CFP last date
20 March 2025
Reseach Article

Risk Assessment of Integrated Library System using COBIT 5 Framework

by Nizar Robbani, Imam Riadi
International Journal of Computer Applications
Foundation of Computer Science (FCS), NY, USA
Volume 184 - Number 27
Year of Publication: 2022
Authors: Nizar Robbani, Imam Riadi

Nizar Robbani, Imam Riadi . Risk Assessment of Integrated Library System using COBIT 5 Framework. International Journal of Computer Applications. 184, 27 ( Sep 2022), 25-36. DOI=10.5120/ijca2022922337

@article{ 10.5120/ijca2022922337,
author = { Nizar Robbani, Imam Riadi },
title = { Risk Assessment of Integrated Library System using COBIT 5 Framework },
journal = { International Journal of Computer Applications },
issue_date = { Sep 2022 },
volume = { 184 },
number = { 27 },
month = { Sep },
year = { 2022 },
issn = { 0975-8887 },
pages = { 25-36 },
numpages = {9},
url = { },
doi = { 10.5120/ijca2022922337 },
publisher = {Foundation of Computer Science (FCS), NY, USA},
address = {New York, USA}
%0 Journal Article
%1 2024-02-07T01:22:34.643594+05:30
%A Nizar Robbani
%A Imam Riadi
%T Risk Assessment of Integrated Library System using COBIT 5 Framework
%J International Journal of Computer Applications
%@ 0975-8887
%V 184
%N 27
%P 25-36
%D 2022
%I Foundation of Computer Science (FCS), NY, USA

The Integrated Library System (INLIS) at the Office of The Department of Library and Archives of Yogyakarta is an information system used for data processing of library administration. The business process can run well, so risk management is needed. The Department of Library and Archives of Yogyakarta Office requires a risk assessment of the ongoing business process. COBIT 5 is here to answer the challenges of this modern era, especially risk management. The need for a risk assessment to measure how far risk management is applied by elements in The Department of Library and Archives of Yogyakarta. The purpose of this study is to assess the Capability Level (maturity level), calculate the gap value, and provide recommendations by the APO12 (manage risk) and EDM03 (ensure risk optimization) domains.The risk management assessment in this study uses the COBIT 5 framework using the APO12 (manage risk) and EDM03 (ensure risk optimization) process domains which include the stages of data collection, risk analysis, risk profile, articulating risk, risk tolerance value, how to respond to risk, evaluate risk management, and direct risk management. The stages of research carried out in this study have three stages of analysis in research, namely determining the current capability level and the expected level, conducting gap analysis, and providing recommendations and suggestions for improvement. Based on the results of the calculations carried out in this study, the current level capability of the APO12 domain (manage risk) got a value of 2.59 which was at level 2 (managed process) meaning that IT processes in the Information system of The Department of Library and Archives of Yogyakarta has been done, achieved, and managed well. Domain APO12 (manage risk) gets a gap value of 0.31. The level of capability in the EDM03 domain (ensure risk optimization) gets a capability value of 2.70 (managed process) and the results of the calculation of the gap value get a gap value of 0.30 in the EDM03 (ensure risk optimization) domain. The recommendations generated in this study are by the expected goals.

  1. Andriani, Y. P., & Riadi, I. (2021). Risk Assessment of Monitoring Services using COBIT 5 Framework.
  2. Astuti, R. (2018). Implementation of Information System Risk Management Using COBIT 5. Media Informatics (Vol.17 No.1).
  3. Elly., & Halim, F. (2021). ‘IT Infrastructure Governance Evaluation With COBIT 5 Framework’, Journal of Information Systems, SMIK Mikroskil.
  4. Firdaus, N. Z. (2018). Evaluation of Information Technology Risk Management Using the COBIT 5 IT Risk Framework (Case Study: PT. Petrokimia Gresik) (Vol. 2, Issue 1).
  5. Fitriani, W., & et al. (January 2019). Information Technology Governance Audit Using COBIT 5. Journal of Engineering and Informatics Vol. 6, No. 1, Pg. 42 - 45.
  6. Fuad, M.N. (2020). Risk Management Assessment in UAD HR Information Technology Services Using the COIT 5 Method
  7. Ichwani, A. (2020). Measurement of the Risk Management Capability Level of the Sharia Cooperative Information System Using the COBIT 5 Framework.
  8. Indriyanto. (2020). Analysis of Risk Assessment in Canasoft Information Systems Using the COBIT Framework
  9. ISACA. 2012. COBIT 5: A Business Framework For The Governance And Management Of Enterprise IT. 2012.
  10. ISACA. 2012. COBIT 5: Enabling Processes, Rolling Meadows. ISACA. 2012. COBIT 5 Implementation.USA: IT Governance Institute.
  11. ISACA. 2012. COBIT 5: Process Assessment Model, USA: IT Governance Institute.
  12. Khairuna, D., Wibowo, S., & Gamayanto, I. (2020). ‘Evaluation of Information Technology Risk Management Using COBIT 5 Framework Based on Domain APO12 (Manage Risk) at the Head Office of BPR Agung Sejahtera’, Journal of Information System, Vol. 5, No. 1, Mei 2020: 18-26 DOI: 10.33633/joinsv5i1.3088.
  13. M Hanafi, M (2009). Risk, Risk Management Process, and Enterprise Risk Management. EKMA4262 Module 1, p. 1-40.
  14. Mutiah, N. (2019). ‘Tanjungpura University Information Technology Governance Assessment Using COBIT 5 Domain APO’, Journal of Computer Engineering, Vol. 4, No. 1, January 2019
  15. Nurhidayat, R. (2019). Analysis of Risk Management in Student Resignation Services Using the COBIT 5 Framework Focusing on Managing Risk (APO12).
  16. Octaviana. L.D., Private. P., Sabrinawati. M. (2019). Evaluation of IT Governance Using the COBIT 5 Framework. e/download/812/498.
  17. Prastiyawan, DA, Ambarwati, A., & Setiawan, E. (2020). Analysis of Risk Management Dealer Management System Services Using COBIT 5. Matrix: Journal of Information Technology and Management, 10(2), 43–49
  18. Putri, C. (2017). Risk Assessment of Information Technology Processes Based on the COBIT 5 Framework at the Helpdesk, Sub-directorate of Information Technology and Systems Services, Directorate of Information Technology and Systems Development (DPTSI) Sepuluh Institute of Technology. 241
  19. Rahmadani. (2019) IB Hasanah's Multipurpose Financing Risk Minimization Strategy.
  20. Rabhani, P. A., Maharani A., & Putrie A. A. (2020). ‘Attendance Information System Audit at the Bandung City Public Prosecutor's Office Using the COBIT 5 'Framework, Journal of Information Systems and Computers, Vol. 9, No.2, Agustus 2020.
  21. Saputra, C.D., & Riadi, I. (2021). Risk Assessment on Integrated Information System using COBIT 5 Framework. International Journal of Computer Applications, 183(23), 38–45.
  22. Sari Nanda, R. 2019. Audit of Information Systems Using COBIT 5 Framework (Case Study of Information and Communication Systems Bureau, Ahmad Dahlan University). Thesis, Information Systems, Ahmad Dahlan University, Yogyakarta.
  23. Sekarini, I. M. A. A, Candiasa, I. M., Aryanto, K. Y. E. (2021). Electronic Medical Records (EMR) System Audit at Kasih Ibu Hospital using the COBIT 5 Framework.
  24. Setiadi, A. F. (2018). Evaluation of Library Service Risk Management Based on APO12 Process at COBIT 5. National Seminar on Technology. oad/70/66
  25. Setyaningrum, N. D. (2018). Evaluation of Information Technology Risk Management Using the COBIT 5 Framework (Case Study: PT. Kimia Farma (Prsero) Tbk-Plant Watudakon). Journal of Information Technology Development and Computer Science. (Vol. 2 No. 1)
  26. Sugiyono. (September 2019). Quantitative, Qualitative, and R&D Research Methods. Bandung: ALFABETA.
Index Terms

Computer Science
Information Sciences


Information Systems Risk Management COBIT 5 Process Capability Level.