This study aims to information security in academic information systems to provide recommendations for improvements in information security management by the expected maturity level based on ISO/IEC 27002:2013. By using a qualitative descriptive approach, data collection and validation techniques with triangulation techniques are interviews, observation, and documentation. The data were analyzed by using gap analysis and to measure the maturity level determined 15 objective control and 45 security controls scattered in 5 clauses, the result of the research found that the performance of academic information system maturity level at level 2. That is, the current level of maturity is below the expected maturity level, so it needs to be increased to the expected level.
翻译:这项研究旨在学术信息系统的信息安全,根据ISO/IEC 27002:2013采用定性描述方法,用三角技术收集数据和验证技术是访谈、观察和文件,通过差距分析对数据进行分析,并衡量分散在5个条款中的15个客观控制和45个安全控制措施的成熟度,研究结果发现,学术信息系统第2级成熟度的绩效低于预期成熟度,即目前的成熟度低于预期成熟度,因此,需要将其提高到预期水平。