- 13/03/2017
- Category: Commentaries
The world today has arrived at a stage where it is shaken by recent phenomenon of cyber issues. The latest example is the cyberwar that President Trump inherited against North Korea missile.[1] Due to high efficiency and less calamity that cyberwar may produce, compares to actual wars with hard security and more victims on the field, the cyber war was Trump’s predecessor strategy, the former President of United States of America, Barrack Obama on the missile program against North Korea. What happens in America may occur in other places as well, or the opposite. Alas, the stage of Indonesia’s government in taking account cyber attacks or cyberwar as growing nuisance is still minuscule. The lack of concern is not only depicted from the top level of the country, but also shown in the bottom level, or in the level of Indonesian society in general. The fact is that little do most Indonesia know that Indonesia is among top three sources of cyber attacks in 2013 – 2014.[2] The explanation behind such episode might be regarding the inadequate knowledge of Indonesia’s cyber – savviness in Southeast Asia (Indonesia only reaches the percentage of 63% compares to Malaysia in 74,6% and Thailand in 72,5%).[3]
Indonesia’s Cybersecurity: How Far Have We Come?
In retrospect to the meager level of cybersecurity knowledge, the underlying assumption of Indonesia that has not yet considered cybersecurity as important cannot be taken for granted. We must, instead, re-evaluate our assumption because Indonesia has captured cybersecurity as important part of defense security today. Only, if it is not too less, it was a bit too late. The chronology was depicted by the efforts to regulate cybersecurity back in the making of regulation regarding ICT development in Indonesia in general, The Telecommunication Act, no. 36, the year 1999. The Act is quite broad and ‘flexible’ – makes it open to be the interception for adopting further transformation or accepting new knowledge related to the cyber world. It is evident to the emergence of new regulatory acts in conjunction with the Telecommunication Act. Such as; Copyright Act, No. 19/2002, Information and Transaction Electronic Act, No. 11/ 2008, Pornography Act, No. 44/2008, and finally in the recent development, Electronic System Provider, and Electronic Transaction Regulation No. 82/ 2012 to comply with Ministry of Communication and Information Technology (KOMINFO).[4] The regulations are capable of being the foundation of dealing with cybercrime. However, irony persists regarding the lacking coverage of cybersecurity within any of the regulations above in detail. Until the present time, the recent development of cybersecurity law was introduced by Global Internet Initiative (GIPI) Indonesia and Indonesia Media law and Policy Center (IMLPC) and was submitted to Badan Legislatif Dewan Perwakilan Rakyat (Legislative Body of People’s Representatives Council), as Drafted Law on Cybercrime Related to Information, Communication, and Technology (RUU-TIPITI).
Cybersecurity today is nevertheless a manifestation of any ICT developments (both infrastructures and resources). In the larger picture, cybersecurity is indeed the backbone of national integrity in tackling any attacks and handling any cyber threats. The embodiment of strengthening cybersecurity is practiced by the existing actor to monitor the posting cyber threats and to counter them, named Indonesia Security Incident Response Team on Internet Infrastructure (ID-SIRTII).[5] Under KOMINFO, ID-SIRTII is the institutionalized version of Indonesian Computer Incident Response Team (CIRT) and Computer Security Incident Response Team (CSRIT). The team is assembled to (1) provide early warning system of threat and (2) empower and train related bureaucracy or other institutions in Indonesia that may face cyber threats.[6] ID-SIRTII has successfully established and developed two types of CERT/CSRIT so far, Gov-CSRIT and Academic CSRIT. By developing these measures to face cyber threats, securitizing government-owned databases and protecting campus assets are indeed possible.
In a technical context, there is a certain standard and procedure to handle cyber threats performed by ID-SIRTII, despite the evasive and presumably ‘credential’ report on the measures. It is depicted by limited sources of reports in ID-SIRTII activities, especially in the context of cybersecurity related.[7] ID-SIRTII, in general, must be assessed due to report released by International Telecommunication Union (ITU) in 2014. The report placed Indonesia as number 5 in Asia Pacific, just one rank below Hong Kong.[8] In general, we may value this as an achievement; however, the fact is rather ‘bitter’ than the ‘sweet’ ranking number. Indonesia compares to Hong Kong only surpasses the ‘legal’ indicator and matches the ‘cooperation level.’ The technical, organizational, and capacity indicators still lagged behind Hong Kong with the gap of 0.2000 – 0.3000.[9] In other words, the legal approach to regulating cybersecurity is prevailing, but not with the technical, organizational, and capacity, or in this respect related to ID-SIRTII and other bodies related to cybersecurity in Indonesia.
Beside ID-SIRTII, there is an establishment of Indonesia Computer Emergency Response Team (ID-CERT) that is based on community and has no operational authority towards cyber incidents domestically nor internationally. The membership is voluntary based and has been established before the regulation of ICT in Indonesia being legalized, on 1 December 1998.[10] The achievement of ID-CERT is rather vital; ID-CERT was the founding father of APCERT (Asia Pacific Computer Emergency Response Team in 2001-2003), and furthermore, the reports that ID-CERT has received and responded are transparent (265.194 reports and 868 responses in 2012 and also 133.297 reports and 1.244 responses in 2013).[11] ID-CERT is a credible institution that may help to strengthen the government – assembled organization to tackle cybersecurity issues in Indonesia, ID-SIRTII.
Cybersecurity in Indonesia: Where Should We Go?
In Indonesia, a topic on cybersecurity, besides on the regulatory context and institutional context, has not embarked in depth – discussion just yet. According to ESET in 2015, Indonesia ranked bottom in term of cyber savviness knowledge (among Singapore, Malaysia, Thailand, India, and Hong Kong) in 25,1% compares to Malaysia in 29,9%.[12] People in Indonesia bureaucracy barely knew or even grasped the sense of cybersecurity; making the inclusion of cybersecurity bizarre and too banal from time to time. Long story short, the discourse on cybersecurity was and is being left hanging far away behind other topics related to ICT development in Indonesia, such as smart city, financial technology, or e-government. Not to mention, the visibility of integrating triple-helix coordination on strengthening cybersecurity in Indonesia based on Public – Private Partnership (PPP) still endures deficit progress.[13] Industries, as they continue to grow significant roles in cybersecurity need to establish cooperation with government and also academic institutions to nurture cyber awareness among society. Indeed, there is a discrepancy out of cybersecurity discussion that needs to be mapped out. Otherwise, it may cost ‘time – bomb’ of cyber-wellness for Indonesia in the future.
Today, the thorough discussion of cybersecurity in Indonesia have already reached the culminated point where the weaknesses must be scrutinized, and the strategic direction can be designed. Based on the weaknesses, we may identify that we have the regulatory supports, but no law specifies on cybersecurity in detail. Even then, regulations are still largely scattered as well. On a practical level, we have particular bodies, both at the administrative level and also at the community level, but there is no such thing as synchronization or inter-organizational meeting to train, educate, or even empower other bodies related to cybersecurity issues. Let alone the inter-organizational meeting on the top level of the country, and we must also take account society awareness of cybersecurity. At last, to answer the question on whether or not we are ready; regardless the condition we must assure that we are. But of course, we need further equipped knowledge, management on measurement, and pre-emptive stratagem on our national cybersecurity.
picture: pixabay
[1] Sanger, E., and Broad, W. 2017. ‘Trump Inherits a Secret Cyberwar Against North Korean Missile’, New York Times, Available from: nytimes.com [online]. 4 March. https://www.nytimes.com/2017/03/04/world/asia/north-korea-missile-program-sabotage.html?_r=0, [6 March 2017].
[2] Parameswaran, P. 2016, ‘Does Indonesia Need a New Cyber Agency?’, The Diplomat, Available from: thediplomat.com [online]. 21 September. http://thediplomat.com/2016/09/does-indonesia-need-a-new-cyber-agency/, [6 March 2017].
[3] ESET. 2017. 2015 ESET Asia Cyber Savviness Report, ESET.com [online]. 9 January. Available from https://www.eset.com/sg/about/press/articles/whitepapers/article/2015-eset-asia-cyber-savviness-report/, [6 March 2017].
[4] DAKA Advisory. 2016. Meeting the Cybersecurity Challenge in Indonesia, Sweden: DAKA Advisory, pp. 26 – 27.
[5] Setiadi, Sucahyo, and Hasibuan, Z. 2012. ‘An Overview of the Development Indonesia National Cyber Security’, in International Journal of Information Technology & Computer Science (IJITCS), (ISSN No: 2091-1610), Volume 6: Issue on November / December, p. 110, (this paper is presented on: International Conference on Information Technology, E-Government and applications) (ICITEA 2012).
[6] DAKA Advisory. 2016. p. 27.
[7] IDSIRTII, Laporan Kegiatan. Available from: idsirtii.or.id [online], http://www.idsirtii.or.id/halaman/tentang/laporan-kegiatan.html. [7 March 2017].
[8] ABI Research. 2014. GLOBAL CYBERSECURITY INDEX, Sweden: International Telecommunication Union, p. 8.
[9] ABI Research. 2014. p. 8.
[10] Alkazimy, A. 2014. Tren dan Peringatan Keamanan ID-CERT 2014’ [Power Point Presentation], Computer Emergency Response Team, 15 October 2014, Padang: Indonesia, slide 3.
[11] Alkazimy, A. 2014. slide 6.
[12] ESET. 2017.
[13] DAKA Advisory. 2016. pp. 34 – 35.