Abstract
The increasing reliance on digital information systems has made information security governance a critical requirement for maintaining secure and reliable organizational operations. PT Pertamina Patra Niaga Fuel Terminal Manokwari utilizes the Safety Patrol feature within the E-Mansinam Website to support Health, Safety, Security, and Environment (HSSE) activities, including hazard reporting, safety monitoring, and corrective action management. This study evaluates the information security governance capability of the Safety Patrol feature using the COBIT 2019 framework, focusing on the APO13 (Managed Security) and DSS05 (Managed Security Services) domains. A descriptive quantitative approach was employed through observations, interviews, questionnaires, and documentation. The collected data were analyzed using Capability Assessment, Gap Analysis, and Root Cause Analysis (RCA). The results show that the APO13 domain achieved an average capability level of 4.04, exceeding the organization's target of Level 4, whereas the DSS05 domain achieved an average capability level of 3.93, indicating that several operational security service processes require further improvement. The largest capability gap was identified in DSS05.07 with a gap value of 0.44. Root Cause Analysis revealed that inconsistent security monitoring, incomplete documentation, limited periodic evaluations, and varying levels of personnel awareness were the primary factors contributing to the identified capability gaps. Based on these findings, this study proposes practical recommendations to strengthen information security governance and support the continuous improvement of the Safety Patrol feature, particularly in operational security service management.