Accelerate Literature Icon
Want to do a literature review? Try our new Literature Review workflow

Assessing Information Security Readiness in Indonesian Fintech Companies Using KAMI Index 5.0 Framework

  • Abstract
  • Literature Map
  • Similar Papers
Abstract
Translate article icon Translate Article Star icon

The development of Indonesian financial technology (fintech) has transformed the financial industry paradigm but has also introduced significant information security risks, particularly for technology-based companies. The fintech companies should establish IT governance through an Information Security Management System (ISMS) which adheres to international standards, ensuring the confidentiality, integrity, and availability of information. This work adopts a qualitative approach deploying observations, interviews, and literature reviews on Indonesian fintech companies, especially digital banking fields, payment gateways, and digital wallet platforms. This study is to identify information security risks and assess the readiness and feasibility of implementing ISO/IEC 27001:2022 using the KAMI Index 5.0, which evaluates domains such as policy, governance, risk management, access control, incident management, asset management, and personal data protection. The research findings indicate that the electronic system of fintech companies plays a strategic role in supporting sustainability and business growth, with an implementation score of 809 and a fairly good level of information security feasibility. In conclusion, this reflects the company’s readiness for further information security implementation. The system not only supports basic operations but also serves as a key element in achieving business objectives, both internally and externally, including regulators, banking partners, and customers.

Similar Papers
  • Conference Article
  • 10.5339/qfarc.2016.ictpp2531
Enhancing Information Security Process in Organisations in Qatar
  • Jan 1, 2016
  • Aisha Khalid Al-Hamar

Due to the universal use of technology and its pervasive connection to the world, organisations have become more exposed to frequent and various threats (Rotvold, 2008).Therefore, organisations today are giving more attention to information security as it has become a vital and challenging issue. Mackay (2013) noted that the significance of information security, particularly information security policies and awareness, is growing due to the increasing use of IT and computerization. Accordingly, information security presents a key role in the internet era of technology. Gordon & Loep (2006) stated that information security involves a group of actions intended to protect information and information systems. It involves software, hardware, physical security and human factors, where each element has its own features. Information security not only secures the organisation's security but the complete infrastructure that enables the information's use. Organisations are facing an increase in daily security breach...

  • Conference Article
  • 10.21125/edulearn.2019.0639
A NEW APPROACH FOR IMPLEMENTATION THE EU NIS DIRECTIVE IN ROMANIAN INSTITUTIONS – INFORMATION SECURITY MANAGER TRAINING PROGRAM
  • Jul 1, 2019
  • EDULEARN proceedings
  • Adriana-Meda Udroiu

A NEW APPROACH FOR IMPLEMENTATION THE EU NIS DIRECTIVE IN ROMANIAN INSTITUTIONS – INFORMATION SECURITY MANAGER TRAINING PROGRAM

  • Research Article
  • Cite Count Icon 1
  • 10.3103/s014768822004005x
The Validity of Information Security Risk Assessment Methods for Organizations
  • Oct 1, 2020
  • Scientific and Technical Information Processing
  • L V Astakhova

Based on statistical data, a contradiction is shown between an increase in financial investments in the information security (IS) of organizations and a steady increase in the number of IS incidents caused by internal users. A conclusion is made about the cognitive vulnerability and low degree of validity of modern IS risk assessment methods. Stereotypes have been identified, the result of which are cognitive errors in assessing IS risks: the priority of technical protection of information from external threats of IS over organizational and technical protection from internal threats; distrust of the internal client, perception of it exclusively as an object of tough managerial influence, ignoring its subjective role in IS management; restriction of work with personnel within the IS management system with one-time measures and static criteria for assessing human risks and inattention to systemic measures and dynamic, situational criteria. The necessity of updating standards for IS risk management, as well as the development of new methods and tools for assessing, IS risks based on rejecting outdated stereotypes, is substantiated.

  • PDF Download Icon
  • Research Article
  • 10.20535/2411-1031.2020.8.2.222610
Interpretation model of assessments boundary information security risks
  • Dec 30, 2020
  • Collection "Information Technology and Security"
  • Vitalii Bezshtanko + 1 more

Amendments to the legislation of Ukraine allow building, implementing, and conducting certifications of information protection systems owned by the state, or the requirements for the protection of which are established by law. It is recommended to use the requirements and/or guidelines of international practices that provide for the use of a risk-oriented approach. Thus, the international standard ISO/IES 27001 implemented in Ukraine recommends choosing or developing a method for assessing information security risks. At the same time, the results of the analysis of open sources revealed the absence of models and methods for quantifying their limit values. By informational, we mean the risks associated with the possibility of losses as a result due to violations of the properties of confidentiality, integrity, availability of information. Therefore, the purpose of this article is to develop an interpretive model that will provide the limit values of information security risks. Their quantitative values could be used as criteria at the stage of formation requirements for a comprehensive information security system and / or information security management system. The basis for calculating the value of the risk limit value is the standard deviation of the uncollected profit for the period. If the profit exceeds the planned, then hypothetically during the analysis period there were no incidents that would affect resources. Information risks are a component of the organization's risks. According to the recommendations of ISO/IES 27005, where risk is the effect of uncertainty on the achievement of goals, and the effect is a positive or negative deviation from the expected, the hypothetically obtained standard deviation can be considered an assessment of the impact of information uncertainty of additive information resources on economic results. In addition, assessing the acceptable threshold of information risk of the organization. Thus, an interpretive model for estimating the marginal risks of information security and allowable losses on individual components of threats to the information properties as a formalization of the impact of information uncertainty on financial consequences. This made it possible to quantify these estimates based on available actual economic / cost indicators of information activity in the organization.

  • Research Article
  • Cite Count Icon 30
  • 10.4258/hir.2010.16.2.89
Analysis of Information Security Management Systems at 5 Domestic Hospitals with More than 500 Beds
  • Jun 1, 2010
  • Healthcare Informatics Research
  • Woo-Sung Park + 8 more

ObjectivesThe information security management systems (ISMS) of 5 hospitals with more than 500 beds were evaluated with regards to the level of information security, management, and physical and technical aspects so that we might make recommendations on information security and security countermeasures which meet both international standards and the needs of individual hospitals.MethodsThe ISMS check-list derived from international/domestic standards was distributed to each hospital to complete and the staff of each hospital was interviewed. Information Security Indicator and Information Security Values were used to estimate the present security levels and evaluate the application of each hospital's current system.ResultsWith regard to the moderate clause of the ISMS, the hospitals were determined to be in compliance. The most vulnerable clause was asset management, in particular, information asset classification guidelines. The clauses of information security incident management and business continuity management were deemed necessary for the establishment of successful ISMS.ConclusionsThe level of current ISMS in the hospitals evaluated was determined to be insufficient. Establishment of adequate ISMS is necessary to ensure patient privacy and the safe use of medical records for various purposes. Implementation of ISMS which meet international standards with a long-term and comprehensive perspective is of prime importance. To reflect the requirements of the varied interests of medical staff, consumers, and institutions, the establishment of political support is essential to create suitable hospital ISMS.

  • PDF Download Icon
  • Research Article
  • Cite Count Icon 13
  • 10.21686/1818-4243-2018-2-61-70
Calculation of risks of information security of telecommunication enterprise
  • May 7, 2018
  • Open Education
  • L M Il’Chenko + 3 more

The goal of this work is to identify and assess information security risks for a typical distributed information system within three controlled areas. The main emphasis, application of information security in the considered information system is done to minimize damage from security threats, aimed at the integrity and availability of the hardware and software complex of the information system, and not to the confidentiality of information resources processed with their help. The study examined international and national standards in the field of information security, which regulate issues of information security risks management. In particular, the basic requirements for the assessment and processing of information security risks were established, based on the international standard “ISO 27001: 2013 Information technologies. Methods of protection. Information security management systems”, as well as a comparison of this standard with its version from 2005 is made. As a leading method of risk assessment and processing, the most economical the qualitative method was chosen, in the absence of ready data on the number of attacks implemented in the considered information system for a certain period of time. In the process, valuable assets of the organization were considered, and based on the business process of the telecommunication company, major and minor assets were allocated, as well as the corresponding information security threats in accordance with the security threat data bank of the Federal Service for Technical and Export Control. The result of this work was the calculation of information security risks, based on the allocation of valuable assets of the organization, the degree of potential damage in the implementation of threats to such assets and the probability of the implementation of threats to the information system of the telecommunication enterprise. In addition, acceptable risks were identified, the processing of which is not required due to the fact that the actual cost of minimizing them is greater than the losses from the implementation of threats over them. In conclusion, possible measures were proposed to minimize information security risks, including a backup system, a system for protecting against unauthorized access, an anti-virus protection system, firewalling, and organizational measures and physical protection measures. The proposed method makes it possible to reasonably assess information security risks of an organization in conditions of insufficient initial data, as well as the absence of additional hardware and software for assessing information security risks, which allows applying it to model organizations based only on scaling of the considered system, if there is no state information secret in the processed data. The risk management procedure helps not only to identify and eliminate the analysis of vulnerabilities and innovations in the field of risk assessment, but also to increase the literacy level of staff, involved in the assessment and risk management process.

  • Conference Article
  • Cite Count Icon 2
  • 10.1109/sai.2017.8252214
E-discovery as a mean to improve information security
  • Jul 1, 2017
  • Michel Gomes Nogueira + 3 more

This article deals with the use of the e- discovery process to verify the electronic discoveries that can show a likely information security failure, possibly generating financial/economic losses and / or damage to the organization's image. This article proposes the use of the Electronic Discovery Reference Model of the e-discovery process as a mean prioritizing the implementation and improvement of an organization's Information Security. Such approach can help both the e-discovery readiness as well as the improvement of Information and Communications Security System. As a consequence, the sustainability of Governance of Information Technology is also improved. The reverse is also true: Improvements on the Information Security Management Systems and Polices also reflect positively on the e-discovery processes.

  • Research Article
  • Cite Count Icon 5
  • 10.2478/picbe-2018-0043
Considerations on the implementation steps for an information security management system
  • May 1, 2018
  • Proceedings of the International Conference on Business Excellence
  • Răzvan Cristian Ionescu + 2 more

News about various information security attacks against companies appears almost every day. The sources of these attacks vary from cyber-criminals who want to steal companies’ data to demand a ransom, to current or former employees who want to create damage to the organization. The best way to defend organizational critical assets is to implement an Information Security Management System that secures all sensitive assets from confidentiality, availability and integrity perspective. An Information Security Management System offers top management a framework for sensitive information flow control. This framework includes with a risk assessment that considers the security threats and vulnerabilities of the company’s assets. Companies usually implement Information Security Management System only after they have a functional quality management system, which brings clarity and optimization to the company’s processes. Current approaches on creation and implementation of effective Information Security Management System are very theoretical and thus difficult to use in practice. The main objective of this paper is to present an Information Security Management System implementation method in the case of a small company by defining the basic steps in achieving a fully functional Information Security Management System. The proposed methodology considers the top management Information Security Management System objectives, organizational context, risks assessment and third parties expectations fulfillment.

  • Research Article
  • 10.36002/jutik.v9i2.2304
EVALUASI KEAMANAN SISTEM PEMERINTAHAN BERBASIS ELEKTRONIK DI KOTA XYZ
  • Jan 25, 2023
  • Jurnal Teknologi Informasi dan Komputer
  • I Gede Putu Krisna Juliharta + 2 more

The Electronic-Based Government System (SPBE) is a form of E-Government implementation in Indonesia which is expected to be able to harmonize information technology and government administration. XYZ City as an area that has implemented SPBE, has evaluated the SPBE in 2021. Based on this evaluation, XYZ City Government received a score of 3.19 (good). However, if we look at the details of the audit results, SPBE Management Domain gets the lowest score. This domain has a key role, because in that domain there are indicators related to information security which should have a high value because it is related to information security in the regions that administer the SPBE. This study evaluates or re-audits the implementation of SPBE in the XYZ City Government, especially in the implementation of information security. The evaluation method is carried out using the Information Security Management System (ISMS) standard through the Indeks KAMI combined with COBIT 5 APO13 Manage Security to obtain the maturity level of information security. Based on the reassessment, it was found that the SPBE of the XYZ City Government was at a value of 3.17 (good), with the maturity level value being at level 1 (stub). Keywords: E-Government, SPBE, Audit, Information Security, ISMS, Indeks KAMI, COBIT 5 APO13. ABSTRAK Sistem Pemerintahan Berbasis Elektronik (SPBE) adalah bentuk penyelenggaraan EGovernment di Indonesia yang diharapkan mampu menyelaraskan teknologi informasi dan penyelenggaraan pemerintahan. Kota XYZ sebagai daerah yang telah menerapkan SPBE, telah melakukan evaluasi terhadap SPBE pada tahun 2021. Berdasarkan evaluasi tersebut, Pemerintah Kota XYZ mendapatkan nilai 3,19 (baik). Namun, jika melihat secara rinci mengenai hasil audit tersebut, Domain Manajemen SPBE mendapat nilai terendah. Domain ini memiliki peran kunci, karena pada domain tersebut terdapat indikator-indikator terkait dengan keamanan informasi yang seharusnya memiliki nilai tinggi karena terkait dengan keamanan informasi pada daerah yang penyelenggara SPBE. Penelitian ini melakukan evaluasi atau audit kembali terhadap penerapan SPBE pada Pemerintah Kota XYZ, khususnya dalam penyelenggaraan keamanan informasi. Metode evaluasi dilakukan dengan menggunakan standar Sistem Manajemen Keamanan Informasi (SMKI) melalui Indeks KAMI yang dipadukan dengan COBIT 5 APO13 Manage Security untuk mendapatkan tingkat kematangan keamanan informasi. Berdasarkan penilaian ulang didapatkan bahwa SPBE Pemerintah Kota XYZ berada pada nilai 3,17 (baik), dengan nilai tingkat kematangan berada pada level 1 (rintisan). Kata Kunci : E-Government, SPBE, Audit, Keamanan Informasi, SMKI, Indeks KAMI, COBIT 5 APO13.

  • Research Article
  • Cite Count Icon 3
  • 10.14419/ijet.v7i4.35.22907
The Role of Organizational Factors to the Effectiveness of ISMS Implementation in Malaysian Public Sector
  • Nov 30, 2018
  • International Journal of Engineering & Technology
  • Noralinawati Ibrahim + 1 more

Many organizations have initiated efforts to manage the security of their information by implementing an Information Security Management System (ISMS). ISMS is a set of guiding principles for managing organization’s confidential information and minimizing risk for business continuity. However, information security remains a major challenge and the effectiveness of ISMS is often argued due to the exposure of organizations to information security threats, incidents, risks, and vulnerabilities. One of the reasons is the unsuccessful ISMS current practices amongst all employees and lack of ISMS awareness in organizations. Several critical success factors are identified from previous studies that lead to the ISMS success. Among the success factors are human, organizational and technical factors. This study explores the factors that contribute to the success of ISMS and identify the organizational factors that relate to the information security effectiveness. The conceptual model is developed and will be tested within the Malaysian Public Sectors (MPS) organizations to provide a preliminary insight, understanding, and clarification of the organizational factors, together with the significant effects on ISMS effectiveness. This study used a quantitative approach and data collected from personnel’s that were directly involved with the ISMS implementation through a questionnaire survey.

  • Research Article
  • Cite Count Icon 1
  • 10.37405/1729-7206.2023.1(44).45-49
Peculiarities of the Functional Approach to the Management of Information Security of Enterprises in Crisis Conditions
  • Jan 1, 2023
  • Herald of the Economic Sciences of Ukraine
  • K S Ozarko + 1 more

The paper identifies the relevance of the problem under study with regard to the development of information security management systems for enterprises and organizations. This issue is of particular importance in the context of economic crisis. With the active development of the latest information and communication technologies, general computerization, information security is becoming a key characteristic of enterprise information systems The problems of using a functional approach in the formation of information security management systems for enterprises in crisis conditions are considered. The essence of the information danger of enterprises in crisis conditions is analyzed. It is proposed that the process of forming an integrated information security management system should be carried out on the basis of a comprehensive functional approach. A conceptual model of enterprise information security management in crisis conditions based on the functional approach is built. This model will help to increase the level of information and economic security of enterprise. This model will help to increase the level of information and economic security of an enterprise. The proposed methodology for building enterprise information security management systems, which is formed on the basis of a functional approach, should provide a reliable level of protection of information and communications of an enterprise. This will be achieved through continuous monitoring of the information environment (threats, dangers, challenges, etc.), constant monitoring of the information and communication activities of an enterprise, forecasting of information security (in particular, the risks that will affect it), etc. The result of the formation and application of the enterprise information security management system based on the functional approach is the formation of a comprehensive, balanced, effective and flexible information security system that will take into account all the features of the application of measures to protect the enterprise from negative information and communication influences, protect information arrays (data), information and intellectual rights, and provide open access to information resources of employees.

  • Research Article
  • Cite Count Icon 4
  • 10.1093/comjnl/bxq059
Information Security Risk Modeling Using Bayesian Index
  • Jul 30, 2010
  • The Computer Journal
  • C.-L Chan

The goal of this study lies in the construction and evaluation of a Bayesian index for measuring enterprises’ information security (IS) risk. By integrating IS experts’ judgments, we constructed a quantitative Bayesian index model for the assessment of enterprises’ IS risk. The risk assessment of enterprises’ IS makes enterprises aware of their IS risk and enables them to make better decisions to reduce that risk. Through the Delphi method and in-depth interviews with domain experts, the risk factors of IS were grouped into five categories with a total of 29 risk items. The first five key indicators are as follows: (i) top management support; (ii) the impediment and detection of the attack by worms, viruses and spyware programs; (iii) the protective measure and technique against the known hacker's attack; (iv) system access privilege control password, gold key management and (v) the IS equipment/software meets the requirement. Finally, the model was cross validated with enterprises that have implemented International Organization for Standardization/International Electro-technical Commission 27001. The study demonstrated that a subjective Bayesian model can be used to develop a reliable index for measuring IS risk, with potential for practical application in the management of the IS risk.

  • Research Article
  • Cite Count Icon 4
  • 10.28945/5185
How Information Security Management Systems Influence the Healthcare Professionals’ Security Behavior in a Public Hospital in Indonesia
  • Jan 1, 2023
  • Interdisciplinary Journal of Information, Knowledge, and Management
  • Puspita Kencana Sari + 3 more

Aim/Purpose: This study analyzes health professionals’ information security behavior (ISB) as health information system (HIS) users concerning associated information security controls and risks established in a public hospital. This work measures ISB using a complete measuring scale and explains the relevant influential factors from the perspectives of Protection Motivation Theory (PMT) and General Deterrence Theory (GDT) Background: Internal users are the primary source of security concerns in hospitals, with malware and social engineering becoming common attack vectors in the health industry. This study focuses on HIS user behavior in developing countries with limited information security policies and resources. Methodology: The research was carried out in three stages. First, a semi-structured interview was conducted with three hospital administrators in charge of HIS implementation to investigate information security controls and threats. Second, a survey of 144 HIS users to determine ISB based on hospital security risk. Third, a semi-structured interview was conducted with 11 HIS users to discuss the elements influencing behavior and current information security implementation. Contribution: This study contributes to ISB practices in hospitals. It discusses how HIS managers could build information security programs to enhance health professionals’ behavior by considering PMT and GDT elements. Findings: According to the findings of this study, the hospital has implemented particular information security management system (ISMS) controls based on international standards, but there is still room for improvement. Insiders are the most prevalent information security dangers discovered, with certain working practices requiring HIS users to disclose passwords with others. The top three most common ISBs HIS users practice include appropriately disposing of printouts, validating link sources, and using a password to unlock the device. Meanwhile, the top three least commonly seen ISBs include transferring sensitive information online, leaving a password in an unsupervised area, and revealing sensitive information via social media. Recommendations for Practitioners: Hospital managers should create work practices that align with information security requirements. HIS managers should provide incentives to improve workers’ perceptions of the benefit of robust information security measures. Recommendation for Researchers: This study suggests more research into the components that influence ISB utilizing diverse theoretical foundations such as Regulatory Focus Theory to compare preventive and promotion motivation to enhance ISB. Impact on Society: This study can potentially improve information security in the healthcare industry, which has substantial risks to human life but still lags behind other vital sector implementations. Future Research: Future research could look into the best content and format for an information security education and training program to promote the behaviors of healthcare professionals that need to be improved based on this ISB measurement and other influential factors.

  • Research Article
  • Cite Count Icon 8
  • 10.14419/ijet.v9i2.30581
Maturity Framework Analysis ISO 27001: 2013 on Indonesian Higher Education
  • Apr 18, 2020
  • International Journal of Engineering & Technology
  • Ign Mantra + 2 more

Information Security Management System (ISMS) implementation in Institution is an effort to minimize information security risks and threats such as information leakage, application damage, data loss and declining IT network performance. The several incidents related to information security have occurred in the implementation of the Academic System application in Indonesian higher education. This research was conducted to determine the maturity level of information security practices in Academic Information Systems at universities in Indonesia. The number of universities used as research samples were 35 institutions. Compliance with the application of ISO 27001:2013 standard is used as a reference to determine the maturity level of information system security practices. Meanwhile, to measure and calculate the level of maturity using the SSE-CMM model. In this research, the Information System Security Index obtained from the analysis results can be used as a tool to measure the maturity of information security that has been applied. There are six key areas examined in this study, namely the role and importance of ICT, information security governance, information security risk management, information security management framework, information asset management, and information security technology. The results showed the level of information security maturity at 35 universities was at level 2 Managed Process and level 3 Established Process. The composition is that 40% of universities are at level 3, and 60% are out of level 3. The value of the gap between the value of the current maturity level and the expected level of maturity is varied for each clause (domain). The smallest gap (1 level) is in clause A5: Information Security Policy, clause A9: Access Control, and clause A11: Physical and environmental security. The biggest gap (4 levels) is in clause A14: System acquisition, development and maintenance and clause A18: compliance.  Â

  • Research Article
  • 10.25140/2411-5363-2025-2(40)-207-220
Systematization of approaches to the information security risk assessment of transportation and logistics centers
  • Aug 11, 2025
  • Technical sciences and technologies
  • Oleksii Trunov + 1 more

Relevance of the study is driven by significant and constant growth of cyber threats to critical infrastructure, in particular to transport and logistics centers (TLCs), which are key nodes in global supply chains. Attacks on TLCs lead to serious conse-quences, namely: financial losses, disruption of logistics, and data compromise. This creates urgent need for effective ap-proaches to information security (IS) risk management adapted to the specifics of the TLC. Existing methods for assessing IS risks do not sufficiently take into account unique operational processes, integrated IT and OT systems, and technological landscape of TLCs, which jeopardizes their sustainability.The main problem addressed in this study is fragmentation of knowledge and insufficient adaptation of existing IS risk assessment methodologies to the specific conditions of TLCs. General approaches do not take into account unique attack vectors (via WMS, TMS), specific IT/OT vulnerabilities (SCADA), and cascading effects on physical operations. This mismatch makes it difficult to build effective cyber defense, which is critical for the sustainability of operations and data protection.The purpose of the article is to comprehensively systematize existing approaches to assessing IS risks, identify their advantages/disadvantages, and determine their relevance to TLCs.The study analyzed scientific works, standards and practices, which confirmed insufficient coverage of the specifics of TLCs' IS. The categories of security risks for TLCs are systematized. Risk assessment methodologies (FAIR, EBIOS, NIST, ISO/IEC 27005:2023, etc.) are classified and compared, their suitability for TLC is assessed, and advantages, disadvantages, and difficulties of adaptation are identified. The use of the combined, multi-level approach to selection of methods is proposed.The scientific novelty lies in development of classification and systematization of modern methods of assessing IS risks for TLC, as well as in the analysis of relationships between risk assessment methods, attack detection methods and approaches to their implementation in the context of TLC. This forms the knowledge base for making informed decisions by the TLC management on IS management. Practical value is possibility of improving the cybersecurity of TLCs through implementation of the recommended combined approach. At the same time, limitations of existing methods have been identified, including: fragmentation, insufficient consideration of the specifics of TLCs (especially IT/OT convergence) and potential resource intensity.Conclusions confirm achievement of the goal and substantiate urgent need for further research to develop the integrated, specialized methodology for assessing IS risks specifically for TLCs.

Save Icon
Up Arrow
Open/Close
Notes

Save Important notes in documents

Highlight text to save as a note, or write notes directly

You can also access these Documents in Paperpal, our AI writing tool

Powered by our AI Writing Assistant