BibTex Citation Data :
@article{JSINBIS72634, author = {Andys Kurniawan and Aris Widodo and Adi Wibowo}, title = {Security Risk Management Assessment in Information Technology Services using Information Technology Infrastructure Library (ITIL) V4}, journal = {Jurnal Sistem Informasi Bisnis}, volume = {15}, number = {4}, year = {2025}, keywords = {ITIL V4 Maturity Model; Risk Management; Information Security Management; Capability level; IT Service Management}, abstract = { Information Technology (IT) is currently implemented in various fields of life, including in higher education. Some common IT-based service problems such as server down, slow systems, poor integration, and data security are important concerns for education managers. IT Service Management or Information Technology Service Management (ITSM) is a strategic approach to designing, providing, managing, and improving the way IT is used in an organization. ITIL is one of the most popular ITSM frameworks and includes a framework for evaluation and assessment. This study proposes the use of ITIL V4 to assess the level of maturity of security risk management in the higher education sector, which has not been widely explored. This study aims to measure and analyze the level of capability and assess the maturity of IT services, especially in risk management practices and information security management and analyze the level of gap between actual conditions that occur and expected standards. The results of the study indicate that the assessment of the level of maturity of higher education in managing IT service security risks, especially in both management practices, is at level 3 (Defined). These results indicate that universities have begun to realize the importance of IT security risk management, where practices are well defined, processes and activities are documented and standardized. To achieve continuous improvement according to the ITIL V4 standard, it is necessary to increase the capacity of the technology used, consistency in evaluation, and build an organizational culture that supports continuous risk management. }, issn = {2502-2377}, pages = {469--472} doi = {10.14710/vol15iss4pp469-472}, url = {https://ejournal.undip.ac.id/index.php/jsinbis/article/view/72634} }
Refworks Citation Data :
Information Technology (IT) is currently implemented in various fields of life, including in higher education. Some common IT-based service problems such as server down, slow systems, poor integration, and data security are important concerns for education managers. IT Service Management or Information Technology Service Management (ITSM) is a strategic approach to designing, providing, managing, and improving the way IT is used in an organization. ITIL is one of the most popular ITSM frameworks and includes a framework for evaluation and assessment. This study proposes the use of ITIL V4 to assess the level of maturity of security risk management in the higher education sector, which has not been widely explored. This study aims to measure and analyze the level of capability and assess the maturity of IT services, especially in risk management practices and information security management and analyze the level of gap between actual conditions that occur and expected standards. The results of the study indicate that the assessment of the level of maturity of higher education in managing IT service security risks, especially in both management practices, is at level 3 (Defined). These results indicate that universities have begun to realize the importance of IT security risk management, where practices are well defined, processes and activities are documented and standardized. To achieve continuous improvement according to the ITIL V4 standard, it is necessary to increase the capacity of the technology used, consistency in evaluation, and build an organizational culture that supports continuous risk management.
Article Metrics:
Last update:
Last update: 2026-05-14 19:28:33
Authors who submit the manuscripts to Journal JSINBIS must understand and agree that if the manuscript is accepted for publication, the copyright of the article belongs to JSINBIS and Diponegoro University as the journal publisher.
Copyright includes the exclusive right to reproduce and provide articles in all forms and media, including reprints, photographs, microfilm and any other similar reproductions, as well as translations. The author reserves the rights to the following:
JSINBIS and Diponegoro University and the Editors make every effort to ensure that no false or misleading data, opinions or statements are published in this journal. The content of articles published in JSINBIS is the sole and exclusive responsibility of the respective authors.
Copyright transfer agreement can be found here: [Copyright transfer agreement in doc] and [Copyright transfer agreement in pdf].
JSINBIS (Jurnal Sistem Informasi Bisnis) is published by the Magister of Information Systems, Post Graduate School Diponegoro University. It has e-ISSN: 2502-2377 dan p-ISSN: 2088-3587 . This is a National Journal accredited SINTA 2 by RISTEK DIKTI No. 48a/KPT/2017.
Journal JSINBIS which can be accessed online by http://ejournal.undip.ac.id/index.php/jsinbis is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
View My Stats