Hastuti et. Security Analysis of Enterprise Resource Planning EVALUATING ERP INFORMATION SECURITY USING ISO/IEC 27001:2013 STANDARD IN AGRICULTURAL TECHNOLOGY ENTERPRISES Puji Hastuti1*. Nourma Islam Dewi Cantika2. Aditya Pratama3. Dhanar Intan Surya Saputra4 Sistem Informasi. Universitas Amikom Purwokerto. Banyumas. Indonesia1-4 E-mail address: pujih1211@. com1, cantikasj20@gmail. adityaprtma383951@gmail. com3, dhanarsaputra@amikompurwokerto. Received: 04. April, 2025 Revised: 10. May, 2025 Accepted: 20. June, 2025 ABSTRACT Data security is an essential component of ERP system management, particularly given the increasing cyber dangers in the digital age. This study assesses the maturity of ERP-based information security at PT BroilerX Yogyakarta using the ISO/IEC 27001:2013 standard. The growing dependence on digital platforms in agriculture has expedited the implementation of ERP solutions, like Odoo, to optimize business processes. This research employs a qualitative descriptive case study methodology to examine the implementation of ten ISO domains, utilizing data gathered from interviews with the IT team and analyzed through the Capability Maturity Model Integration. The findings indicate that the majority of domains attained a maturity level of 4 (Manage. , signifying consistent and thoroughly documented processes, although Human Resource Security and Incident Management remained at level 3 (Define. , highlighting the necessity for enhanced automation and proactive incident management. These findings underscore both the strengths and flaws in ERP security implementation and offer actionable advice to enhance the Information Security Management System (ISMS). This research contextualizes ISO/IEC 27001:2013 within a poultry agritech enterprise, thereby enhancing understanding of the integration of international security standards in technologydriven agribusiness and providing practical insights for similar organizations aiming to bolster their resilience against cyber threats. Keywords: Enterprise Resource Planning (ERP). ISO/IEC 27001:2013. Information Security. Agritech Enterprise. Maturity Level Assessment INTRODUCTION Digital transformation in the agricultural sector has become a key catalyst in driving the modernization of agribusiness practices through the utilization of information technology. (Amirova & Klychova, 2. One of the most concrete manifestations of this transformation is the adoption of Enterprise Resource Planning (ERP) systems, which are designed to improve operational efficiency and strengthen integration across business processes. (Auliani, 2023. (Pryshliak & Semenenko, 2. (Shirokov, 2019. In the face of global challenges concerning food security and supply chain efficiency. ERP systems offer a viable solution by accelerating the flow of information, minimizing data redundancy, and enhancing coordination among various units within an agricultural organization (Singh et al. , 2. Hastuti et. Security Analysis of Enterprise Resource Planning ERP systems are digital platforms that integrate various core organizational functions such as financial management, inventory, production, distribution, and human resources into a single, real-time, interconnected system (Mazorenko, 2. With this capability. ERP supports more accurate and timely data-driven decision-making while providing comprehensive visibility into operational performance (Alwan & Fahmi, 2023. (Shirokov, 2019b. Litvinova et al. , 2. the agricultural sector, the implementation of ERP can assist business actors in responding to market dynamics, increasing productivity, and developing adaptive management strategies based on analytical data insights (Val et al. , 2. However, despite its numerous advantages. ERP systems present specific challenges, particularly regarding the complexity of their architecture and their heavy reliance on centralized information. (Melnyk, 2. This dependency makes ERP systems vulnerable to information security threats, including cyberattacks, data breaches, and unauthorized system (Nehrey, 2. The intricate configuration of ERP also creates challenges in terms of system maintenance and comprehensive data protection (Chervanova, 2. Therefore, in adopting ERP, the agricultural sector must not only focus on functionality but also establish robust information security strategies, including human resource training and the implementation of strict security policies (Nobari et al. , 2. (Chutcheva, 2. (Voitsekhovska & Lomachynska, 2. (Demchuk & Rusyn-Hrynyk, 2. PT. BroilerX Yogyakarta is a technology startup in the poultry farming sector that employs Odoo-based ERP to facilitate its business operations, encompassing production management, logistics, and digital payments. This system also features a connection to a mobile application for direct interaction with farmer partners in real time. This information was obtained through interviews with the IT team at PT. BroilerX Yogyakarta. The international standard ISO/IEC 27001:2013 provides a framework for systematically managing information security based on risk assessment (Jevelin & Faza, 2. (ISO, 2. ISO 27001:2013 has 14 security control clauses, encompassing a total of 35 control objectives and 114 security controls to achieve the objectives (Diamantopoulou et al. , 2. (Vorobyev & Kuleshova, 2. The 14 security control clauses such Information security policies. Organization of information security. Human resource security. Asset management. Access control. Cryptography. Physical and Environmental security. Operations security. Communications security. System acquisition, development, and maintenance. Supplier relationships. Information security incident management. Information security aspects of business continuity management, and Compliance (Fajar et al. , 2. Previous research indicates that the implementation of ISO 27001 can improve operational efficiency, regulatory compliance, and stakeholder trust (Clarissa & Wang, 2023. Rodryguez et al. , 2023. Suorsa & Helo, 2. (Khanna, 2. However, there has been little research specifically analyzing the implementation of ISO/IEC 27001:2013 controls in the context of ERP in the poultry farming industry, particularly in startups using platforms like Odoo. Therefore, this study contributes to filling this gap and provides a new perspective on evaluating information security systems based on international standards in the agricultural technology business environment. To resolve these issues, this Inspiration: Jurnal Teknologi Informasi dan Komunikasi Volume 15. Number 1. June 2025: 78 Ae 89 https://doi. org/10. 35585/inspir. P-ISSN : 2088-6705 E-ISSN : 2621-5608 research aims to analyze the level of implementation and maturity of information security controls in the ERP system at PT. BroilerX Yogyakarta uses the ISO/IEC 27001:2013 standard. The study employs a descriptive qualitative approach using a case study method, focusing on the 10 main domains in Annex A of the ISO standard (A. 16, and A. Data was collected through interviews with the company's IT team and analyzed using a maturity model framework to measure the gap between the current state and ideal practices. This research is expected to contribute to improving information security practices in the Indonesian agritech sector. This structure enables a systematic assessment of the extent to which the company has met the security standards established by ISO 27001:2013. THEORY According to (Amirinnisa et al. , 2. Information security refers to a set of measures taken to protect information from various threats to ensure business continuity, reduce risk, and optimize investment value. The main principle follows the CIA (Confidentiality. Integrity, and Availabilit. model as a guideline in maintaining confidentiality, integrity, and availability of ISO/IEC 27001:2013 is an international standard that specifies the requirements for an information security management system (ISMS) (Podrecca et al. , 2. According to Alit Yuniargan Eskaluspita. ISO 27001 itself is an international standard published by the International Organization for Standardization (ISO), which describes the information security management methodology in organizations, with the latest revision in 2013, so that ISO 27001: 2013 was produced. Accuracy of the system to protect information (Eskaluspita, 2. ERP (Enterprise Resource Plannin. is a software system used to organize and integrate all the main business processes in an organization into one integrated system (Alwan & Fahmi. According to (Auliani, 2023. ERP (Enterprise Resource Plannin. is an integrated application that organizations can use to collect, save, organize, and interpret data from the daily business activities of the company. ERP provides an integrated and continuously updated view of core business processes using a common database. According to (Kaban & Legowo, 2. Maturity level is a tool to measure how maturity achieved by a company in the application of information system audit. The CMMI (Capability Maturity Model Integratio. framework provides structured levels to measure this maturity. The goal of implementing CMMI within an organization is to improve manufacturing and the product of the company's software. (Junior et al. , 2. METHOD In this research, data collected by interviews with the company's IT team improved information system security from May 6, 2025, to June 16, 2025. The research is intended to obtain insights into how ISO/IEC 27001:2013 the implementation of information security controls in the ERP system at PT. BroilerX Yogyakarta. The interview guidelines were developed based on the controls outlined in ISO/IEC 27001:2013, with a focus on 10 key domains. An overview of the clauses used in this research can be seen in Table 1. Hastuti et. Security Analysis of Enterprise Resource Planning Table 1. Clauses used in this Research Domain (Clause. Control Information Security Policy Information Security Organizational Human Resource Security Access Controls A10 Cryptography A12 Operational Security A13 Communication Security A14 System Development Security A16 Information Security Incident Management A18 Compliance The data collected will be analyzed based on each control domain, aiming to identify the conformity of implementation with the ISO/IEC 27001:2013 standard and to identify any possible gap analysis by comparing the actual conditions obtained from the interview results with the ideal standards in ISO/IEC 27001:2013, and using the CMMI model, which covers five maturity levels. The research is based on the alignment between the actual conditions in the company and the characteristics of each maturity level. An overview of the maturity level used in this research can be seen in Table 2. Level Level 1 Level 2 Level 3 Name Initial Repeatable but Intuitive Defined Level 4 Managed Level 5 Optimized Table 2. Clauses used in this Research Description No procedures. ad-hoc practices Procedures exist but are not documented or consistently Policies are documented, but not fully implemented consistently or evaluated. The controls are implemented, documented, trained, and monitored regularly. The controls have been automated and are sustainable best Based on the analysis results and maturity level, conclusions and strategic recommendations are provided to improve the information security management system (ISMS) implementation at PT. BroilerX Yogyakarta. Figure 1. Research Concept. RESULTS AND DISCUSSION These research results were obtained through interviews with the IT team at PT. BroilerX Yogyakarta. The interview was structured based on the ISO/IEC 27001:2013 framework, which encompasses the ten core domains of an Information Security Management System (ISMS). This research aims to gain a comprehensive understanding of the effective implementation of information security controls at PT. BroilerX Yogyakarta. The analysis Inspiration: Jurnal Teknologi Informasi dan Komunikasi Volume 15. Number 1. June 2025: 78 Ae 89 https://doi. org/10. 35585/inspir. P-ISSN : 2088-6705 E-ISSN : 2621-5608 process has three main steps: data collection from interviews, gap analysis, and a maturity level assessment based on domains A. 16, and A. The interview results were then analyzed according to the ten domains of ISO/IEC 27001:2013. The domain covers relevant questions on information security control aspects with responses from the IT team at PT. BroilerX Yogyakarta. This structure enables a systematic assessment of the extent to which the company has met the security standards established by ISO 27001:2013. 1 Results of interviews with IT based on the ISO 27001:2013 standard 1 Domain A. 5 (Information Security Polic. This document guides all divisions in maintaining data and system security and is evaluated and updated regularly to anticipate threats and meet the company's evolving needs. 2 Domain A. 6 (Information Security Organizatio. In Domain A. 6 at PT BroilerX Yogyakarta, the structure of the information security organization has been defined clearly. In addition to the IT team, there are representatives from management and the Quality Assurance (QA) division who are also responsible for the implementation of the security policy. IT security is a part of the routine evaluation in management meetings. Security issue escalation protocols are in place, although documentation needs to be improved to ensure more effective communication channels. 3 Domain A. 7 (Human Resource Securit. PT BroilerX has implemented information security training for new employees and periodic re-training. Access revocation procedures are carried out automatically and manually through coordination between the IT and Human Resources divisions. However, monitoring of security violations by employees is still done manually, so it does not yet fully support systematic 4 Domain A. 9 (Access Contro. In Access control implementation has been effective. Access rights are granted based on job responsibilities and must be approved by a supervisor. The system has also implemented multifactor authentication, with most internal systems using two-factor authentication. Access to sensitive data is strictly limited to authorized personnel, supported by audit logs and regular system updates. 5 Domain A. 10 (Cryptograph. The system uses strong encryption such as AES-256 and TLS 1. 2/1. 3 for data protection, both during storage and transfer. Encryption key management is carried out through a Key Management System (KMS) and is equipped with encrypted access logs. 6 Domain A. 12 (Operational Securit. Patch management for the company's IT systems is carried out every week and on an ad-hoc basis if critical vulnerabilities are identified. Before launching new features, a set of Quality Assurance tests and internal audits is carried out to make sure the system is stable and secure. Monitor logs and detect anomalies using security information and event management software, which allows for early identification of potential disruptions. Network Infrastructure is protected through the implementation of active firewalls and IDS. Data backup processes are performed daily and stored in separate locations to ensure data availability in the event of a Hastuti et. Security Analysis of Enterprise Resource Planning system failure. Additionally, antivirus software on all servers and endpoints is always active and regularly updated to address the latest malware threats. 7 Domain A. 13 (Communication Securit. Communication networks within the company environment are protected through firewall configuration and the implementation of an active intrusion detection system (IDS), with realtime monitoring carried out by the information security team to quickly detect and respond to potential threats. 8 Domain A. 14 (System Development Securit. PT BroilerX Yogyakarta has implemented secure software development procedures with regular secure coding training, as well as code review and testing to detect potential vulnerabilities early on. Version control is managed using Git to ensure structured and transparent change logging. All application development is done internally using the Odoo system, customized to the company's needs. 9 Domain A. 16 (Information Security Incident Managemen. The PT. BroilerX Yogyakarta has established Standard Operating Procedures (SOP. for incident handling, including isolation, investigation, reporting, and system recovery. However, incident response simulations are not conducted regularly, which poses a risk of reducing preparedness for real-world attacks. It is recommended to conduct regular simulations to enhance incident response capabilities and effectiveness. 10 Domain A. 18 (Complianc. PT BroilerX Yogyakarta routinely conducts security audits, both internal and external, and documents the results thoroughly. This practice helps ensure compliance with information security standards and supports continuous improvement. Monitoring and updating audits must be ongoing to keep pace with regulatory developments and security threats. 2 Manurity level Maturity level assessments are done for the ISO 27001:2013 control domains based on interview results that are categorized according to clauses A. 16, and A. The control domain is evaluated using indicators that reference five maturity levels. Table 3. Maturity Level of ISO 27001:2013 Based on Interviews. Domain Control Testing Results Maturity Description Level A5 - Information The company has 4 - Managed Procedures are in Security Policy documented SOPs that are place, and documents routinely reviewed and need to be A6 - Information The responsibilities are clear, 4 - Managed Organized but not yet Security and SOPs are available. Organizational Structure A7 - Human Training and suspension of 3 - Defined Effective and Resource Security access are implemented, but penalties are not monitored implementation of Inspiration: Jurnal Teknologi Informasi dan Komunikasi Volume 15. Number 1. June 2025: 78 Ae 89 https://doi. org/10. 35585/inspir. Domain Control A9 - Access Controls A10 Cryptography A12 - Operational Security A13 Communication Security A14 - System Development Security A16 - Information Security Incident Management A18 - Compliance Testing Results Using 2FA, access rights are restricted according to need and position. Data and encryption keys are well managed and conform to industry standards. System backup and monitoring procedures are performed regularly and The use of IDS, firewalls, and network security is active and under monitoring. Adoption of secure coding and documentation of the development process has been implemented. There is an SOP for incident handling, but an incident simulation has not been carried out periodically. Security audits are conducted regularly, and there are records of audit results. P-ISSN : 2088-6705 E-ISSN : 2621-5608 Maturity Description Level 4 - Managed Active cryptographic 4 - Managed The operational process is running 4 - Managed Protected network 4 - Managed Documented and 4 - Managed Simulations need to be held regularly. 3 - Defined An audit has been conducted and 4 - Managed Procedures are in place, and documents need to be 2 Gap Analysis A gap analysis was conducted to compare the actual state of information security implementation at PT BroilerX Yogyakarta with ideal practices as stipulated in ISO/IEC 27001:2013. The differences between the IT team's interviews and these international standards serve as the basis for identifying areas requiring improvement. Domains with no gaps indicate that security controls have been adequately implemented and align with best practices. Table 3 below presents the current state of implementation based on the interview results and findings from the testing conducted. Table 3. Maturity Level of ISO 27001:2013 Based on Interviews. ISO Clauses Current Implementation Testing Results There is an SOP policy. Tasks are clearly defined, and SOPs are Advanced documentation for escalation procedures is Training and revocation are active. Sanction monitoring is not yet automated. Factor Authentication and appropriate access rights. Hastuti et. Security Analysis of Enterprise Resource Planning ISO Clauses A10 A14 A16 Current Implementation The encryption and Key Management System works well. Routine monitoring and backup are carried out. Intrusion Detection System and firewall are active. Safe coding practices in action. Handling SOP document available. A18 There is an SOP policy. A12 A13 Testing Results Incident simulation is still not done regularly. To quantitatively determine the level of the gap, maturity levels were measured in each domain. The results of these measurements are shown in Table 4. Domain A10 A12 A13 A14 A16 A18 Table 4. Result of Maturity Levels Gap by Domain Maturity Level Maturity Level Real GAP ANALYSIS Ideal The measurement results show that most domains, such as A5 (Information Security Policie. A6 (Organization of Information Securit. A9 (Access Contro. A10 (Cryptograph. A12 (Operations Securit. A13 (Communications Securit. A14 (System Acquisition. Development and Maintenanc. , and A18 (Complianc. , have reached maturity level 4 (Manage. This indicates that security controls in these areas have been implemented consistently and are well-documented. However, there are still two domains that are only at maturity level 3 (Define. , namely A7 (Human Resource Securit. and A16 (Incident Managemen. This gap is mainly caused by the suboptimal automation in the sanctions monitoring system in A7, as well as the lack of periodic incident simulations in A16. To clarify the comparison between the actual conditions and the ideal standard ISO/IEC 27001:2013, a visual representation in the form of a spider chart is used in Figure 1. Inspiration: Jurnal Teknologi Informasi dan Komunikasi Volume 15. Number 1. June 2025: 78 Ae 89 https://doi. org/10. 35585/inspir. P-ISSN : 2088-6705 E-ISSN : 2621-5608 Figure 1. Representation Manurity Level Result. The orange line in the figure represents the ideal maturity level . evel 5 Ae Optima. expected to be achieved across all domains, while the blue line shows the actual maturity level based on interviews with the IT team at PT BroilerX Yogyakarta. This visualization shows that although most domains are at level 4, there are still significant gaps in the human factor and incident readiness aspects. Overall, this gap analysis indicates that the ERP security system at PT BroilerX has a strong foundation. However, to achieve the optimal maturity level according to the ISO/IEC 27001:2013 standard, strengthening the Human Resource Security aspect is necessary through automated monitoring, as well as increasing the effectiveness of Incident Management through conducting scheduled incident simulations. CONCLUSIONS AND SUGGESTIONS Based on the results of investigations and studies on ISO 27001:2013. PT BroilerX has adopted various information security measures that are quite adequate, with a maturity level between 3 (Define. and 4 (Manage. The company has official policies and solid technical implementations in most areas, particularly in access control, encryption, and operational However, there are still some areas that can be improved, such as training for incident handling and documentation for system development testing. To resolve these issues and improve the effectiveness of the Information Security Management System (ISMS), they suggested a few strategic recommendations, including: . Improving documentation and evaluating procedures regularly. Implementing regular information security incident simulations. Automating monitoring and reporting of policy violations. Integrating encryption key lifecycle management policies. Standardizing access controls in all ERP modules. The implementation of these recommendations is expected to enhance PT. BroilerX Yogyakarta is ready against digital security threats and supports the sustainable operation of a secure and reliable ERP system. ACKNOWLEDGEMENTS The authors would like to gratefully express their sincere thanks to PT. BroilerX Yogyakarta for the opportunities and support provided during the research process. Special thanks to the IT team for their cooperation and insights during the interviews and data collection. The authors would also like to thank the academic mentors and lecturers from the Department of Sistem Hastuti et. Security Analysis of Enterprise Resource Planning Informasi at Universitas Amikom Purwokerto for the continuous guidance and support. This research would not have been possible without the support and contributions of all parties REFERENCES