STMIK Amik Riau implements an integrated information system to support a fast and real-time information management process where each service has its security. In this study, the analysis used to determine the maturity level of information system security governance was the COBIT 2019 framework with a CMMI scale. In COBIT 2019 the domains used were DSS05 and APO13. Based on the result of the analysis, the results of the average value of the overall maturity level on the security of the academic information system of STMIK Amik Riau were currently at level 3, which was defined. It meant that the security of the information system was running well but needed to be evaluated and optimized continuously. The value of each sub domain was 3.08 for the DSS05 sub domain (user), 3.35 for DSS 05 sub domains (maintainer), and 2.5 for APO13 sub domains (maintainer). Then the average result obtained from the gap was 0.53, meaning that the current level of maturity level with the desired maturity level is not too far away and can be increased by providing recommendations.