General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) Compliance

The use of technology in the era of the Industrial Revolution 4.0 is essential, marked by the use of technology in the economy and business. This situation makes many companies in the payment sector have to improve their information technology security systems. In Indonesia, Bank Indonesia and the F...

Full description

Bibliographic Details
Main Authors: Khairur Razikin, Agus Widodo
Format: Article
Language:English
Published: Bina Nusantara University 2021-08-01
Series:CommIT Journal
Subjects:
Online Access:https://journal.binus.ac.id/index.php/commit/article/view/6931
_version_ 1797724009685581824
author Khairur Razikin
Agus Widodo
author_facet Khairur Razikin
Agus Widodo
author_sort Khairur Razikin
collection DOAJ
description The use of technology in the era of the Industrial Revolution 4.0 is essential, marked by the use of technology in the economy and business. This situation makes many companies in the payment sector have to improve their information technology security systems. In Indonesia, Bank Indonesia and the Financial Services Authority (Otoritas Jasa Keuangan - OJK) are agencies that provide operational permits for companies by making Payment Card Industry-Data Security Standard (PCI-DSS) certification as one of the requirements for companies to obtain operating permits. However, not all companies can easily get PCI-DSS certification because many companies still do not meet the PCI-DSS requirements. The research offers a methodology for measuring the level of technology and information maturity using general cybersecurity requirements adopted from the cybersecurity frameworks of CIS, NIST, and Cobit. Then, the research also performs qualitative calculations based on interviews, observations, and data surveys conducted on switching companies that have been able to implement and obtain certification. PCI-DSS to produce practical cybersecurity measures, in general, can be used as a measure of the maturity of technology and information security. The results and discussion provide a model assessment tool on the procedures and requirements needed to obtain PCI-DSS certification. The maturity level value of PT XYZ is 4.0667 at maturity level 4, namely quantitatively managed, approaching level 5 as the highest level at maturity level.
first_indexed 2024-03-12T10:11:06Z
format Article
id doaj.art-ed0f98d0a2d640fe9bee6a43879ae40b
institution Directory Open Access Journal
issn 1979-2484
language English
last_indexed 2024-03-12T10:11:06Z
publishDate 2021-08-01
publisher Bina Nusantara University
record_format Article
series CommIT Journal
spelling doaj.art-ed0f98d0a2d640fe9bee6a43879ae40b2023-09-02T10:53:22ZengBina Nusantara UniversityCommIT Journal1979-24842021-08-011529110410.21512/commit.v15i2.69316005General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) ComplianceKhairur Razikin0Agus Widodo1Bina Nusantara UniversityBina Nusantara UniversityThe use of technology in the era of the Industrial Revolution 4.0 is essential, marked by the use of technology in the economy and business. This situation makes many companies in the payment sector have to improve their information technology security systems. In Indonesia, Bank Indonesia and the Financial Services Authority (Otoritas Jasa Keuangan - OJK) are agencies that provide operational permits for companies by making Payment Card Industry-Data Security Standard (PCI-DSS) certification as one of the requirements for companies to obtain operating permits. However, not all companies can easily get PCI-DSS certification because many companies still do not meet the PCI-DSS requirements. The research offers a methodology for measuring the level of technology and information maturity using general cybersecurity requirements adopted from the cybersecurity frameworks of CIS, NIST, and Cobit. Then, the research also performs qualitative calculations based on interviews, observations, and data surveys conducted on switching companies that have been able to implement and obtain certification. PCI-DSS to produce practical cybersecurity measures, in general, can be used as a measure of the maturity of technology and information security. The results and discussion provide a model assessment tool on the procedures and requirements needed to obtain PCI-DSS certification. The maturity level value of PT XYZ is 4.0667 at maturity level 4, namely quantitatively managed, approaching level 5 as the highest level at maturity level.https://journal.binus.ac.id/index.php/commit/article/view/6931general cybersecurity maturity assessment modelbest practicepayment card industry-data security standard (pci-dss)
spellingShingle Khairur Razikin
Agus Widodo
General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) Compliance
CommIT Journal
general cybersecurity maturity assessment model
best practice
payment card industry-data security standard (pci-dss)
title General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) Compliance
title_full General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) Compliance
title_fullStr General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) Compliance
title_full_unstemmed General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) Compliance
title_short General Cybersecurity Maturity Assessment Model: Best Practice to Achieve Payment Card Industry-Data Security Standard (PCI-DSS) Compliance
title_sort general cybersecurity maturity assessment model best practice to achieve payment card industry data security standard pci dss compliance
topic general cybersecurity maturity assessment model
best practice
payment card industry-data security standard (pci-dss)
url https://journal.binus.ac.id/index.php/commit/article/view/6931
work_keys_str_mv AT khairurrazikin generalcybersecuritymaturityassessmentmodelbestpracticetoachievepaymentcardindustrydatasecuritystandardpcidsscompliance
AT aguswidodo generalcybersecuritymaturityassessmentmodelbestpracticetoachievepaymentcardindustrydatasecuritystandardpcidsscompliance