You are on page 1of 20

LOGO

A. BUDI SETIAWAN
AN ANALYSIS OF INFORMATION SECURITY
GOVERNANCE READINESS IN GOVERNMENT
INSTITUTION

The Center of Research and Development of Informatic
Application.
Agency of Human Resource Research and Development,
Ministry of ICT Indonesia
Delivered at 4
th
International Symposium on Chaos
Revolution in Science, Technology and Society
August, 28-29, 2013 in Jakarta, Indonesia
INTRODUCTION
Internet usage is increasing
ICT is enabler
The use of ICT in the public sector
Presidential Instruction No. 3/2003 about Policy & National
Strategy on the Development of e-Government
Vulnerability on ICT system
Increasing IT Risk in Indonesia
Real incident reported such as phishing, identity theft, data (information resources)
stealing, critical information resources hostages, information leakage, insider
attack (i.e. virus spread)
Cases: cyber war, fraud, web deface, hoax, etc
Malicious code, common vulnerabilities/zero day attack -pirate software are widely
used (not updated)
(source: Id-SIRTII/CC, 2012)
Recent Risk Report in Indonesia
Distributed Denial of Service attack on the system of Domain Name Service
(DNS) ccTLD-ID indicates that the attack on the domain "go.id" is the most
(source: Zone-h, 2012)
(source: Id-SIRTII, 2012)
Number of attacks to domain id website on
October 2012
THREAT
Observe the readiness of Information Security Governance
implementation in government agencies
Analysis was performed by using index of e-Government Rank
(PeGI) and Information Security Index (Index KAMI
The Study of IT Security Readiness in Government
PeGI
Index
KAMI
Trianggulation:
Expert
judgemnet
(FGD)
Indonesias Statistics
Internet users: 55,000,000 Internet users as of June.30, 2012, and
22.1% penetration.
(source : http://www.internetworldstats.com/asia.htm#id)
Internet subs: 2,3 millions


Cyber Security Legal Framework in Indonesia
National Policy and Law on Internet Security
Indonesias Act
Indonesias Telecommunication Act
(UU Telekomunikasi)


Information & Electronic Transaction Act
(UU ITE)


No. 29/PER/M.KOMINFO/10 /2010 about
Securing Telecommunication Network
Utilization based on Internet Protocol
Number: 133/KEP/M/KOMINFO/04/2010
Number: 01/SE/M.KOMINFO/02/2011
Regulation of Minister of CIT

Decree of Minister of CIT

Circular of Minister of CIT

Information Security Index
The Index of Indonesian e-Government Rank
No. Dimensions
1 Policy
2 Institutional
3 Infrastructure
4 Application
5 Planning
5 Dimensions of Indonesian e-Government Rank:
Provides a reference for the development and utilization of ICT in public sector
Provide impetus for the development of ICT in the government through the
evaluation of a large, balanced, and objective
Provides map of the environment conditions of the use of ICT in the national
government
Goals:
Indonesian e-Government Rank 2012:

Ministries
NO Ministries
DIMENSION SCORE
CATEGORY
POLICY INSTITUTIONAL
INFRASTRUCT
URE
APPLICATION PLANNING AVERAGE
1 Kementerian Keuangan 3.50 3.53 3.52 3.37 3.63 3.51 Good
2 Kementerian Pekerjaan Umum 3.10 3.52 3.11 3.34 3.52 3.32 Good
3 Kementerian Perindustrian 3.13 3.50 3.48 3.40 3.00 3.30 Good
4 Kementerian Pendidikan dan Kebudayaan 3.17 3.27 3.40 3.22 3.13 3.24 Good
5 Kementerian Tenaga Kerja dan Transmigrasi 3.10 2.96 2.83 2.94 3.16 3.00 Good
6 Kementerian Perhubungan 2.79 2.70 2.90 2.92 2.77 2.82 Good
7 Kementerian Perdagangan 2.73 2.73 3.19 2.92 2.40 2.79 Good
8 Kementerian Pertahanan 2.84 3.10 2.68 2.50 2.75 2.77 Good
9 Kementerian Pemuda dan Olah Raga 2.44 2.73 2.95 2.73 2.83 2.74 Good
10 Kementerian Perencanaan Pembangunan Nasional 2.10 2.43 3.14 2.90 2.73 2.66 Good
11 Kementerian Kesehatan 2.23 2.88 2.74 2.70 2.52 2.61 Good
12 Kementerian Energi dan Sumber Daya Mineral 1.98 2.63 2.98 2.67 2.73 2.60 Good
13 Kementerian Kehutanan 2.54 2.80 2.93 2.62 1.67 2.51 Poor
14 Kementerian Pertanian 2.63 3.03 2.69 2.37 1.67 2.48 Poor
15 Kementerian Luar Negeri 2.15 2.44 2.77 2.40 2.40 2.43 Poor
16 Kementerian Hukum dan Hak Asasi Manusia 2.17 2.33 2.26 2.63 2.70 2.42 Poor
17 Kementerian Koordinator Bidang Kesejahteraan Rakyat 2.38 2.70 2.36 2.27 2.27 2.39 Poor
18 Kementerian Riset dan Teknologi 2.10 2.87 2.55 2.60 1.70 2.36 Poor
19 Kementerian Koperasi dan Usaha Kecil dan Menengah 2.25 2.28 2.37 2.58 2.20 2.34 Poor
20 Kementerian Badan Usaha Milik Negara 1.55 2.28 2.40 2.64 2.40 2.25 Poor
21 Kementerian Koordinator Bidang Perekonomian 2.40 2.60 2.10 2.45 1.57 2.22 Poor
22 Kementerian Pariwisata dan Ekonomi Kreatif 2.19 2.57 2.24 2.03 1.67 2.14 Poor
23 Kementerian Kelautan dan Perikanan 2.02 2.67 2.07 2.38 1.40 2.11 Poor
24
Kementerian Pemberdayaan Perempuan dan Perlindungan
Anak
2.03 2.44 1.80 2.08 1.44 1.96 Poor
25
Kementerian Koordinator Bidang Politik, Hukum, dan
Keamanan
1.50 2.00 1.94 2.10 2.12 1.93 Poor
26 Kementerian Lingkungan Hidup 1.44 1.90 2.24 2.18 1.83 1.92 Poor
27 Kementerian Agama 1.43 2.04 2.46 1.88 1.48 1.86 Poor
28 Kementerian Perumahan Rakyat 1.38 1.83 1.90 2.23 1.30 1.73 Poor
29 Kementerian Pembangunan Daerah Tertinggal 1.21 1.63 1.57 1.80 1.40 1.52 Very Poor
AVERAGE 2.29 2.63 2.61 2.58 2.29 2.48 Poor
Indonesian e-Government Rank 2012:

Local Government (Provinces)
NO Provinces
DIMENSION SCORE
CATEGORY
POLICY INSTITUTIONAL INFRASTRUCTURE APPLICATION PLANNING AVERAGE
1 Jawa Barat 3.46 3.53 3.33 3.10 3.47 3.38 Good
2 Jawa Timur 3.17 3.47 3.10 2.73 2.67 3.03 Good
3 DKI Jakarta 2.88 2.73 2.90 2.77 2.80 2.82 Good
4 Yogyakarta 2.79 2.67 2.90 2.73 2.80 2.78 Good
5 Aceh 2.42 2.87 3.05 2.77 2.47 2.71 Good
6 Bangka Belitung 2.67 3.07 2.38 2.27 2.73 2.62 Good
7 Sumatera Selatan 2.71 2.60 2.67 2.40 2.67 2.61 Good
8 Gorontalo 2.42 2.47 2.48 2.60 2.87 2.57 Poor
9 Jambi 1.83 2.73 2.24 2.53 2.47 2.36 Poor
10 Jawa Tengah 2.08 2.67 2.67 2.40 1.80 2.32 Poor
11 Kalimantan Timur 2.00 2.40 2.43 2.23 2.20 2.25 Poor
12 Kalimantan Tengah 2.21 2.40 2.00 2.03 2.40 2.21 Poor
13 Nusa Tenggara Barat 2.29 2.13 1.71 2.43 1.67 2.05 Poor
14 Sumatera Barat 2.38 2.13 2.05 1.77 1.60 1.98 Poor
15 Kalimantan Barat 1.92 2.20 1.95 2.00 1.80 1.97 Poor
16 Papua 1.67 1.90 1.93 1.98 2.27 1.95 Poor
17 Sulawesi Utara 2.00 2.20 1.67 2.37 1.20 1.89 Poor
18 Kepulauan Riau 1.38 2.47 1.48 1.80 2.13 1.85 Poor
19 Sumatera Utara 1.21 2.20 1.86 1.77 1.47 1.70 Poor
20 Sulawesi Barat 1.50 1.70 1.90 1.70 1.47 1.65 Poor
21 Lampung 1.21 2.07 1.43 1.90 1.47 1.61 Poor
22 Bengkulu 1.50 1.73 1.19 1.63 1.33 1.48
Very Poor
Poor
23 Sulawesi Tengah 1.33 1.80 1.24 1.63 1.00 1.40
Very Poor
Poor
24 Kalimantan Selatan 1.00 1.47 1.00 1.67 1.00 1.23
Very Poor
Poor
AVERAGE 2.08 2.40 2.15 2.22 2.07 2.18 Poor
Analysis of Indonesian e-Government Rank
Ministries
31.03%
48.28%
20.69%
Dimension: Policy
Good Poor Very Poor
58.62%
41.38%
0%
Dimension: Institutional
Good Poor Very Poor
51.72% 44.83%
3.45%
Dimension:Infrastructure
Good Poor Very Poor
51.72%
68.28%
0%
Dimension: Application
Good Poor Very Poor
3.45%
34.48%
41.38%
20.69%
Dimension: Planning
Very Good Good
Poor Very Poor
Analysis of Indonesian e-Government Rank
Local Government (Provinces)
25.00%
45.83%
29.17%
Dimension: Policy
Good Poor Very Poor
37.50%
58.33%
4%
Dimension: Institutional
Good Poor Very Poor
29.17%
50.00%
20.83%
Dimension: Infrastructure
Good Poor Very Poor
20.83%
79.17%
0%
Dimension: Application
Good Poor Very Poor
0.00%
29.17%
41.67%
29.17%
Dimension: Planning
Very Good Good Poor Very Poor
Source: Directorate of
Information Security
Information Security Index 2012
1. Coordination between government agencies is still weak
in terms of cyber security
2. The levels of internet safety and cyber security
awareness of government agencies and public are still
low
3. Implementation of ICT security in Indonesia is still
running on silo system
4. ICT governance and information security management
systems in government agencies do not operate
effectively
Cyber Security Readiness in Government
1. Need strong commitment form all level management in
government institution related to implement IT Security
governance
2. Information security should become the spirit for all ICT
regulation and policy
3. Need particular policy from the highest level government
management which is mandate for all government
institution to implement IT Security governance
Recommendation for Cyber Security Readiness
in Government
THANK YOU
A. BUDI SETIAWAN
ICT Researcher at Center of R&D of Informatic Application
Human Resource R&D Agency, Ministry of ICT Indonesia
ahma003@kominfo.go.id
ahmed_setiawan007@yahoo.com