Evaluation of Information Security Readiness Level Using the Integration of KAMI Index 5.0 and ISO/IEC 27001:2022

Authors

  • Nasya Ananda Rozi Universitas Mulia Balikpapan
  • Agus Wijayanto Universitas Mulia
  • Wahyu Nur Alimyaningtias Universitas Mulia

DOI:

https://doi.org/10.30871/jaic.v10i4.13451

Keywords:

KAMI Index 5.0, Information Security, ISO 27001:2022

Abstract

Information security is a strategic aspect that determines the continuity of organizational operations amid an increasing dependence on digital systems. PT. QAZ, as a regionally owned business entity providing clean water services, relies on information systems to support customer management, payment systems, and distribution network management, so evaluating the readiness of its information security is crucial. This study aims to measure the level of information security readiness of PT. QAZ through the integration of the KAMI Index 5.0 with ISO/IEC 27001:2022 control using a mixed methods approach. The results of the evaluation of the Electronic Systems Category obtained a score of 19 points with a high category, while the accumulation of the sixth score in the evaluation area reached 372 out of a maximum total of 918 points, with the achievement of the supplement category of 26%. In detail, the maturity level of each domain is: Level I+ Information Security Governance, Level II Risk Management, Level I Information Security Management Framework, Level I+ Information Asset Management, Level II Information Technology and Security, and Level I Personal Data Protection.

Downloads

Download data is not yet available.

References

[1] I Nyoman Adi Artha Wibawa, "Information Security Evaluation at Hospital Using Index KAMI 5 . 0 and Recommendations Based on ISO/IEC 27001 : 2022," vol. 6, no. 4, pp. 3070–3086, 2024, doi: 10.51519/journalisi.v6i4.949.

[2] T. Rochmadi and I. Y. Pasa, "Measurement of Risk and Evaluation of Information Security Using The Information Security Index in BKD XYZ Based on ISO 27001/SNI," CyberSecurity and Digit Forensics., vol. 4, no. 1, pp. 38–43, 2021, doi: 10.14421/csecurity.2021.4.1.2439.

[3] D. Rohmaniah, W. M. Ashari, Lukman, and A. D. Putra, "Enhancing Website Security Using Vulnerability Assessment and Penetration Testing (VAPT) Based on OWASP Top Ten," J. Appl. Informatics Comput., vol. 9, no. 2, pp. 404–411, 2025, doi: 10.30871/jaic.v9i2.9069.

[4] M. T. Akbar, R. T. Veronica, R. I. Widyana, and H. Nurahman, "Evaluation of BAWASLU ABC Information Security Readiness Evaluation of BAWASLU ABC Using KAMI Index 5 . 0," vol. 9, no. 1, pp. 88–97, 2026.

[5] A. D. Saputra, F. Dione, and I. Uluputty, "Management of Information Security and Encryption at the Communication and Information Service of East Kalimantan Province," J. Techno. and Commun. Government., vol. 5, no. 2, pp. 159–187, 2023, doi: 10.33701/jtkp.v5i2.3735.

[6] F. Anis Sekar Ningrum, Y. Riwanto, I. Yanuar Risca Pratiwi, and M. A. Fikri, "Security Analysis of Higher Education Information Systems Based on OUR Index," J. Inform. Polynesian, vol. 10, no. 3, pp. 437–444, 2024.

[7] A. Apriany and A. Wibowo, "Analysis of the Implementation of ISO 27001: 2022 and KAMI Index in Enhancing the Information Security Management System in Consulting Firms," IJCCS (Indonesian J. Comput. Cybern. Syst., vol. 18, no. 4, pp. 417–428, 2024, doi: 10.22146/ijccs.100385.

[8] O. J. Pratomo, M. U. A. Al Huraibi, and M. Ridwan, "Evaluation of Information Security in DNY Skincare Company Based on the Information Security Index (WE) ISO/IEC 27001:2013," Inf. Syst. Educ. Prof. J. Inf. Syst., vol. 10, no. 2, p. 117, 2025, doi: 10.51211/isbi.v10i2.3670.

[9] A. H. Nadanta, H. Farisi, and D. W. Brata, "Evaluation Analysis of the KAMI Index (Information Security) 5.0 in Information Security Management at SMK Telkom Purwokerto," J. Pengemb. Technology. Inf. and Computing Science., vol. 9, no. 8, pp. 1–9, 2025.

[10] Y. Rahmah, W. Hayuhardika, and A. Dwi herlambang, "Evaluation of Information Security at the Communication and Information Service of Mojokerto Regency using the Information Security Index (KAMI)," Pengemb. Technology. Inf. and Computing Science., vol. 3, no. 6, pp. 840–846, 2019.

[11] B. Novriyadi, M. Jazman, M. Megawati, and M. Afdal, "Evaluation of Information Security Readiness Using the KAMI Index 5.0 and ISO/IEC 27001: 2022," Progressive J. Ilm. Computer., vol. 21, no. 2, pp. 573–585, 2025.

[12] M. Fadhli Ma'arif, Melwin Syafrizal, Jeki Kuswanto, and Aiko Nur Hendry Yansyah, "Security Risk Analysis of QRIS Implementation in Public Locations Using ISO 31000:2018 Framework," J. Appl. Informatics Comput., vol. 9, no. 4, pp. 1670–1680, 2025, doi: 10.30871/jaic.v9i4.9877.

[13] Y. R. Rizky and H. Said, "EVALUATION OF INFORMATION SECURITY AT SMAN 1 TANGGAMUS USING OUR INDEX VERSION 4.2," vol. 13, no. 2, pp. 181–187, 2023.

[14] F. S. Wati, D. A. Prambudi, and H. I. Sunardi, "Evaluation of Information Security at XYZ University Using the KAMI Index 4.2," Equiva J., vol. 2, no. 1, pp. 1–7, 2024.

[15] S. Nurul, S. Anggrainy, and S. Aprelyani, "Factors Affecting Information System Security: Information Security, Information Technology and Network (Sim Literature Review)," vol. 3, no. 5, pp. 564–573, 2022.

[16] L. D. A. Jelita, M. N. Al Azam, and A. Nugroho, "Evaluation of Information Technology Security Using the Information Security Index 5.0 and ISO/EIC 27001:2022," J. SAINTEKOM, vol. 14, no. 1, pp. 84–94, 2024, doi: 10.33020/saintekom.v14i1.623.

[17] G. Fitria, D. Yuniarto, and D. Setiadi, "Evaluation of the Security of the Online Regional Tax System of Sumedang Regency Using the Information Security Index 5.0," J. Tek. Machinery, Ind. Electrical and Inform., vol. 4, no. 1, pp. 232–242, 2025.

[18] R. Sinaga and F. Taan, "The Application of ISO/IEC 27001:2022 in Information Systems Security Governance: Process Evaluation and Constraints," Nuances Inform., vol. 18, no. 2, pp. 46–54, 2024, doi: 10.25134/ilkom.v18i2.205.

[19] S. Salisa, A. Zahra, I. Aknuranda, and H. Farisi, "Evaluation of the Maturity Level of Information Security Using the KAMI Index 5 . 0 at Universitas Darul ' Ulum Jombang," vol. 9, no. 9, pp. 1–7, 2025.

[20] D. I. Khamil, "Evaluation of Information Security Readiness Level Using Our Index 4.2 and ISO/IEC 27001:2013 (Case Study: Diskominfo Gianyar Regency)," JATISI (Tek Journal. Inform. and Sist. Information), vol. 9, no. 3, pp. 1948–1960, 2022, doi: 10.35957/jatisi.v9i3.2310.

[21] A. H. Harahap, C. D. Andani, A. Christie, and A. Fauzi, "The Importance of the CIA Triad's Role in Information and Data Security for Stakeholders or Stakeholders," vol. 1, no. 2, pp. 73–83, 2023.

[22] Frangky and R. Sinaga, "The Application of ISO / IEC 27001: 2022 in Information System Security Governance: Process Evaluation and Constraints," vol. 18, pp. 46–54, 2024.

[23] Nyoman, "Information Security Risk Analysis Using the Octave Allegro Method and Analytical Hierarchy Process at the Buleleng Regency Government Data Center," 2022, Ganesha University of Education.

[24] G. Fitria and D. Yuniarto, "Evaluation of the Security of the Online Regional Tax System of Sumedang Regency Using the Information Security Index 5.0," vol. 4, 2025.

[25] D. I. Khamil, G. Made, A. Sasmita, A. Agung, and N. Hary, "Evaluation of Information Security Readiness Level Using Our Index 4 . 2 And ISO / IEC 27001 : 2013 (Case Study: Diskominfo Gianyar Regency)," vol. 9, no. 3, pp. 1948–1960, 2022.

[26] A. P. Putra et al., "Journal Information System Audit Using COBIT 5 Framework on DSS01 and DSS05 Domains," vol. 3, no. 1, pp. 649–658, 2024.

[27] S. Watkins, "ISO/IEC 27001: 2022: An introduction to information security and the ISMS standard," 2022.

[28] A. R. Riswaya and A. Sasongko, "Using Our Index for the Preparation of the SNI ISO/IEC 27001 Standard (Case Study: STMIK Mardira Indonesia)," J. Comput. Business, 2020.

[29] S. Hidayatulloh and D. Saptadiaji, "Penetration Testing on ARS University Website Using the Open Web Application Security Project (OWASP)," pp. 77–86, 2021.

Downloads

Published

2026-08-12

How to Cite

[1]
N. A. Rozi, A. Wijayanto, and W. N. Alimyaningtias, “Evaluation of Information Security Readiness Level Using the Integration of KAMI Index 5.0 and ISO/IEC 27001:2022”, JAIC, vol. 10, no. 4, pp. 3796–3807, Aug. 2026.