Evaluation of Cybersecurity Awareness and Training for Digital Branch Frontliners at Bank XYZ
DOI:
https://doi.org/10.47709/cnahpc.v7i3.6016Keywords:
Cybersecurity, ISO/IEST 27002:2022, NIST SP 800-500, CPLP, Information Security Evaluation, Banking IndustryAbstract
The digital transformation in the banking sector has driven a shift in operations, including the establishment of digital branches that rely on information technology to deliver services to customers. However, the increased use of technology brings significant information security risks, particularly those stemming from human factors. This study aims to evaluate the level of cybersecurity awareness among frontliners at Bank XYZ’s digital branch using the ISO/IEC 27002:2022 framework and to develop training recommendations based on NIST SP 800-50. The research was conducted using both quantitative and qualitative methods, involving questionnaires and observations of 36 frontliners. The evaluation results revealed that several controls, particularly Response to Information Security Incidents (ID 5.26), still showed low levels of understanding (60%), indicating the need for training intervention. Training recommendations were designed based on the Cybersecurity and Privacy Learning Program (CPLP) principles from NIST SP 800-50, which include visual approaches, role-based training, and digital learning media. The implementation of these recommendations for one of the controls showed a significant improvement in post-test scores (average >= 93), exceeding the 85% threshold. This indicates that the CPLP-based approach is effective in enhancing frontliners’ cybersecurity awareness. This research is expected to serve as a reference for other banks in developing adaptive information security training strategies aligned with international standards.
Downloads
References
Astuti, D. W. (2019). Penyusunan Rekomendasi untuk Meningkatkan Kesadaran Keamanan Informasi berdasarkan NIST SP 800-50 (Studi Kasus: Institut Teknologi Sepuluh Nopember). Institut Teknologi Sepuluh Nopember.
Catota, F. E., Granger Morgan, M., & Sicker, D. C. (2018). Cybersecurity incident response capabilities in the Ecuadorian financial sector. Journal of Cybersecurity, 4(1). https://doi.org/10.1093/cybsec/tyy002
Domínguez-Domínguez, R., Flores-Laguna, O. A., & ... (2023). Evaluation of an information security management system at a Mexican higher education institution. ArXiv Preprint ArXiv …. Retrieved from https://arxiv.org/abs/2306.11050%0Ahttps://arxiv.org/pdf/2306.11050
Fajri, K. S. Al, & Harwahyu, R. (2024). Information Security Management System Assessment Model by Integrating ISO 27002 and 27004. MALCOM: Indonesian Journal of Machine Learning and Computer Science, 4(2), 498–506. https://doi.org/10.57152/malcom.v4i2.1245
Fathurohman, A., & Witjaksono, R. W. (2020). Analysis and Design of Information Security Management System Based on ISO 27001: 2013 Using ANNEX Control (Case Study: District of Government of Bandung City). Bulletin of Computer Science and Electrical Engineering, 1(1), 1–11. https://doi.org/10.25008/bcsee.v1i1.2
Ho, H., Ko, R., Mazerolle, L., Gilmour, J., & Miao, C. (2024). Using Situational Crime Prevention (SCP)-C3 cycle and common inventory of cybersecurity controls from ISO/IEC 27002:2022 to prevent cybercrimes. Journal of Cybersecurity, 10(1). https://doi.org/10.1093/cybsec/tyae020
International Organization for Standardization. (2022). International Standard ISO/IEC 27001:2022. Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements, 2022. https://doi.org/10.2307/j.ctv30qq13d
Jufri, M. T., Hendayun, M., & Suharto, T. (2017). Risk-Assessment Based Academic Information System Security Policy Using OCTAVE Allegro and ISO 27002. International Conference on Informatics and Computing (ICIC).
Kurniawan, E., & Irmawan, A. (2022). Performance Measurement of Security Academic Information System using Maturity Level. International Journal of Innovative Science and Research Technology, 7(4). Retrieved from www.ijisrt.com65
Kusnandar, A., Rochim, A. F., & Gunawan, V. (2024). Pengukuran Tingkat Risiko dan Keamanan Informasi Menggunakan Metode FMEA Berbasis ISO / IEC 27001 pada Instansi XYZ untuk Keamanan Sistem Informasi. Jurnal Sistem Informasi Bisnis, 04. https://doi.org/10.21456/vol14iss4pp375-384
Merritt, M., Hansche, S., Ellis, B., Sanchez-Cherry, K., Snyder, J. N., & Walden, D. (2024). Building a Cybersecurity and Privacy Learning Program. (National Institute of Standards and Technology, Gaithersburg, MD), NIST Special Publication (SP) NIST SP 800-50r1. https://doi.org/https://doi.org/10.6028/NIST.SP.800-50r1
Pambudi, R. D., & Ramli, K. (2023). Information Security Risk Management Design of Supervision Management Information System At Xyz Ministry Using Nist Sp 800-30. Jurnal Teknik Informatika (Jutif), 4(3), 591–599. https://doi.org/10.52436/1.jutif.2023.4.3.978
Paramita, S., Siregar, S. A., Damanik, R. A., & Irawan, M. D. (2022). Analisis Manejemen Resiko Keamanan Data Sistem Informasi Berdasarkan Indeks Keamanan Informasi (KAMI) ISO 27001:2013. Bulletin of Information Technology (BIT), 3(4), 374–379. https://doi.org/10.47065/bit.v3i1
Santi, R., Alfresi, A. I., & Octariana, B. (2023). INFORMATION SYSTEM SECURITY AUDIT USING ISO/IEC 27002:2013 AT UNIVERSITY OF XXX. Jurnal Teknik Informatika (Jutif), 4(4), 733–750. https://doi.org/10.52436/1.jutif.2023.4.4.689
Simatangkir, D. W. E., Afifah, E. F. N., & Faliha, N. S. (2025). Keamanan Siber Dalam Perbankan Serta Tantangan Dan Solusi Di Era Digital. Jurnal Multidisiplin Ilmu Akademik, 2(1), 33–42.
Tan, T., & Soewito, B. (2022). Manajemen Risiko Serangan Siber Menggunakan Framework Nist Cybersecurity Di Universitas Zxc. Journal of Information System, Applied, Management, Accounting and Research, 6(2), 411–422. https://doi.org/10.52362/jisamar.v6i2.781
Verizon. (2023). Verizon Data Breach Investigations Report (DBIR). Verizon Enterprise Solutions. Retrieved from https://inquest.net/wp-content/uploads/2023-data-breach-investigations-report-dbir.pdf
Wiemas, K. N. G., & Suroso, J. S. (2022). Analysis of Risk Management Information System Applications Using Iso/Iec 27001:2022. Jurnal Ilmiah Indonesia, 7(11), 14–20. https://doi.org/10.56304/s0040363622080021
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Ayu Novira Shinta Permatasari, Alfa Ryano Yohannis

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

