesting that governance processes have been implemented but that risk management and operational monitoring require enhancement. This study concludes that the integration of COBIT 5 and ISO/IEC 27001:2022 provides a comprehensive evaluation of governance and information security.
Keywords
Article Keywords
Downloads
Article Details

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Amiryan Ahadis, M. R., Nama, G. F., Annisa, R., & M. A. M. (2025). Audit tata kelola teknologi informasi menggunakan framework COBIT 5 pada PT Bank Rakyat Indonesia Unit 1 Pringsewu. Jurnal Informatika Dan Teknik Elektro Terapan, 13(2), 1454–1462. https://doi.org/10.23960/jitet.v13i2.6477
Forester, B. J., Idris, A., Khater, A., Afgani, M. W., Isnaini, M., Islam, U., Raden, N., & Palembang, F. (2024). Penelitian kuantitatif: Uji reliabilitas. Quantitative Research: Data Reliability Test, 4(3), 1812–1820.
Frangky, & Sinaga, R. (2024). Penerapan ISO/IEC 27001:2022 dalam tata kelola keamanan sistem informasi: Evaluasi proses dan kendala. Nuansa Informatika, 18(2), 46–54. https://doi.org/10.25134/ilkom.v18i2.205
Gade, U. R. (2025). Core banking system modernization (Retail banking). Sarcouncil Journal of Multidisciplinary, 5(9), 112–121.
Hanif, M. F., Harahap, A. R., Fakhrudin, A., Madina, F. F., & Febriawan, D. (2025). Integrating COBIT and ISO frameworks in IT audits: A literature review. International Journal of Emerging Research in Engineering, Science, and Management, 4(3), 8–14. https://doi.org/10.58482/ijeresm.v4i3.2
Hidayah, N., Amanda, A., & Az-Jahra, S. (2024). Menelaah tantangan bank syariah dalam menghadapi perkembangan di era digital. Journal of Waqf and Islamic Economic Philanthropy, 1(3), 1–8. https://doi.org/10.47134/wiep.v1i3.295
Kristen, U., & Wacana, S. (2025). Penerapan framework COBIT pada perbankan di Indonesia: Sebuah tinjauan literatur sistematis. 10(3), 2426–2434.
Lestari, P. S., Tambunan, F. Z., Nasution, A. W., Amelia, M., Lita, C., Panjaitan, P., & Sinaga, D. S. (2025). Implementasi ISO 27001 dalam meningkatkan kepercayaan pengguna dalam sektor industri. Jurnal Pengabdian Masyarakat Dan Riset Pendidikan, 4(1), 1152–1167.
Nawir, M., Ap, I., & Wajidi, F. (2022). Integrasi framework ISO 27001 dan COBIT 2019 pada keamanan informasi smart tourism PT. YoY Manajemen Internasional. J-ICON, 10(2), 122–128. https://doi.org/10.35508/jicon.v10i2.7985
Negeri, U., Thaha, S., Jambi, S., & Kuantitatif-kualitatif, P. (2024). Pendekatan penelitian kuantitatif dan kualitatif serta tahapan penelitian. 15(1), 82–92.
Prasetya, B., Mahardhika, D. P., & Usino, W. (2025). Analysis of the effect of system quality, information quality, and service quality on user satisfaction of T24 application (Temenos Transact core banking) with perceived usefulness as an intervening variable (case study: J Trust Bank Indonesia). Indonesian Interdisciplinary Journal of Sharia Economics (IIJSE), 8(3), 7453–7471.
Pratiwi, S. F., Zalukhu, L. A., Tesa, A. R., Aisyah, I. S., & Saputra, B. (2025). Implementasi digital pada tata kelola administrasi: Upaya meningkatkan mutu pelayanan di era birokrasi modern. 2(June), 38–44.
Pratiwi, Y., & Widianti, L. W. (2025). Implementasi tata kelola teknologi informasi menggunakan framework COBIT 5 pada salah satu bank milik BUMN. Jurnal Kecerdasan Buatan Dan Teknologi Informasi, 4(2), 98–113. https://doi.org/10.69916/jkbti.v4i2.281
Ramadhian, P. R., Dwiki, G., Aryono, P., & Masyhuri, M. (2025). Audit of the Srikandi information system at the Banten regional library and archives department using the COBIT 5 framework. 10(3), 1321–1330.
Tanjung, A. M., Lase, W. A., Zega, O., & Lafau, R. O. (2025). Keamanan siber dalam sistem informasi berbasis cloud: Tantangan dan solusi. 02, 127–133.
Yoga, T. P., Maharani, V., & Maulana, N. D. (2024). Audit keamanan sistem informasi puskesmas dengan standar ISO/IEC 27001:2013 dan framework COBIT 5. Nuansa Informatika, 18(1), 2614–5405. https://journal.fkom.uniku.ac.id/ilkom93
Zayrin, A. A., Nupus, H., Maizia, K. K., & Marsela, S. (2025). Analisis instrumen penelitian pendidikan (uji validitas dan reliabilitas instrumen penelitian). 780–789.