Published: 2024-10-01
BPRDCo SME Digital Transformation by Designing Information Security Using ISO 27001:2022
DOI: 10.35870/jtik.v8i4.3148
Ignatius Christ Surya, Rahmat Mulyana, Ryan Adhitya Nugraha
Article Metrics
- Views 0
- Downloads 0
- Scopus Citations
- Google Scholar
- Crossref Citations
- Semantic Scholar
- DataCite Metrics
-
If the link doesn't work, copy the DOI or article title for manual search (API Maintenance).
Abstract
In the digital era of the Industrial Revolution 4.0, organizations such as BPRDCo must undergo Digital Transformation (DT) to remain competitive. A significant obstacle in this process is often the inadequacy of information security controls, which can lead to DT failure. Previous research has highlighted the necessity of ambidextrous information security management—integrating both traditional and agile approaches—as a crucial mechanism for DT success in large banks, particularly in data management and information security. However, this strategy has not been proven effective for smaller banks like BPRDCo. Therefore, this study aims to develop and propose priority information security management solutions specifically tailored for SMEs, while also estimating the improvement in maturity level capabilities to boost DT success. The research follows five stages in Design Science Research (DSR): problem identification, requirements specification, design and development, demonstration, and evaluation. Data were collected through interviews and document analysis, and analyzed using the ISO 27001:2022 Information Security Management System (ISMS) framework. Six priority PDCA and Annex controls were identified for BPRDCo as the case study. Based on the identified gaps, six essential solutions were designed using ISMS controls. These recommendations were compiled into an implementation roadmap to enhance BPRDCo's readiness for full ISMS implementation and certification, ultimately supporting DT success in small banks.
Keywords
Digital Transformation ; Design Science Research ; Information Security ; ISO 27001:2022 ; BPR
Article Metadata
Peer Review Process
This article has undergone a double-blind peer review process to ensure quality and impartiality.
Indexing Information
Discover where this journal is indexed at our indexing page to understand its reach and credibility.
Open Science Badges
This journal supports transparency in research and encourages authors to meet criteria for Open Science Badges by sharing data, materials, or preregistered studies.
How to Cite
Article Information
This article has been peer-reviewed and published in the Jurnal JTIK (Jurnal Teknologi Informasi dan Komunikasi). The content is available under the terms of the Creative Commons Attribution 4.0 International License.
-
Issue: Vol. 8 No. 4 (2024)
-
Section: Computer & Communication Science
-
Published: %750 %e, %2024
-
License: CC BY 4.0
-
Copyright: © 2024 Authors
-
DOI: 10.35870/jtik.v8i4.3148
AI Research Hub
This article is indexed and available through various AI-powered research tools and citation platforms. Our AI Research Hub ensures that scholarly work is discoverable, accessible, and easily integrated into the global research ecosystem. By leveraging artificial intelligence for indexing, recommendation, and citation analysis, we enhance the visibility and impact of published research.
Ignatius Christ Surya
Information Systems Study Program, Universitas Telkom, Bandung City, West Java Province, Indonesia
Rahmat Mulyana
Department of Computer and Systems Science, Stockholm University, Frescativägen 54, Frescati, Stockholm, Sweden
-
Schwertner, K. (2017). Digital transformation of business. Trakia Journal of Science, 15(Suppl. 1), 388–393. https://doi.org/10.15547/tjs.2017.s.01.065
-
-
Gong, C., & Ribiere, V. (2021). Developing a unified definition of digital transformation. Technovation, 102. https://doi.org/10.1016/j.technovation.2020.102217
-
Viamianni, A., Mulyana, R., & Dewi, F. (2023). COBIT 2019 information security focus area implementation for Reinsurco digital transformation. JIKO (Jurnal Informatika dan Komputer), 6(2). https://doi.org/10.33387/jiko.v6i2.6366
-
Vial, G. (2019). Understanding digital transformation: A review and a research agenda. Elsevier B.V. https://doi.org/10.1016/j.jsis.2019.01.003
-
Mulyana, R., Rusu, L., & Perjons, E. (2022). IT governance mechanisms that influence digital transformation: A Delphi study in Indonesian banking and insurance industry. PACIS 2022 Proceedings. https://aisel.aisnet.org/pacis2022
-
Mulyana, R., Rusu, L., & Perjons, E. (2021). IT governance mechanisms influence on digital transformation: A systematic literature review. AMCIS 2021 Proceedings. https://aisel.aisnet.org/amcis2021
-
-
-
Mulyana, R., Rusu, L., & Perjons, E. (2024). Key ambidextrous IT governance mechanisms for successful digital transformation: A case study of Bank Rakyat Indonesia (BRI). Digital Business, 4(2). https://doi.org/10.1016/j.digbus.2024.100083
-
Mulyana, R., Rusu, L., & Perjons, E. (2024). The influence of key ambidextrous IT governance mechanisms on digital transformation and organizational performance in the Indonesian banking and insurance industry. PACIS 2024 Proceedings. https://aisel.aisnet.org/pacis2024
-
Tarbiyatuzzahrah, B. D., Mulyana, R., & Santoso, A. F. (2023). Penggunaan COBIT 2019 GMO dalam menyusun pengelolaan layanan TI prioritas pada transformasi digital BankCo. JTIM: Jurnal Teknologi Informasi dan Multimedia, 5(3), 218–238. https://doi.org/10.35746/jtim.v5i3.400
-
-
-
-
-
-
-
-
-
-
-
-
-
-
Nistotskaya, M., Charron, N., & Lapuente, V. (2014). The wealth of regions: quality of government and SMEs in 172 European regions. Environment and Planning C: Government and Policy, 0(0), 0–0. https://doi.org/10.1068/c13224r
-
-
-
-
Patricia, I., Ph. D., & Ness, L. R. (2015). Are we there yet? Data saturation in qualitative research. Walden Faculty and Staff Publications. https://scholarworks.waldenu.edu/facpubs/455
-
-
Shenton, A. K. (2004). Strategies for ensuring trustworthiness in qualitative research projects. Education for Information, 22(2), 63–75. https://doi.org/10.3233/EFI-2004-22201.

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Authors who publish with this journal agree to the following terms:
1. Copyright Retention and Open Access License
Authors retain copyright of their work and grant the journal non-exclusive right of first publication under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
This license allows unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
2. Rights Granted Under CC BY 4.0
Under this license, readers are free to:
- Share — copy and redistribute the material in any medium or format
- Adapt — remix, transform, and build upon the material for any purpose, including commercial use
- No additional restrictions — the licensor cannot revoke these freedoms as long as license terms are followed
3. Attribution Requirements
All uses must include:
- Proper citation of the original work
- Link to the Creative Commons license
- Indication if changes were made to the original work
- No suggestion that the licensor endorses the user or their use
4. Additional Distribution Rights
Authors may:
- Deposit the published version in institutional repositories
- Share through academic social networks
- Include in books, monographs, or other publications
- Post on personal or institutional websites
Requirement: All additional distributions must maintain the CC BY 4.0 license and proper attribution.
5. Self-Archiving and Pre-Print Sharing
Authors are encouraged to:
- Share pre-prints and post-prints online
- Deposit in subject-specific repositories (e.g., arXiv, bioRxiv)
- Engage in scholarly communication throughout the publication process
6. Open Access Commitment
This journal provides immediate open access to all content, supporting the global exchange of knowledge without financial, legal, or technical barriers.