Evaluation of Cybersecurity Awareness and Training for Digital Branch Frontliners at Bank XYZ

Authors

  • Ayu Novira Shinta Permatasari Universitas Pradita
  • Alfa Ryano Yohannis Universitas Pradita, Tangerang, Indonesia

DOI:

https://doi.org/10.47709/cnahpc.v7i3.6016

Keywords:

Cybersecurity, ISO/IEST 27002:2022, NIST SP 800-500, CPLP, Information Security Evaluation, Banking Industry

Abstract

The digital transformation in the banking sector has driven a shift in operations, including the establishment of digital branches that rely on information technology to deliver services to customers. However, the increased use of technology brings significant information security risks, particularly those stemming from human factors. This study aims to evaluate the level of cybersecurity awareness among frontliners at Bank XYZ’s digital branch using the ISO/IEC 27002:2022 framework and to develop training recommendations based on NIST SP 800-50. The research was conducted using both quantitative and qualitative methods, involving questionnaires and observations of 36 frontliners. The evaluation results revealed that several controls, particularly Response to Information Security Incidents (ID 5.26), still showed low levels of understanding (60%), indicating the need for training intervention. Training recommendations were designed based on the Cybersecurity and Privacy Learning Program (CPLP) principles from NIST SP 800-50, which include visual approaches, role-based training, and digital learning media. The implementation of these recommendations for one of the controls showed a significant improvement in post-test scores (average >= 93), exceeding the 85% threshold. This indicates that the CPLP-based approach is effective in enhancing frontliners’ cybersecurity awareness. This research is expected to serve as a reference for other banks in developing adaptive information security training strategies aligned with international standards.

Downloads

Download data is not yet available.

References

Astuti, D. W. (2019). Penyusunan Rekomendasi untuk Meningkatkan Kesadaran Keamanan Informasi berdasarkan NIST SP 800-50 (Studi Kasus: Institut Teknologi Sepuluh Nopember). Institut Teknologi Sepuluh Nopember.

Catota, F. E., Granger Morgan, M., & Sicker, D. C. (2018). Cybersecurity incident response capabilities in the Ecuadorian financial sector. Journal of Cybersecurity, 4(1). https://doi.org/10.1093/cybsec/tyy002

Domínguez-Domínguez, R., Flores-Laguna, O. A., & ... (2023). Evaluation of an information security management system at a Mexican higher education institution. ArXiv Preprint ArXiv …. Retrieved from https://arxiv.org/abs/2306.11050%0Ahttps://arxiv.org/pdf/2306.11050

Fajri, K. S. Al, & Harwahyu, R. (2024). Information Security Management System Assessment Model by Integrating ISO 27002 and 27004. MALCOM: Indonesian Journal of Machine Learning and Computer Science, 4(2), 498–506. https://doi.org/10.57152/malcom.v4i2.1245

Fathurohman, A., & Witjaksono, R. W. (2020). Analysis and Design of Information Security Management System Based on ISO 27001: 2013 Using ANNEX Control (Case Study: District of Government of Bandung City). Bulletin of Computer Science and Electrical Engineering, 1(1), 1–11. https://doi.org/10.25008/bcsee.v1i1.2

Ho, H., Ko, R., Mazerolle, L., Gilmour, J., & Miao, C. (2024). Using Situational Crime Prevention (SCP)-C3 cycle and common inventory of cybersecurity controls from ISO/IEC 27002:2022 to prevent cybercrimes. Journal of Cybersecurity, 10(1). https://doi.org/10.1093/cybsec/tyae020

International Organization for Standardization. (2022). International Standard ISO/IEC 27001:2022. Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements, 2022. https://doi.org/10.2307/j.ctv30qq13d

Jufri, M. T., Hendayun, M., & Suharto, T. (2017). Risk-Assessment Based Academic Information System Security Policy Using OCTAVE Allegro and ISO 27002. International Conference on Informatics and Computing (ICIC).

Kurniawan, E., & Irmawan, A. (2022). Performance Measurement of Security Academic Information System using Maturity Level. International Journal of Innovative Science and Research Technology, 7(4). Retrieved from www.ijisrt.com65

Kusnandar, A., Rochim, A. F., & Gunawan, V. (2024). Pengukuran Tingkat Risiko dan Keamanan Informasi Menggunakan Metode FMEA Berbasis ISO / IEC 27001 pada Instansi XYZ untuk Keamanan Sistem Informasi. Jurnal Sistem Informasi Bisnis, 04. https://doi.org/10.21456/vol14iss4pp375-384

Merritt, M., Hansche, S., Ellis, B., Sanchez-Cherry, K., Snyder, J. N., & Walden, D. (2024). Building a Cybersecurity and Privacy Learning Program. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) NIST SP 800-50r1. https://doi.org/https://doi.org/10.6028/NIST.SP.800-50r1

Pambudi, R. D., & Ramli, K. (2023). Information Security Risk Management Design of Supervision Management Information System At Xyz Ministry Using Nist Sp 800-30. Jurnal Teknik Informatika (Jutif), 4(3), 591–599. https://doi.org/10.52436/1.jutif.2023.4.3.978

Paramita, S., Siregar, S. A., Damanik, R. A., & Irawan, M. D. (2022). Analisis Manejemen Resiko Keamanan Data Sistem Informasi Berdasarkan Indeks Keamanan Informasi (KAMI) ISO 27001:2013. Bulletin of Information Technology (BIT), 3(4), 374–379. https://doi.org/10.47065/bit.v3i1

Santi, R., Alfresi, A. I., & Octariana, B. (2023). INFORMATION SYSTEM SECURITY AUDIT USING ISO/IEC 27002:2013 AT UNIVERSITY OF XXX. Jurnal Teknik Informatika (Jutif), 4(4), 733–750. https://doi.org/10.52436/1.jutif.2023.4.4.689

Simatangkir, D. W. E., Afifah, E. F. N., & Faliha, N. S. (2025). Keamanan Siber Dalam Perbankan Serta Tantangan Dan Solusi Di Era Digital. Jurnal Multidisiplin Ilmu Akademik, 2(1), 33–42.

Tan, T., & Soewito, B. (2022). Manajemen Risiko Serangan Siber Menggunakan Framework Nist Cybersecurity Di Universitas Zxc. Journal of Information System, Applied, Management, Accounting and Research, 6(2), 411–422. https://doi.org/10.52362/jisamar.v6i2.781

Verizon. (2023). Verizon Data Breach Investigations Report (DBIR). Verizon Enterprise Solutions. Retrieved from https://inquest.net/wp-content/uploads/2023-data-breach-investigations-report-dbir.pdf

Wiemas, K. N. G., & Suroso, J. S. (2022). Analysis of Risk Management Information System Applications Using Iso/Iec 27001:2022. Jurnal Ilmiah Indonesia, 7(11), 14–20. https://doi.org/10.56304/s0040363622080021

Downloads

Published

2025-07-02

How to Cite

Permatasari, A. N. S., & Yohannis, A. R. (2025). Evaluation of Cybersecurity Awareness and Training for Digital Branch Frontliners at Bank XYZ. Journal of Computer Networks, Architecture and High Performance Computing, 7(3), 672–683. https://doi.org/10.47709/cnahpc.v7i3.6016

Citation Tracker

Cited by: 0 documents

No citing documents were found.

Source: OpenAlex  · Updated 2026-09-22 16:23 UTC