Towards Indonesia’s Digital Transformation – Information Security in Interoperability and Government Application Streamlining

Author: Audley Thania Teshalonica Siagian

Editor: Iradat Wirid

Introduction

Electronic government (e-Government) initiatives have become an important part of modern governments around the world, aiming to increase efficiency, transparency and accessibility in government systems [1]. Its implementation in Indonesia, through the ‘Sistem Pemerintahan Berbasis Elektronik’ (SPBE), faces complex challenges like other developing countries [2] such as inadequate infrastructure, technology, regulations, financing and human resources [3]. Indonesia, with around 27,000 government applications, experiences difficulties and obstacles in providing user-centered services [4]. To overcome this, the government has decided to focus on developing 9 SPBE superapps [5]. On the other hand, increasingly advanced developments in ICT adaptation complicate the challenge of controlling applications that threaten privacy [6]. Therefore, information security and local government capabilities for integration towards superapps are still important issues that need to be addressed. The main challenge is to ensure interoperability and information security are well integrated in SPBE implementation.

Interoperability and Information Security Challenges in SPBE

Interoperability refers to the ability of ICT systems and associated business processes to exchange data and facilitate the sharing of information and knowledge. There are three dimensions of interoperability that must be considered, namely organizational interoperability, semantic interoperability, and technical interoperability [7]. Interoperability goes beyond the ability to manage data from different systems, but also administrative collaboration, information processing capabilities, etc.

The governments of other countries, including Australia, Brazil, Denmark and the UK, have prepared a Government Interoperability Framework to increase interoperability [8]. In Indonesia, the Ministry of Communication and Information introduced the concept of interoperability almost two decades ago [9]. In 2019, Indonesia launched the Satu Data Indonesia initiative to establish data standards to facilitate interoperability within SPBE [10]. In 2023, regulations regarding Data Interoperability in the Implementation of SPBE and Satu Data Indonesia will also be implemented, which highlight technical and semantic approaches to interoperability [11].

In developing an effective SPBE in Indonesia, security is a primary concern because the e-government handles a large amount of sensitive and legal information that must be protected from unauthorized access [12]. This includes information such as personal data, financial transactions, and legal documents that require strict protection [13]. In Indonesia, the National Cyber and Crypto Agency (BSSN) has regulated information security in the implementation of e-government through BSSN Regulation 4/2021 concerning SPBE Information Security Management Guidelines and Technical Standards and SPBE Security Procedures [14].

Even though the government has implemented policies in interoperability and information security, these two things are still challenges. Data standardization is still a challenge due to various factors such as human resource capabilities, leadership, technology, regulations, and financing [15]. Existing regulation [16] do not adequately address security issues that may arise from interoperability with other applications. Instead, the regulations focus more on the security standards that need to be met when developing new applications, without considering security integration for existing systems. Information security when the government application is ‘closed’ or stops operating has also not been regulated in detail.

The results of the latest information security assessment show that SPBE security in Indonesia needs to be improved. The IT Security Assessment conducted by BSSN for SPBE in 2023 identified 2,860 security vulnerabilities across 586 government electronic systems.. The type of vulnerability with the highest level of risk is Insecure Data Object Reference, which allows threat actors to easily access or modify data without requiring adequate validation or authorization [17]. This indicates the need for further efforts to strengthen security within SPBE to protect the integrity and confidentiality of information. Although Indonesia has demonstrated a commitment to establishing policies to support interoperability and information security, achieving these goals requires a holistic approach that combines policy, management and technological capabilities [18].

Superapps Policy and Implementation Gaps

In the midst of these challenges, new policies have emerged that change the focus of interoperability. Through Presidential Regulation Number 82 of 2023 which regulates the development of 9 priority SPBE superapps for public services, regional governments are directed to accelerate digital transformation through the use of the superapps [19]. However, interoperability in this latest policy only regulates interoperability between applications, not yet interoperability for local governments. Even though many of these applications are local government applications.

How data and information that has been collected from thousands of previous applications will be managed or treated also requires attention. Although PP 71/2019 has regulated that users have the right to delete data deemed ‘irrelevant’, which can be submitted to the court regarding electronic system providers, the technical criteria regarding data relevance are still not clearly defined. This raises the need to clarify these technical aspects to ensure consistent and effective data protection for application users [20].

Conversely, decentralization has given previous regional governments the freedom to develop their own system. As a result, various agencies and local governments may have adopted different cybersecurity tools from different vendors. When local governments are directed to use superapps in providing services, the ability to integrate existing security tools with superapps also needs to be considered. Communication failures between these applications can create a fragmented cybersecurity environment, making it difficult to thoroughly identify security threats and coordinate effective responses [21].

At the local level, responsibility for evaluating and auditing e-government security often falls to local governments or related agencies. They employ trusted agents for this purpose. System evaluation has been carried out separately [22]. When local governments are directed to use these superapps, the previous SPBE implementation ecosystem can potentially be ‘disrupted’ which can have an impact on service delivery performance. Given the differences in regulations and policies at the regional level, this adjustment will also have an impact on aspects of technology, human resources and capital. Clear guidelines and policies are needed in the implementation of these superapps at the regional level and how information security will be maintained. This policy must ensure that evaluation, auditing and procurement of SPBE can be carried out effectively and efficiently amidst efforts to centralize SPBE and still enable local governments to achieve SPBE development targets.

Ultimately, the formation of innovative policies and programs at the national level must consider their implementation at the local level so that the digital transformation implemented is not only instrumental, but also systemic, inclusive and user-oriented, including citizens, businesses and government [23]. In addition to ensuring quality public services, it is important to identify information security challenges in the process of implementing superapps for local governments so that information security strategies can be developed properly. Challenges that have long been faced in implementing SPBE, such as technology, infrastructure and human resources, also need to be considered seriously to increase the effectiveness of e-government in the future. With this approach, it is hoped that digital transformation can take place holistically and sustainably, providing real benefits for all stakeholders.

Referensi

[1] United Nations. (2022). E-Government Development Index. Available at: https://publicadministration.un.org/egovkb/en-us/About/Overview/-E-Government-Development-Index [Accessed May 2024]

[2] Pangaribuan, A.A. (2019). The challenges of e-government implementation in developing countries. JPAS (Journal of Public Administration Studies), 4(1), pp.260-29.

[3] Nugroho, R.A. and Purbokusumo, Y., 2020. E-Government Readiness: Penilaian Kesiapan Aktor Utama Penerapan E-Government di Indonesia (E-Government Readiness: Main Actor Readiness Assessment for E-Government Application in Indonesia). JURNAL IPTEKKOM Jurnal Ilmu Pengetahuan & Teknologi Informasi, 22(1), pp.1-17.

[4] Isdarmadji, N.Q. (2023) Menteri Panrb Tekankan anggaran Negara Harus Berdampak Bagi Masyarakat, Kementerian Pendayagunaan Aparatur Negara dan Reformasi Birokrasi. Available at: https://www.menpan.go.id/site/berita-terkini/menteri-panrb-tekankan-anggaran-negara-harus-berdampak-bagi-masyarakat (Accessed: May 2024).

[5] Azhar, M. (2024) Pemerintah Indonesia Akan luncurkan 9 ‘superapps’, Dari Digital ID, Pendidikan, Hingga Layanan Kesehatan, Gov Insider Asia. Available at: https://govinsider.asia/indo-en/article/pemerintah-indonesia-akan-luncurkan-9-superapps-dari-identitas-digital-hingga-layanan-kesehatan (Accessed: May 2024).

[6] Aquilina, K. (2010) ‘Public security versus privacy in technology law: A balancing act?’, Computer Law & Security Review, 26(2), pp. 130–143. doi:10.1016/j.clsr.2010.01.002.

[7] Laskaridis, G., Markellos, K., Markellou, P., Panayiotaki, A., Sakkopoulos, E. and Tsakalidis, A., (2007). E-government and Interoperability Issues. International Journal of Computer Science and Network Security, 7(9), pp.28-38.

[8] Lallana, E., (2007). E-Government Interoperability: A Review of Government Interoperability Frameworks in Selected Countries. Bangkok, Thailand: UNDP. http://www.unapcict.org/ecohub/resources/e-government-interoperability-a-review-of.

[9] Fajar, M.N. (2023) ‘Challenges of interoperability governance in village and SUB-DISTRICT Profile Information System as an effort to support the One Data Indonesia program’, Jurnal Analis Kebijakan, 7(1), pp. 48–68. doi:10.37145/jak.v7i1.601.

[10] Peraturan Presiden No.39 Tahun 2019 Tentang Satu Data Indonesia (Indonesia). Available at: https://peraturan.bpk.go.id/Details/108813/perpres-no-39-tahun-201

[11] Peraturan Menteri Komunikasi dan Informatika Nomor 1 Tahun 2023 tentang Interoperabilitas Data Dalam Penyelenggaraan Sistem Pemerintahan Berbasis Elektronik dan Satu Data Indonesia. Available at: https://jdih.kominfo.go.id/produk_hukum/view/id/857/t/peraturan+menteri+komunikasi+dan+informatika+nomor+1+tahun+2023

[12] Hassan, R.G. and Khalifa, O.O., (2016). E-Government-an information security perspective. International Journal of Computer Trends and Technology (IJCTT), 36(1), pp.1-9.

[13] Otjacques, B., Hitzelberger, P. and Feltz, F. (2007) ‘Interoperability of E-Government Information Systems: Issues of identification and Data Sharing’, Journal of Management Information Systems, 23(4), pp. 29–51. doi:10.2753/mis0742-1222230403.

[14] Peraturan Badan Siber dan Sandi Negara Nomor 4 Tahun 2021 tentang Pedoman Manajemen Keamanan Informasi Sistem Pemerintahan Berbasis Elektronik dan Standar Teknis dan Prosedur Keamanan Sistem Pemerintahan Berbasis Elektronik. (Indonesia). Available at: https://peraturan.bpk.go.id/Details/174275/peraturan-bssn-no-4-tahun-2021

[15] Prasetiya, W.S., Fauzi, A.A., Taufiq, O.H., Garvera, R.R. and Arifin, F.S., (2022). TANTANGAN IMPLEMENTASI SATU DATA INDONESIA DI PEMERINTAH DAERAH KABUPATEN/KOTA (STUDI KASUS KABUPATEN CIAMIS).

[16] Munandar, A. (2023) ‘KEAMANAN SPBE PADA TRANSFORMASI DIGITAL’. Direktorat Keamanan Siber dan Sandi Pemerintah Daerah.

[17] BSSN. (2022). LANSKAP KEAMANAN SIBER INDONESIA 2022. BADAN SANDI DAN SIBER NEGARA.

[18] Pardo, T.A. and Burke, G.B., (2008). Improving Government Interoperability: A capability framework for government managers. Center for Technology in Government, University of Albany.

[19] Azhar, M. (2024) Pemerintah Indonesia Akan luncurkan 9 ‘superapps’, Dari Digital ID, Pendidikan, Hingga Layanan Kesehatan, Gov Insider Asia. (Accessed: May 2024).

[20] Waruwu, R. (2022) Penghapusan Informasi Elektronik dan/atau Dokumen Elektronik, Sekolah TInggi Ilmu Hukum Painan. (Accessed: May 2024).

[21] Crumpler, W.D. and Lewis, J.A., 2022. Cybersecurity and the Problem of Interoperability. Center for Strategic and International Studies (CSIS).

[22] BSSN. (2022). Audit Keamanan SPBE. Badan Siber Dan Sandi Negara Indonesia. (Accessed: May 2024) Available at: https://www.bssn.go.id/audit-keamanan-spbe/

[23] Pitaloka, D., & Idris, I. K. (2022). Wacana ‘Super Apps’: Pemerintah perlu menjamin akses yang inklusif dan perlindungan data pribadi, jangan hanya latah teknologi. The Conversation. https://theconversation.com/wacana-super-apps-pemerintah-perlu-menjamin-akses-yang-inklusif-dan-perlindungan-data-pribadi-jangan-hanya-latah-teknologi-187001