Prioritizing Governance of the COBIT 2019 DSS02 Domain Based on Incident Management Data

Authors

  • Lahan Adi Purwanto Department of Informatics Engineering, Universitas Muhammadiyah Purwokerto
  • Achmad Fauzan Department of Informatics Engineering, Universitas Muhammadiyah Purwokerto

DOI:

10.33395/sinkron.v10i3.16421

Keywords:

COBIT 2019, data-driven governance, DSS02, event log, incident management, operational indicators

Abstract

Information technology (IT) governance plays a crucial role in ensuring service quality, and COBIT 2019 provides a structured framework for incident management through the DSS02 domain. However, DSS02 implementation is commonly evaluated using surveys or capability assessments that are subjective, difficult to reproduce, and challenging to verify independently, despite the availability of detailed operational event logs in IT service management platforms. This study proposes an event-log-based approach to identify governance improvement priorities within the COBIT 2019 DSS02 domain. Five operational indicators were developed, namely the Process Complexity Index (PCI), Operational Interaction Index (OII), Reassignment Indicator (RI), Reopened Incident Indicator (RII), and Delay Severity Index (DSI). These indicators were mapped to DSS02 subprocesses and integrated into a Governance Priority Score (GPS), which was evaluated using local sensitivity analysis and Spearman correlation analysis on a ServiceNow event log containing 141,707 events and 24,918 incidents. The results identified DSS02.04 (Investigate, Diagnose and Resolve) as the highest governance priority (GPS = 5.06), followed by DSS02.02 (4.27) and DSS02.03 (1.14). Sensitivity analysis showed that moderate (±10%) changes in indicator weights did not alter the priority ranking, while correlation analysis revealed a strong relationship between reassignment frequency and incident modification activity (ρ = 0.67). The proposed approach provides an objective, reproducible, and auditable data-driven prioritization mechanism that complements conventional survey-based governance assessment using operational event logs.

GS Cited Analysis

Downloads

Download data is not yet available.

References

Amaral, C. A. L., Fantinato, M., & Peres, S. (2018). Incident Management Process Enriched Event Log [Dataset]. UCI Machine Learning Repository. https://doi.org/https://doi.org/10.24432/C57S4H

Augusto, A., Conforti, R., Dumas, M., Rosa, M. La, Maggi, F. M., Marrella, A., Mecella, M., & Soo, A. (2019). Automated Discovery of Process Models from Event Logs: Review and Benchmark. IEEE Transactions on Knowledge and Data Engineering, 31(4), 686–705. https://doi.org/10.1109/TKDE.2018.2841877

Augusto, A., Mendling, J., Vidgof, M., & Wurm, B. (2022). The Connection Between Process Complexity of Event Sequences and Models Discovered by Process Mining. Information Sciences, 598, 196–215. https://doi.org/10.1016/j.ins.2022.03.072

Caturkusuma, R. M., Alzami, F., Nurhindarto, A., Sulistiyono, M. T., Irawan, C., & Kusumawati, Y. (2025). Predicting IT Incident Duration using Machine Learning: A Case Study in IT Service Management. Sinkron, 9(1), 8–19. https://doi.org/10.33395/sinkron.v9i1.14310

De Haes, S., Van Grembergen, W., Joshi, A., & Huygh, T. (2020). Enterprise Governance of Information Technology. Springer International Publishing. https://doi.org/10.1007/978-3-030-25918-1

Garcia, C. dos S., Meincheim, A., Faria Junior, E. R., Dallagassa, M. R., Sato, D. M. V., Carvalho, D. R., Santos, E. A. P., & Scalabrin, E. E. (2019). Process mining techniques and applications – A systematic mapping study. Expert Systems with Applications, 133, 260–295. https://doi.org/10.1016/j.eswa.2019.05.003

Hardjadinata, M. B., & Wiratama, J. (2023). Capability Assessment of IT Governance Using the 2019 COBIT Framework for the IT Business Consultant Industry. International Journal of Science, Technology & Management, 4(4), 1034–1039. https://doi.org/10.46729/ijstm.v4i4.902

Huygh, T., & De Haes, S. (2019). Investigating IT Governance through the Viable System Model. Information Systems Management, 36(2), 168–192. https://doi.org/10.1080/10580530.2019.1589672

ISACA. (2018). COBIT 2019 framework : governance and management objectives. ISACA.

ISACA. (2019). COBIT 2019 Design guide designing an information and technology governance solution.

Kouzari, E., Sotiriadis, L., & Stamelos, I. (2023). Enterprise Information Management Systems Development Two Cases of Mining for Process Conformance. International Journal of Information Management Data Insights, 3(1), 100141. https://doi.org/10.1016/j.jjimei.2022.100141

Kouzari, E., & Stamelos, I. (2024). A Tertiary Study for Process Mining. Algorithms, 17(12), 548. https://doi.org/10.3390/a17120548

Marin-Castro, H. M., Morales-Sandoval, M., González-Compean, J. L., & Hernandez, J. (2024). A Novel Trace-Based Sampling Method for Conformance Checking. PeerJ Computer Science, 10, e2601. https://doi.org/10.7717/peerj-cs.2601

Meyer, C., Heininger, R., & Stary, C. (2024). Improving Vulnerability Management Through Process Mining. Applied Sciences, 14(23), 11392. https://doi.org/10.3390/app142311392

Mulyana, R., Rusu, L., & Perjons, E. (2024). Key Ambidextrous IT Governance Mechanisms for Successful Digital Transformation: A Case Study of Bank Rakyat Indonesia (BRI). Digital Business, 4(2), 100083. https://doi.org/10.1016/j.digbus.2024.100083

Raptaki, M., Stergiopoulos, G., & Gritzalis, D. (2024). Automated Event Log Analysis With Causal Dependency Graphs for Impact Assessment of Business Processes. IEEE Access, 12, 194322–194339. https://doi.org/10.1109/ACCESS.2024.3520420

Rosid, A., Lailiya, N., & Shina, M. Y. I. (2025). Measuring The Governance Capability of The BYOND by BSI Application Using Cobit 2019: Focusing on The DSS02 Domain for Strengthening Management Information Systems. Journal of Information System, Applied, Management, Accounting and Research, 9(4), 1349. https://doi.org/10.52362/jisamar.v9i4.2058

Schad, J., Sambasivan, R., & Woodward, C. (2022). Predicting Help Desk Ticket Reassignments with Graph Convolutional Networks. Machine Learning with Applications, 7, 100237. https://doi.org/10.1016/j.mlwa.2021.100237

van der Aalst, W. (2016). Process Mining. Springer Berlin Heidelberg. https://doi.org/10.1007/978-3-662-49851-4

Vidgof, M., Wurm, B., & Mendling, J. (2023). The Impact of Process Complexity on Process Performance: A Study Using Event Log Data. In A. and J. C. and S. S. Di Francescomarino Chiara and Burattin (Ed.), Business Process Management (pp. 413–429). Springer Nature Switzerland. https://doi.org/10.1007/978-3-031-41620-0_24

Downloads


Crossmark Updates

How to Cite

Purwanto, L. A., & Fauzan, A. (2026). Prioritizing Governance of the COBIT 2019 DSS02 Domain Based on Incident Management Data. Sinkron : Jurnal Dan Penelitian Teknik Informatika, 10(3), 1962-1972. https://doi.org/10.33395/sinkron.v10i3.16421