Evaluasi Tingkat Keamanan Informasi Pada Pusat Teknologi Informasi Dan Pangkalan Data (PTIPD) Universitas Islam Negeri Sunan Kalijaga Berdasarkan Indeks KAMI Versi 4.2
DOI:
https://doi.org/10.14421/csecurity.2026.9.1.5931Abstract
Peningkatan ketergantungan terhadap teknologi informasi di lingkungan perguruan tinggi menimbulkan risiko keamanan yang memerlukan penilaian rutin untuk melindungi kerahasiaan, integritas, dan ketersediaan data. Penelitian ini bertujuan untuk menilai tingkat kematangan keamanan informasi di Pusat Teknologi Informasi dan Pangkalan Data (PTIPD) UIN Sunan Kalijaga dengan menggunakan instrumen Indeks Keamanan Informasi (KAMI) versi 4.2, yang didasarkan pada standar ISO/IEC 27001. Metode yang diterapkan adalah deskriptif kualitatif melalui wawancara dan kuesioner untuk mengukur lima domain utama keamanan informasi beserta aspek tambahannya. Hasil penilaian menunjukkan bahwa sistem elektronik institusi tersebut termasuk dalam kategori ketergantungan yang "Tinggi". Secara umum, tingkat keamanan informasi mencapai predikat "Baik" dengan skor total 635. Tingkat kematangan pada area yang dievaluasi berkisar antara Level III hingga V, di mana Tata Kelola (Level IV), Pengelolaan Risiko (Level V), dan Kerangka Kerja (Level V) telah diimplementasikan secara komprehensif. Akan tetapi, Pengelolaan Aset serta Teknologi dan Keamanan Informasi masih berada pada Level III (Diterapkan Sebagian). Penilaian terhadap aspek tambahan menunjukkan hasil yang sangat memuaskan, khususnya dalam pengamanan layanan infrastruktur awan yang mencapai 100%. Kesimpulannya, PTIPD UIN Sunan Kalijaga telah memenuhi standar keamanan informasi minimum, tetapi memerlukan perhatian lebih besar pada aspek teknologi dan pengelolaan aset.
Kata kunci: Indeks KAMI, PTIPD, keamanan informasi, ISO/IEC 27001, evaluasi keamanan.
----------------------------------------------------------------------
Evaluation Of Information Security Levels At The Information Technology And Data Center (PTIPD) Of Sunan Kalijaga State Islamic University Yogyakarta Based On KAMI Index Version 4.2
Increased dependence on information technology in higher education environments poses security risks that require regular assessment to protect the confidentiality, integrity, and availability of data. This study aims to assess the level of information security maturity at the Information and Data Technology Center (PTIPD) of Sunan Kalijaga State Islamic University Yogyakarta using the Information Security Index (KAMI) version 4.2 instrument, which is based on the ISO/IEC 27001 standard. The method used is descriptive qualitative through interviews and questionnaires to measure the five main domains of information security and other additional aspects. The assessment results show that the institution's electronic system is in the “High” category in terms of dependence. In general, the level of information security achieved a rating of “Good” with a total score of 635. The maturity level in the areas evaluated ranged from Level III to V, where Governance (Level IV), Risk Management (Level V), and Framework (Level V) have been comprehensively implemented. However, Asset Management and Information Technology and Security are still at Level III (Partially Implemented). The assessment of additional aspects shows very satisfactory results, particularly in securing cloud infrastructure services, which reached 100%. In conclusion, PTIPD UIN Sunan Kalijaga has met the minimum information security standards but requires greater attention to technology and asset management aspects.
Keywords: KAMI Index, PTIPD, information security, ISO/IEC 27001, security evaluation
References
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Naufal Naufal Hafizh Mufafaq, Fiki Sanora, Bambang Sugiantoro

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Attribution-ShareAlike 4.0 International (CC BY-SA 4.0)
You are free to:
- Share — copy and redistribute the material in any medium or format
- Adapt — remix, transform, and build upon the material for any purpose, even commercially.
Under the following terms:
- Attribution — You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.
- ShareAlike — If you remix, transform, or build upon the material, you must distribute your contributions under the same license as the original.
- No additional restrictions — You may not apply legal terms or technological measures that legally restrict others from doing anything the license permits.

