Vol. 4 No. March 2026 . ISSN: 2987-6990 DOI: https://doi. org/10. 60005/coreid. Information System Audit of Learning Management System Using COBIT 5 Army Staff and Command School Erfin Erfiana1. Erwin Teguh Arujisaputra2. Purwadi3 1,2,3 Faculty of Computer Science Universitas Kebangsaan Republik Indonesia Bandung. Indonesia Article Info ABSTRACT Article history: In the digital era, information technology has become a core component of the education system, with the Learning Management System (LMS) as the primary platform for online learning. The Army Staff and Command College (SESKOAD) have implemented an LMS to support educational effectiveness and efficiency, but has not yet undergone a formal audit, thus risking regulatory non-compliance and security weaknesses. This study aims to measure the maturity level of IT governance and LMS management using the COBIT 5 framework through a descriptive quantitative approach. Data were collected through observation, structured interviews, and a Likert-scale questionnaire . Ae. distributed to selected respondents using purposive sampling, covering the roles of IT administrators, operational users, and The research instruments were derived from practices and process activities in the domains APO9. DSS01. DSS04. DSS05. DSS06. MEA01, and MEA02. The assessment was conducted using the COBIT 5 Process Capability Model by measuring the achievement of process attributes (PA1. 1 to PA5. which were converted into numerical scores, then the average value per process was calculated and aggregated to determine the capability level (Level 0Ae. based on the ISO/IEC 15504 standard threshold. The results showed that the LMS was at Level 2 (Managed Proces. with gaps in formal documentation, risk control, and security control. Recommendations focused on standardizing SOPs, increasing user awareness and competence, and implementing continuous security audits to gradually reach Level 4 within five years. Received March 27, 2026 Revised April 22, 2026 Accepted May 13, 2026 Keywords: COBIT 5 Information System Audit Maturity Level Learning Management System Risk Management This is an open access article under the CC BY-SA license. Corresponding Author: Erfin Erfiana Faculty of Computer Science Universitas Kebangsaan Republik Indonesia Bandung. West Java. Indonesia Email: erfin. erfiana@student. INTRODUCTION In the era of digital transformation, the integration of information technology in education has evolved from a mere tool to a key enabler in creating adaptive, efficient, and data-driven learning systems. A Learning Management System (LMS) is a key infrastructure that supports online learning, content management, and integrated learning analytics. The use of an LMS has been proven to improve the quality of learning and the flexibility of educational access, especially after the COVID-19 pandemic . However, increasing reliance on LMS is also accompanied by various risks, including information security, data privacy, and compliance with good information technology governance . Therefore, a systematic information system audit is needed to ensure that the LMS implementation is not only operationally effective, but also meets the principles of governance, risk, and compliance (GRC). In the context of military education, the urgency of IT governance becomes even more critical due to the environment's demanding high levels of security, confidentiality, and compliance. The Army Staff and CoreID Journal | Vol. No. March 2026: 32-37 Command College (Seskoa. , as a strategic educational institution within the Indonesian Army (TNI AD), has adopted an LMS to support its officer training process. However, to date, there has been no formal audit of the LMS system in use. This lack of auditing has the potential to create a gap between system implementation and IT governance standards, which could lead to increased security risks, regulatory inconsistencies, and low information reliability . Studies show that organizations with low levels of IT governance maturity tend to have a higher vulnerability to system disruptions and security incidents . Several previous studies have examined information systems audits using the COBIT 5 framework in the education sector. For example, evaluations of e-learning systems and academic systems show varying levels of capability, generally ranging from level 1 to level 3, with major weaknesses in documentation and process control . , . Other studies have shown that although some domains have reached higher levels of maturity, evaluations are often limited to specific domains and do not include comprehensive gap analysis . Furthermore, most research still focuses on civilian educational institutions, while studies in the context of military education, which has more complex security and control needs, are still very limited . , . This indicates a research gap in the development of a comprehensive and contextual COBIT 5-based LMS audit model . , . Based on this gap, this study aims to conduct an audit of the LMS information system at SESKOAD using the COBIT 5 framework with a focus on measuring capability levels and analyzing gaps between existing conditions and expected targets . The contributions of this study include the application of COBIT 5 in the context of military education, the development of a process attributes-based evaluation instrument to increase measurement objectivity, and the preparation of a structured roadmap for improving IT governance. Thus, this study is expected to provide theoretical contributions to the development of IT governance as well as practical implications in improving the effectiveness, efficiency, and security of LMS. METHOD This research uses the COBIT 5 framework as its methodology because it offers a comprehensive and structured approach to assessing IT governance and information system capabilities . The research focuses on three main domains relevant to an operational LMS . s opposed to development or strategic-level domain. Align. Plan and Organize (APO): Sub-domain APO9 (Manage Service Agreement. assesses the extent to which service agreements between LMS providers and users are designed and implemented in accordance with the operational needs of military education. Deliver. Service and Support (DSS): Sub-domains DSS01 (Manage Operation. DSS04 (Manage Continuit. DSS05 (Manage Security Service. , and DSS06 (Manage Business Process Control. cover service delivery, disaster recovery, data and system security, and business process control. Monitor. Evaluate and Assess (MEA): Sub-domains MEA01 (Monitor Performance and Conformanc. and MEA02 (Monitor Complianc. manage performance monitoring and formal compliance evaluation . The average score for each domain is calculated as: Average Score = OcycEya ycu Table 1. Capability Level Mapping Score Range 0 Ae <1 1 Ae <2 2 Ae <3 Capability Level Level 0 (Incomplet. Level 1 (Performe. Level 2 (Manage. Level 3 (Establishe. The domains EDM (Evaluate. Direct and Monito. and BAI (Build. Acquire and Implemen. were excluded because they focus on strategic governance at top-management level and new system construction, respectively, which are outside the scope of auditing an already-operational LMS system . Data Collection Data was collected through four approaches : . Observation Ae direct observation of LMS usage at Seskoad including workflow, features, and constraints. Interviews Ae semi-structured interviews with IT staff, instructors, and system administrators . based on COBIT 5 process criteria . Questionnaire Ae Likert-scale . Ae. questionnaire with 23 items administered to 162 respondents . tudent officers, instructors, and staf. Literature Review Ae review of peer-reviewed journals and books related to IT governance. COBIT 5, and LMS auditing. Information System Audit of Learning Management System Using COBIT 5. (Erfin, et a. - 33 CoreID Journal | Vol. No. March 2026: 32-37 Capability Assessment Data was analyzed using the COBIT 5 Process Assessment Model (PAM) to determine the capability level of each sub-domain. The assessment evaluates process goal achievement, documentation availability, procedure implementation, risk management readiness, disaster recovery, security governance, and performance monitoring . Maturity levels were determined by comparing actual conditions against COBIT 5 standards, then validated through triangulation of the three data sources . bservation, interview, questionnair. RESULTS AND DISCUSSION Triangulation Results and Maturity Level Triangulation of the three data collection methods yielded consistent results across all seven evaluated sub-domains. Table 2 presents a summary of findings. Table 2. Triangulation Results by Sub-domain Sub-domain Maturity Level Aspect Observation & Interview Result Risk Management Risk management is still weak, with minimal documentation, no formal risk identification, no mitigation plans, and no system security audits. Privacy policy compliance is not enforced. APO9 - Manage Risk Level 2 (Manage. Operations Management Technical documentation and SOPs are inadequate. operations frequently experience technical constraints. backup is available but not optimal. DSS01 - Manage Operations Level 2 (Manage. Service Continuity Disaster recovery plan is not documented or consistently Routine backup exists but service recovery readiness needs strengthening. DSS04 - Manage Continuity Level 2 (Manage. Security Services Security governance is weak. no security audit has been no clear responsible person. physical security is DSS05 - Manage Security Services Level 2 (Manage. Business Process Controls Manual guide documentation exists, but business process controls lack adequate monitoring and audit. Security responsibilities are unclear. DSS06 Ae Manage Business Process Controls Level 2 (Manage. Performance Monitoring LMS performance is measured through user surveys and academic data, but measurement is unstructured and not supported by adequate audit and control. MEA01 Ae Monitor. Evaluate and Assess Performance Level 2 (Manage. Compliance Monitoring Compliance with policies is not well-documented. formal compliance audit has been conducted. regular checks are urgently needed. MEA02 Ae Monitor. Evaluate and Assess Compliance Level 2 (Manage. Table 2 shows that all seven sub-domains are at Maturity Level 2 (Manage. This indicates systemic governance issues rather than isolated problems. Level 2 means processes have been performed and planned, but they are not consistently documented, monitored, or formally controlled. The LMS is operational but relies on informal and unintegrated processes. This finding is consistent with similar studies. Krisyawan et al. found an academic IS at capability level 1 in a university setting. Pratiwi et al. found a library IS at capability level 2. The military context of Seskoad introduces additional governance complexity, as information security and operational continuity are mission-critical concerns that demand higher accountability and documentation standards than civilian GAP Analysis Based on the COBIT 5 maturity model . , a GAP analysis was conducted comparing the current state (Level . against the target state (Level 4 Ae Quantitatively Manage. The target was set at Level 4 because Seskoad, as a military educational institution, requires high reliability, security, and quantitatively measurable governance for its information systems. The GAP spans two levels across all seven sub-domains, indicating that significant and structured improvement efforts are required. At Level 4 . , the LMS would exhibit: . fully integrated documentation and SOPs. proactive real-time operational monitoring. a robust, tested, and automated disaster recovery plan. comprehensive security governance with regular audits. integrated business process controls with quantitative measurement. a structured, data-driven performance and compliance monitoring system. Information System Audit of Learning Management System Using COBIT 5. (Erfin, et a. - 34 CoreID Journal | Vol. No. March 2026: 32-37 Table 3. Rating Scale Score Category Not Achieved Partially Achieved Largely Achieved Fully Achieved Description No evidence of implementation Minor implementation exists Most requirements are fulfilled Fully implemented and documented Improvement Recommendations Based on the triangulation results and GAP analysis, seven improvement recommendations were formulated, as shown in Table 4. Table 4. LMS System Improvement Recommendations No. Aspect Improvement Recommendation Benefit Documentation & SOP Develop and update technical documentation and SOPs for each sub-domain. ensure all processes are clearly documented and easily accessible. Improve user understanding and reduce operational errors. User Training Conduct regular training for instructors, student officers, and administrative staff on LMS usage and new features. Improve overall user proficiency and Risk Management Formally identify risks and develop clear mitigation plans. conduct system security audits regularly. Reduce harmful incidents such as data loss or security breaches. Security Audit Conduct routine security audits to verify controls are functioning properly and in line with established policies. Identify security gaps and ensure user data Business Process Control Implement stricter controls for LMS-related business processes, including data management and user activity Improve operational efficiency and reduce data management errors. Performance Evaluation Implement a structured performance evaluation system with periodic user satisfaction surveys and academic result Identify areas needing improvement. LMS meets user needs. Compliance Policy Develop and implement clear compliance policies for LMS usage, including data privacy policies and academic Ensure all users comply with established reduce violation risks. The recommendations in Table 5 are prioritized in order of urgency: documentation and SOP development must come first (Year . as it underpins all subsequent improvements. User training follows to ensure adoption. Risk management and security audits address the most critical operational vulnerabilities, while business process controls, performance evaluation, and compliance policy represent higher-maturity governance capabilities to be built incrementally. Table 5. Scores per Sub-Domain Domain PA1. PA2. PA2. APO9 DSS01 DSS04 DSS05 DSS06 MEA01 MEA02 Average Score Level System Blueprint and Five-Year Roadmap Based on the capability assessment results and the identified two-level GAP, a transformation blueprint and strategic roadmap were developed following the principles of Ahlaro et al. The blueprint describes the transition from the current state (Level . to the target state (Level . through five implementation Year 1 - Foundation: Draft and finalize documentation and SOPs. conduct user training . wo batche. perform initial risk identification, mitigation, and security audit. conduct annual review. Year 2 Ae Development: Design and implement business process controls. set up performance monitoring tools. develop and simulate a disaster recovery plan. conduct initial compliance assessment and integrate compliance with monitoring. Year 3 - Implementation: Pilot implementation on a limited area. phased rollout. full deployment. audit and documentation of implementation results. Year 4 Ae Optimization: Performance analysis. advanced feature development. external system integration. innovation prototyping lab. Year 5 Ae Evolution: Multi-region system adaptation. AI-based feature integration. system showcase. final documentation as Information System Audit of Learning Management System Using COBIT 5. (Erfin, et a. - 35 CoreID Journal | Vol. No. March 2026: 32-37 organizational legacy. Figure 1. Roadmap E-Learning SESKOAD This phased approach ensures sustainable progress, with each year building on the governance foundations established in the preceding year. The five-year roadmap is expected to elevate all seven subdomains from Level 2 to Level 4, making the LMS governance structure quantitatively measurable and aligned with SeskoadAos educational mission. CONCLUSION This study conducted an audit of the LMS information system at Seskoad using the COBIT 5 framework in seven sub-domains (APO9. DSS01. DSS04. DSS05. DSS06. MEA01, and MEA. , with the results showing the capability level at Level 2 (Managed Proces. This condition indicates that the process has been running but is still partial, not standardized, and not supported by adequate documentation and performance measurement. Key findings include weaknesses in technical documentation and SOPs, unstructured risk management, the absence of a documented disaster recovery plan, weak security governance without regular audits, and the absence of an integrated performance monitoring and evaluation system. Based on a gap analysis of the COBIT 5 capability model, a target for upgrading to Level 4 (Quantitatively Manage. is set with the prerequisite of having measurable performance indicators (KPI. , data-based control, and comprehensive process integration. The proposed five-year roadmap is structured in stages, taking into account inter-process dependencies, organizational readiness, and resource requirements. Its implementation still requires further validation through feasibility testing and performance measurement based on baselines and quantitative targets. Conceptually. COBIT 5 provides a systematic evaluation framework, but its implementation effectiveness is highly dependent on consistency of implementation, managerial support, and organizational readiness. Therefore, further research is recommended to expand the audit scope to other systems, conduct comparative studies across military educational institutions, integrate other frameworks such as ITIL and ISO 27001, and evaluate implementation achievements longitudinally based on performance indicators at each stage of the roadmap. ACKNOWLEDGEMENTS The author would like to express his deepest gratitude to all parties who have provided support in the implementation of this research, especially to the leaders and ranks within the Army Staff and Command School (Seskoa. for permission, data access, and support during the research process, as well as to the information technology management team. LMS system users, and all respondents who have actively participated in data collection through questionnaires and interviews. appreciation is also expressed to fellow academics and colleagues for the constructive input provided, as well as to the author's home institution which has supported this research morally and academically, and to all other parties who cannot be mentioned one by one for their contributions, with the hope that the results of this research can provide benefits for the development of information technology governance, especially in improving the quality of LMS-based learning systems in the military education environment. Information System Audit of Learning Management System Using COBIT 5. (Erfin, et a. - 36 CoreID Journal | Vol. No. March 2026: 32-37 REFERENCES