Vol. 6 No. 3 (2026) Articles
Open Access

Evaluasi Tata Kelola Teknologi Informasi pada Bank PT BPR NTB Persero dengan Menggunakan COBIT 5 dan ISO/IEC 27001

Gina Mahligai Putri
Universitas Bumigora
Khairan Marzuki
Universitas Bumigora
Andi Sofyan Anas
Universitas Bumigora
Ondi Asroni
Universitas Bumigora
Wisnu Alfiansyah
Published: August 28, 2026 Pages: 205-217
Original Full-Text Article
Download published version for reading and archiving
Abstract

The advancement of Information Technology (IT) has driven the use of cloud-based core banking systems as the primary infrastructure in banking operations. PT Bank BPR NTB Perseroda's reliance on this system necessitates IT governance that ensures service availability, system reliability, and information security. Observations and interviews reveal issues such as cloud service network disruptions, power supply interruptions, and potential cybersecurity threats impacting the timeliness of credit processes and customer transactions. This study aims to evaluate the effectiveness of IT governance using COBIT 5 and identify the implementation of information security controls based on ISO/IEC 27001:2022. The COBIT 5 domains utilized include EDM01, APO12, DSS01, and MEA03, while the ISO/IEC 27001:2022 controls encompass A.5.1, A.5.23, and A.5.30. A mixed methods approach was employed through interviews, observations, document studies, and questionnaires involving 32 respondents. Data analysis was conducted using the Process Assessment Model (PAM) of COBIT 5. The results indicate average capability levels ranging from 3.30 to 3.38, suggesting that governance processes have been implemented but that risk management and operational monitoring require enhancement. This study concludes that the integration of COBIT 5 and ISO/IEC 27001:2022 provides a comprehensive evaluation of governance and information security.

Article Metrics & Downloads Graph
Monthly Download Trends:
Author Biographies
Gina Mahligai Putri Universitas Bumigora

Program Studi Teknologi Informasi, Fakultas Teknik, Universitas Bumigora, Kota Mataram, Nusa Tenggara Barat, Indonesia.

Khairan Marzuki Universitas Bumigora

Program Studi Teknologi Informasi, Fakultas Teknik, Universitas Bumigora, Kota Mataram, Nusa Tenggara Barat, Indonesia.

Andi Sofyan Anas Universitas Bumigora

Program Studi Teknologi Informasi, Fakultas Teknik, Universitas Bumigora, Kota Mataram, Nusa Tenggara Barat, Indonesia.

Ondi Asroni Universitas Bumigora

Program Studi Teknologi Informasi, Fakultas Teknik, Universitas Bumigora, Kota Mataram, Nusa Tenggara Barat, Indonesia.

Wisnu Alfiansyah

Program Studi Teknologi Informasi, Fakultas Teknik, Universitas Bumigora, Kota Mataram, Nusa Tenggara Barat, Indonesia.

How to Cite
Putri, G. M., Marzuki, K., Anas, A. S., Asroni, O., & Alfiansyah, W. (2026). Evaluasi Tata Kelola Teknologi Informasi pada Bank PT BPR NTB Persero dengan Menggunakan COBIT 5 dan ISO/IEC 27001. Jurnal Sistem Komputer (SISKOM), 6(3), 205-217. https://doi.org/10.63447/siskom.v6i3.1973
License

Creative Commons Attribution 4.0 International License (CC BY 4.0)

This is an open-access article distributed under the terms of the Creative Commons Attribution 4.0 International License .

  • Share: You are free to copy, distribute, and transmit the work in any medium or format.
  • Adapt: You are free to remix, transform, and build upon the work for any purpose, even commercially.
  • Attribution: You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
Copyright & Retention: Authors retain copyright without restrictions and grant this journal the right of first publication under an open-access model. The journal retains non-exclusive publishing rights for archiving, indexing, and scholarly dissemination.

References
Total: 18 References
  1. Agselmora, D. I., & Utomo, A. P. (2022). Audit teknologi informasi menggunakan COBIT 5 domain DSS pada Universitas Stikubank Semarang. Jurnal Teknik Informatika Dan Sistem Informasi, 9(4), 2804–2814. http://jurnal.
  2. Amiryan Ahadis, M. R., Nama, G. F., Annisa, R., & M. A. M. (2025). Audit tata kelola teknologi informasi menggunakan framework COBIT 5 pada PT Bank Rakyat Indonesia Unit 1 Pringsewu. Jurnal Informatika Dan Teknik Elektro Terapan, 13(2), 1454–1462. https://doi.org/10.23960/jitet.v13i2.6477
  3. Forester, B. J., Idris, A., Khater, A., Afgani, M. W., Isnaini, M., Islam, U., Raden, N., & Palembang, F. (2024). Penelitian kuantitatif: Uji reliabilitas. Quantitative Research: Data Reliability Test, 4(3), 1812–1820.
  4. Frangky, & Sinaga, R. (2024). Penerapan ISO/IEC 27001:2022 dalam tata kelola keamanan sistem informasi: Evaluasi proses dan kendala. Nuansa Informatika, 18(2), 46–54. https://doi.org/10.25134/ilkom.v18i2.205
  5. Gade, U. R. (2025). Core banking system modernization (Retail banking). Sarcouncil Journal of Multidisciplinary, 5(9), 112–121.
  1. Hanif, M. F., Harahap, A. R., Fakhrudin, A., Madina, F. F., & Febriawan, D. (2025). Integrating COBIT and ISO frameworks in IT audits: A literature review. International Journal of Emerging Research in Engineering, Science, and Management, 4(3), 8–14. https://doi.org/10.58482/ijeresm.v4i3.2
  2. Hidayah, N., Amanda, A., & Az-Jahra, S. (2024). Menelaah tantangan bank syariah dalam menghadapi perkembangan di era digital. Journal of Waqf and Islamic Economic Philanthropy, 1(3), 1–8. https://doi.org/10.47134/wiep.v1i3.295
  3. Kristen, U., & Wacana, S. (2025). Penerapan framework COBIT pada perbankan di Indonesia: Sebuah tinjauan literatur sistematis. 10(3), 2426–2434.
  4. Lestari, P. S., Tambunan, F. Z., Nasution, A. W., Amelia, M., Lita, C., Panjaitan, P., & Sinaga, D. S. (2025). Implementasi ISO 27001 dalam meningkatkan kepercayaan pengguna dalam sektor industri. Jurnal Pengabdian Masyarakat Dan Riset Pendidikan, 4(1), 1152–1167.
  5. Nawir, M., Ap, I., & Wajidi, F. (2022). Integrasi framework ISO 27001 dan COBIT 2019 pada keamanan informasi smart tourism PT. YoY Manajemen Internasional. J-ICON, 10(2), 122–128. https://doi.org/10.35508/jicon.v10i2.7985
  6. Negeri, U., Thaha, S., Jambi, S., & Kuantitatif-kualitatif, P. (2024). Pendekatan penelitian kuantitatif dan kualitatif serta tahapan penelitian. 15(1), 82–92.
  7. Prasetya, B., Mahardhika, D. P., & Usino, W. (2025). Analysis of the effect of system quality, information quality, and service quality on user satisfaction of T24 application (Temenos Transact core banking) with perceived usefulness as an intervening variable (case study: J Trust Bank Indonesia). Indonesian Interdisciplinary Journal of Sharia Economics (IIJSE), 8(3), 7453–7471.
  8. Pratiwi, S. F., Zalukhu, L. A., Tesa, A. R., Aisyah, I. S., & Saputra, B. (2025). Implementasi digital pada tata kelola administrasi: Upaya meningkatkan mutu pelayanan di era birokrasi modern. 2(June), 38–44.
  9. Pratiwi, Y., & Widianti, L. W. (2025). Implementasi tata kelola teknologi informasi menggunakan framework COBIT 5 pada salah satu bank milik BUMN. Jurnal Kecerdasan Buatan Dan Teknologi Informasi, 4(2), 98–113. https://doi.org/10.69916/jkbti.v4i2.281
  10. Ramadhian, P. R., Dwiki, G., Aryono, P., & Masyhuri, M. (2025). Audit of the Srikandi information system at the Banten regional library and archives department using the COBIT 5 framework. 10(3), 1321–1330.
  11. Tanjung, A. M., Lase, W. A., Zega, O., & Lafau, R. O. (2025). Keamanan siber dalam sistem informasi berbasis cloud: Tantangan dan solusi. 02, 127–133.
  12. Yoga, T. P., Maharani, V., & Maulana, N. D. (2024). Audit keamanan sistem informasi puskesmas dengan standar ISO/IEC 27001:2013 dan framework COBIT 5. Nuansa Informatika, 18(1), 2614–5405. https://journal.fkom.uniku.ac.id/ilkom93
  13. Zayrin, A. A., Nupus, H., Maizia, K. K., & Marsela, S. (2025). Analisis instrumen penelitian pendidikan (uji validitas dan reliabilitas instrumen penelitian). 780–789.
Most read articles by the same author(s)

Other papers published by author(s) in this journal:

Evaluasi Manajemen Layanan Teknologi Informasi Berdsarkan ISO/IEC 20000-1 dengan Rekomendasi Perbaikan Berbasis ITIL V4 pada Instansi Pemerintah
Perancangan Blueprint Arsitektur Perusahaan Layanan LKP ITEC Mataram Menggunakan Kerangka Zachman dan ITIL V4