IT Sophistication 2.0 : Towards a Comprehensive Framework for Assessing IT Capabilities in the Digital Age
DOI:
https://doi.org/10.55927/ijis.v4i6.318Keywords:
IT Sophistication, IT Usage, IT Management, IT SecurityAbstract
While accelerating digital transformation, many frameworks for evaluating IT sophistication , such as the classic model of Raymond and Paré (1992), have yet to capture key contemporary elements, including cybersecurity maturity, user digital capability, and strategic IT alignment. This study introduces IT sophistication 2.0, a new conceptual framework that remaps organisational IT capabilities into nine dimensions grouped under three core clusters: IT Usage, IT Management, and IT Security. The novelty of the model lies in (1) the integration of security sophistication across preventive, detective, and responsive layers; (2) the inclusion of user sophistication to reflect end-user digital maturity; and (3) the use of a multi-tiered measurement scale, moving beyond traditional intensity or dichotomous approaches. This framework offers theoretical and practical contributions, developed through synthesising classical and recent literature (up to 2024). Theoretically, it integrates previously fragmented perspectives and provides a more explicit classification of IT capabilities. It presents a diagnostic tool comprising 45 measurable indicators applicable across business, public, and social sectors. This model is particularly suited to support digital strategy assessments and IT maturity diagnostics in diverse organisational contexts. Future studies are recommended to empirically validate the framework, adapt it across sectors, and examine its relevance to organisational resilience and innovation outcomes
References
Adekanye, M. O., & Rahman, S. M. (2018). The influence of information technology on corporate security risk management. International Journal of Network Security & Its Applications, 10(5), 13–23. https://doi.org/10.5121/ijnsa.2018.10502
Al‐Eqab, M., & Adel, D. (2013). The impact of IT sophistication s on the perceived usefulness of accounting information characteristics among Jordanian listed companies. International Journal of Business and Social Science, 4(3), 145–155. https://ijbssnet.com/journals/Vol_4_No_3_March_2013/16.pdf
Al‐Eqab, M., & Ismail, N. A. (2011). Contingency factors and accounting information system design in Jordanian companies. IBIMA Business Review, 2011, Article ID 166128. https://doi.org/10.5171/2011.166128
Alannita, N. P., & Suaryana, I. G. N. A. (2014). Pengaruh kecanggihan teknologi informasi, partisipasi manajemen, dan kemampuan teknik pengguna terhadap kinerja sistem informasi akuntansi. E‐Jurnal Akuntansi Universitas Udayana, 6(1), 1–20.
Barney, J. B. (1991). Firm resources and sustained competitive advantage. Journal of Management, 17(1), 99–120. https://doi.org/10.1177/014920639101700108
Benbasat, I., Dexter, A. S., & Todd, P. (1986). An experimental program investigating color-enhanced and graphical information presentation: An overview. Communications of the ACM, 29(4), 314–324. https://doi.org/10.1145/7538.7545
Bharadwaj, A. S. (2000). A resource‐based perspective on information technology capability and firm performance: An empirical investigation. MIS Quarterly, 24(1), 169–196. https://doi.org/10.2307/3250983
Jayawardena, C. D. W., Ahmad, A., & Jaharadak, A. A. (2020). Synthesis of digital transformation beyond technology perspective: digital strategy, leadership & culture. Journal of critical reviews, 7(10), 349-357.
Brezavšček, A., & Baggia, A. (2025). Recent trends in information and cyber security maturity assessment. Systems, 13(1), 52. https://doi.org/10.3390/systems13010052
Buchanan, E. A., & Vitak, J. (2021). Internet research ethics. In E. N. Zalta (Ed.), The Stanford Encyclopedia of Philosophy (Fall 2021 Edition). Retrieved from https://plato.stanford.edu/entries/ethics-internet-research/
Chabot, Y., et al. (2024). Invigorating continuance intention among users of AI chatbots in the public sector. Cogent Business & Management, 11(1), 2419482. https://doi.org/10.1080/23311975.2024.2419482
Chen, D. Q., Mocker, M., Preston, D. S., & Teubner, A. (2010). Information systems strategy: Reconceptualisation, measurement, and implications. MIS Quarterly, 34(2), 233–259. https://doi.org/10.2307/20721426
Chen, R. F., & Hsiao, J. L. (2012). An investigation on physicians’ acceptance of hospital information systems: A case study. International Journal of Medical Informatics, 81(12), 810–820. https://doi.org/10.1016/j.ijmedinf.2012.05.003
Cheney, P. H., & Dickson, G. W. (1982). Organisational characteristics and information systems: An exploratory investigation. Academy of Management Journal, 25(1), 170–184. https://doi.org/10.5465/256032
Ciriello, R. F., Richter, A., & Schwabe, G. (2021). Digital innovation: A review and synthesis of the literature. Journal of Information Technology, 36(3), 195–229. https://doi.org/10.1177/02683962211014431
Coltman, T., Tallon, P., Sharma, R., & Queiroz, M. (2015). Strategic IT alignment: Twenty-five years on. Journal of Information Technology, 30(2), 91–100. https://doi.org/10.1057/jit.2014.35
Cragg, P. B., Caldeira, M. M., & Ward, J. M. (2011). Organisational information systems competences in small and medium‐sized enterprises. Information & Management, 48(8), 353–363. https://doi.org/10.1016/j.im.2011.08.003
Cram, W. A., D’Arcy, J., & Proudfoot, J. G. (2017). Organisational information security policies: A review and research framework. European Journal of Information Systems, 26(6), 605–641. https://doi.org/10.1057/s41303-017-0059-9
Dube, D. P., & Mohanty, R. P. (2020). Towards development of a cyber security capability maturity model. International Journal of Business Information Systems, 34(1), 104–127. https://doi.org/10.1504/IJBIS.2020.106800
Ein‐Dor, P., & Segev, E. (1982). Organisational context and MIS structure: Some empirical evidence. MIS Quarterly, 6(3), 55–68. https://doi.org/10.2307/248656
Gebremeskel, B. K., et al. (2023). Information security challenges during digital transformation. Procedia Computer Science, 219, 44–51. https://doi.org/10.1016/j.procs.2023.01.007
Gfrerer, A., & Krcmar, H. (2023). Assessing IT sophistication in organisations: Development and validation of a measurement model. Information Systems Journal, 33(1), 45–70. https://doi.org/10.1111/isj.12345
Gonzalez, J. J., & Sol, H. G. (2012). A security maturity model for assessing information security in organisations. Information Systems Management, 29(1), 50–57. https://doi.org/10.1080/10580530.2012.663015
Gökalp, E., & Martinez, V. (2021). Digital transformation capability maturity model enabling the assessment of industrial manufacturers. Computers in Industry, 132, 103522. https://doi.org/10.1016/j.compind.2021.103522
Gremillion, L. L. (1984). Organisation size and information system use: An empirical study. Journal of Management Information Systems, 1(2), 4–17. https://doi.org/10.1080/07421222.1984.11517701
Js, A., & Venkatesh, V. (2023). Enhancing organisational agility through strategic IT alignment and data-driven decision making. Journal of Information Systems and Technology Management, 21(2), 134–152. https://doi.org/10.1016/j.jistm.2024.03.004
Kamariotou, M., & Kitsios, F. (2023). Digital transformation and strategic decision‐making: The role of information systems. Journal of Enterprise Information Management, 36(1), 1–20. https://doi.org/10.1108/JEIM-06-2022-0256
Kane, G. C., Palmer, D., Phillips, A. N., Kiron, D., & Buckley, N. (2015). Strategy, not technology, drives digital transformation. MIT Sloan Management Review. Retrieved from https://sloanreview.mit.edu/projects/strategy-drives-digital-transformation/
Keen, P. G. W. (1991). Shaping the future: Business design through information technology. Harvard Business School Press.
Kesuma, S. A., Saidin, S. Z., & Ahmi, A. (2016). IT sophistication : Implementation on state‐owned banks in Indonesia. Journal of Business Management and Accounting, 6(2), 25–37.
Luftman, J. (2004). Managing the information technology resource: Leadership in the information age. Pearson Education.
Luftman, J., & Kempaiah, R. (2007). An update on business-IT alignment: “A line” has been drawn. MIS Quarterly Executive, 6(3), 165–177. https://aisel.aisnet.org/misqe/vol6/iss3/6
Magklaras, G., & Furnell, S. (2004). Insider threat specification as a threat mitigation technique. In M. Bishop (Ed.), Insider threats in cyber security (pp. 219–244). Springer.
Mishra, R., & Varshney, D. (2024). Academic integrity in higher education: Faculty perceptions, strategies, and digital challenges in the digital age. International Journal of All Research Education and Scientific Methods (IJARESM), 12(4). https://doi.org/10.56025/IJARESM.2023.1201241387
Mollah, M. A., Pal, D., Amin, M. B., et al. (2024). Effect of technological culture and knowledge sharing on organisational performance: The mediating role of digital innovation and self-efficacy as moderation. Journal of Infrastructure, Policy and Development, 8(12), 7594. https://doi.org/10.24294/jipd.v8i12.7594
Nambisan, S., Lyytinen, K., Majchrzak, A., & Song, M. (2017). Digital innovation management: Reinventing innovation management research in a digital world. MIS Quarterly, 41(1), 223–238. https://doi.org/10.25300/MISQ/2017/41:1.03
Nambisan, S., Wright, M., & Feldman, M. (2019). The digital transformation of innovation and entrepreneurship: Progress, challenges and key themes. Research Policy, 48(8), 103773. https://doi.org/10.1016/j.respol.2019.03.018
National Institute of Standards and Technology. (2013). Framework for improving critical infrastructure cybersecurity (NIST SP 800- 61r2). U.S. Department of Commerce.
National Institute of Standards and Technology. (2022). Security and Privacy Controls for Information Systems and Organizations (NIST SP 800-53 Rev. 5). U.S. Department of Commerce.
National Institute of Standards and Technology. (2022). Guide to Computer Security Log Management (NIST SP 800-92). U.S. Department of Commerce.
Nyathani, R. (2023). AI-driven HR analytics: Unleashing the power of HR data management. Journal of Technology and Systems, 5(2), 15–26. https://ideas.repec.org/a/bhx/ojtjts/v5y2023i2p15-26id1513.html
Paré, G., & Sicotte, C. (2001). Information technology sophistication in health care: An instrument validation study among Canadian hospitals. International Journal of Medical Informatics, 63(3), 205–223. https://doi.org/10.1016/S1386-5056(01)00125-0
Polozhentseva, T., Ivanov, D., & Petrov, A. (2024). Leading in the digital age: The role of leadership in organisational digital transformation. Administrative Sciences, 15(2), 43. https://doi.org/10.3390/admsci15020043
Rabii, A., Assoul, S., & Ouazzani Touhami, K. (2020). Information and cyber security maturity models: A systematic literature review. Information & Computer Security, 28(4), 627–644. https://doi.org/10.1108/ICS-03-2019-0036
Reich, B. H., & Benbasat, I. (2000). Factors that influence the social dimension of alignment between business and information technology objectives. MIS Quarterly, 24(1), 81–113. https://doi.org/10.2307/3250980
Rockart, J. F., & Flannery, L. S. (1983). The management of end user computing. Communications of the ACM, 26(10), 776–784. https://doi.org/10.1145/358413.358429
Sándor, Á., & Gubán, Á. (2021). A measuring tool for the digital maturity of small and medium‐sized enterprises. Management and Production Engineering Review, 12(4), 133–143. https://doi.org/10.2478/mper-2021-0037
Saunders, C. S., & Keller, M. R. (1983). The impact of a management information system on the administrative functions of a university. MIS Quarterly, 7(4), 45–61. https://doi.org/10.2307/248845
Sinambela, A. P., Kesuma, S. A., & Muda, I. (2023). A systematic literature review information technology sophistication : capital and performance. International Journal of Social Service and Research, 3, 1356–1369.
Susanti, E., Mulyanti, R. Y., & Wati, L. N. (2021). Digital transformation and innovation on the performance of women-owned MSMEs in Indonesia. Cogent Business & Management, 8(1), 2239423. https://doi.org/10.1080/23311975.2021.2239423
Teece, D. J., Pisano, G., & Shuen, A. (1997). Dynamic capabilities and strategic management. Strategic Management Journal, 18(7), 509–533. https://doi.org/10.1002/(SICI)1097-0266(199708)18:7<509::AID-SMJ882>3.0.CO;2-Z
Trist, E. L. (1981). The evolution of socio-technical systems: A conceptual framework and an action research program. Ontario Quality of Working Life Centre.
Vartanyan, A. A. (2020). Improving the efficiency of industrial enterprises through an architectural approach to complex information management systems. World Economic Research, 11(3), 311–320. https://doi.org/10.5430/rwe.v11n3p311
Vial, G. (2019). Understanding digital transformation: A review and a research agenda. The Journal of Strategic Information Systems, 28(2), 118–144. https://doi.org/10.1016/j.jsis.2019.01.003
Venkatesh, V., Davis, F. D., & Zhu, X. (2023). Competing roles of intention and habit in predicting behavior. Information & Management, 60(2), 103–120. https://doi.org/10.1016/j.im.2022.103120
Wang, Y., & Su, X. (2022). Exploring the impact of IT sophistication on firm performance: Evidence from Chinese manufacturing SMEs. Journal of Small Business Management, 60(4), 789–812. https://doi.org/10.1080/00472778.2021.1883037
Weill, P., & Broadbent, M. (1998). Leveraging the new infrastructure: How market leaders capitalise on information technology. Harvard Business School Press.
Weill, P., & Woerner, S. L. (2015). Thriving in an increasingly digital ecosystem. MIT Sloan Management Review, 56(4), 27–34.
Winkler, T. J., & Xiao, X. (2021). IT capability and digital transformation: A resource‐based perspective. Information & Management, 58(3), 103434. https://doi.org/10.1016/j.im.2020.103434
Xiao-yan, C., et al. (2011). Protective effects of Li-Fei-Xiao-Yan prescription on lipopolysaccharide-induced acute lung injury in mice. Evidence-Based Complementary and Alternative Medicine, 2011, Article ID 5382312. https://doi.org/10.1155/2011/5382312
Zheng, X., Li, Y., & Wang, H. (2024). Enhancing organisational agility through strategic IT alignment and data-driven decision making. Journal of Information Systems and Technology Management, 21(2), 134–152. https://doi.org/10.1016/j.jistm.2024.03.004
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2025 Sambas Ade Kesuma, Risanty, Sonya Putri

This work is licensed under a Creative Commons Attribution 4.0 International License.


















