16
6
Students name : Scoots Bar
Course number and Name : IEE 454 - Risk Management
Instructors Name : Brittany Holloman
RISK MANAGEMENT OF CYBERCRIME THREATS
(CYBER CRIME)
.
1.0 Introduction:
Development globalization and technology information has brought great changes in
human life. Information technology makes communication relationships between humans and
between nations easier and faster without being influenced by time and space. Globalization
is a process of changing the dynamics of the global environment as a continuation of the
situation that was once ever existing before characterized by advances in technology and
information, leading to interdependence, blurring of national boundaries (borderless).2 The
impact of development technology and information technology has changed the course of war
happening right now.
The era of globalization encourages some countries to no longer use traditional and
conventional ways of warfare traditional and unconventional ways of war. As a result, the
strength of the state is no longer seen in the strength of weapons, but also in terms of culture,
economy, politics, and technology. This makes competition and warfare increasingly
invisible. Wars and conflicts that occur in a country are not only dominated by military
forces, but non-military forces are also carried out by non-state actors. Threats that evolve
into cyberattacks are not just a concept. The vulnerability of information exchange in
cyberspace has encouraged countries to build security systems that can overcome these
threats. The events in Estonia in 2007 and Georgia in 2008 are examples of cybercrime
attacks using Distributed Denial of Service (DdoS), which paralyzed the country's activities
because many critical sectors were attacked.3 Another attack that has been noted to be quite
alarming is the Stuxnet attack. Stuxnet is an example of highly sophisticated malware that
managed to paralyze one-fifth of the nuclear enrichment control systems of Iran's nuclear
power plants.4
Threats in cyberspace are dominated by non-state actors such as individual hackers,
hacker groups, hacker activities, non-government organizations (NGOs), terrorism,
organized criminal groups and the private sector (such as internet companies and carries,
security companies) can also threaten the defense and sovereignty of the state cybercrime has
occurred in the case of interception of personal communications of the President of Indonesia and
several high-ranking state officials by Australia based on documents leaked by Edward Snowden, a
former contractor of the National Security Agency (NSA) from America.6 In addition, one of the
official websites of the Ministry of Defense of the Republic of Indonesia (Kemhan RI) was broken
into by hackers, namely the website belonging to the Directorate General of Defense Potential (Ditjen
Pothan) which experienced a page change called defacing7 . The site was broken into by CVT (Cyber
Vampire Team) by writing the site page "Oops Myanmar Hacker was here". Then write a sentence in
English, namely:
Hello Indonesia Government, you should be proud with uneducated Indo script kiddies.
Coz they believe (defacing / Ddosing) to other country website is the best solution for them. If
you would sympathize the white programmers/ developers of your country and how they are
feeling. You can catch such script kiddies. Coz CVT are ready to provide those kiddies
information.
Global threats, advances in technology and information are not only aimed at attacking
government and military agencies, but can also threaten all aspects of human life, such as the
economy, politics, culture, and security of a country. Recently, a cyberattack also occurred on
the website of the government-owned telecommunications industry. The threat of cybercrime
can occur due to the interests of various individuals or groups. This threat in the aspect of
people's lives poses various real or unreal physical threats by using computer codes
(software) to steal information and data that can threaten a country.
The increase in the threat of cybercrime committed by both state and non-state actors
has an impact on the occurrence of cyber warfare or cyber violence. The country's
dependence on communication networks brings its own challenges and threats. Therefore,
risk management analysis is needed in the face of cyber crime attacks with the aim of
maintaining the defense and sovereignty of the Republic of Indonesia in realizing national
goals. Risk management can be interpreted as a series of procedures and methodologies used
to identify, measure, monitor and control risks arising from organizational activities. Risk
management in the field of information and communication that relates to the lives of many
citizens or is confidential, is something that is done to reduce the level of vulnerability of
misuse of information and data in cyberspace.
Risks that occur in facing the threat of cyber crime come from within and outside the
country by utilizing social, political, cultural, ideological conditions and technological
16
8
developments. Many ways are done by various parties to obtain information in the State
Defense Information System (Sisfohanneg). Some attacks have even been carried out, for
example, hacking action by defacing the website of the Director General of Pothan Kemhan.
The leaking of information related to national defense contained in Sisfohanneg can threaten
state sovereignty, especially information sovereignty. The concept of risk management in
defense is an important element to analyze how much a threat impacts national defense.
In the context of facing the threat of cyber crime attacks, it cannot be solved by using
only the power of weapons. But it requires the integration of all national forces under the
command and control (Kodal) of the Ministry of Foreign Affairs. Defense (MoD). The risks
faced in overcoming the threat of cyber crime are no less than conventional warfare. The use
of cyber technology has a broad impact because it can cover various aspects of social and
state life, including the fields of ideology, politics, economics, socio-culture, and security.
Cyber crime is increasing which is utilized by certain parties either individually or in groups
or countries with a specific purpose to be able to weaken their opponents. This condition
needs to be watched out for because it does not rule out the possibility that a country can be
paralyzed and destroyed by technological warfare or through cyber.11
As a sovereign and civilized nation, it is necessary to maintain the integrity of a country
by building a strong national defense in order to achieve the goals of national interests. The
various conditions above illustrate the importance of risk management identification in
dealing with the threat of cyber crime in the management of national defense development.
1.1 Definition of Cyber Crime:
Technology is an activity that is born by humans with planning and creating material
objects of practical value, such as cars, airplanes, televisions are the result of technological
development. Judging from the function and importance of technology, all circles of society
and government agencies are very dependent on technology both used for positive and
negative things. The words cyber and technology are described from the origin of the word
technique, from the Greek word Technikos which means art or skill in and logos is limo or
the main principles of cyber (software).12 The increasing use of cyberspace in all lines of
people's lives in the current era of globalization in parallel, will connect to the use of an
internet technology network in certain objects or sectors according to the purpose of its
operation.
Cyberspace is a space where communities are interconnected using networks (e.g. the
internet) to carry out various daily activities.13 Cyber is defined by another term, cyberspace,
which is derived from cybermetrics data. Initially, the term cyberspace was not intended to
describe interactions that occur through computer networks. John Perry Barlow in 1990
applied the term cyber to the internet network. In its development, cyber Internet applications
can bring positive and negative impacts that can lead to crimes in the development of the
cyber world. Crimes that are born as a negative impact of the development of applications on
the internet are called cyber crimes, which include all types of crimes and their modus
operandi carried out as a negative impact of internet applications.
In the opinion of Mcdonnell and Sayers, cyber threats are of three types,14 namely:
Hardware threat
This threat is a threat caused by the installation of certain devices that function to perform
certain activities in a system, so that the equipment is a disruption to network systems and
other hardware.
Software threat:
This threat is a threat caused by the introduction of software software that functions to carry
out theft, destruction, and manipulation of information.
Data/information threats (data/ information threat):
This threat is a threat caused by the dissemination of certain data/information aimed at the
interests of the community.
In the Strategic Cyber Security study National, defines the threat of cybercrime as every
condition and situation as well as the ability that is considered to be able to perform actions
or interference or attacks that are capable of damaging or everything that is detrimental so as
to threaten the confidentiality, integrity, and availability of systems and information.15 Cyber
threats can occur due to the interests of various individuals or groups in certain aspects of
community life that can cause various physical threats, both real and unreal by using
computer codes (software) to steal information (information theft), system destruction,
information manipulation (information corruption) or hardware (hardware) to disrupt the
system (network instruction) or disseminate certain data and information to carry out
propaganda activities.16
17
0
The sources of cyber threats can come from various sources, such as foreign
intelligence services, disaffected employees, investigation journalists, extremist
organizations, and hacktivist activities, and groups crime groups organized crime groups.
The risk of cyber crime has the potential to lose data information systems, military
activities and other disruptions that use computer networks and the internet. In looking at the
sources of threats above, the government through the Ministry of Defense (Kemhan) needs to
prepare itself in facing this cyber threat. The Ministry of Defense needs to prepare Human
Resources who are reliable in mastering technology, reliable infrastructure systems, and
supported by legislation or policies in carrying out cyber warfare operations.
2.0 Discussion:
Indonesia is among the top five countries that use social media and is considered a
potential positive (strength) or potential negative (vulnerability/weakness) when it comes to
the potential for cyber warfare. The use of social media among the public can potentially
threaten state sovereignty. But on the other hand, social media can also be a source of
knowledge about the world of information, communication and digital technology, so that
people can be digitally literate. The activities of Indonesian people who use digital
technology will eventually become a potential in cyber warfare. The use of information
technology will be easily tapped or hacked by hackers and crackers from foreign countries,
thus creating vulnerability, especially intelligence information that uses cyberspace as a
means of transmission. Rapidly advancing wiretapping technology to hack various social
media users will be very dangerous in the era of cyber warfare.
Risk management is defined as "the process of understanding and managing the risks
that an organization is inevitably subject to in attempting to achieve its corporate
objectives".17 Risk management is also defined as "the essence of risk management lies in
maximizing the areas where we can mitigate risk have some control over the outcome while
minimizing the areas where we have absolutely no control over the outcome, and the linkage
between effect and cause is hidden from us".18
Referring to the two definitions above, risk management is a continuous process,
carried out during defense management activities in the face of cybercrime threats. Risk
management is management that plans advanced plans in the face of risk and uncertainty in
order to maximize the achievement of objectives.
Elements of risk management according to the Institute of Risk Management include
Risk Assessment, which is the process of identifying, describing and estimating; Risk
Evaluation, decision-making about significant risks that should be assigned to a risk
management program. Risk treatment depends on risk appetite; risk treatment, risk appetite is
carried out response or treatment which is a process of selection and implementation. The several
stages in the risk management process that can be implemented in dealing with the threat of cyber
crime are described below: 19
Identify:
In this stage, the identification of cybercrime risks should be carried out periodically against
the triggers of cybercrime. In this process, all aspects that have the potential to cause harm
are carefully identified. All identified risks are then measured. The risk measure for this
threat refers to two measures, namely Probability and Impact Probability.
Assess:
In this stage, assess or assessment basically assesses the level of risk posed by cybercrime
that impacts all aspects of life, especially national defense. The assessment of cybercrime
cannot be measured directly but can use a matrix table in measuring the risks posed by
cybercrime.
Treat:
After identifying and Risk measurement is then used as a basis for determining the treatment
and response to risk, whether the risk will be accepted, transferred, minimized or avoided. In
this case, it is necessary to minimize the theft of information and data that often occurs both
individually and institutionally.
Control:
Continuous monitoring and adjustments should be made to assess the success of risk
management. In the monitoring process, there should be an early warning mechanism for
security controllers such as the Ministry of Defense of the Republic of Indonesia, so that
controllers can take the necessary actions to anticipate cybercrime.
Risk Matrix:
The potential threat of cyber crime leads to cyber warfare. The potential threats of cyber
crime in Indonesia are as follows.
Hacking
17
2
Hacking cases have occurred several times in Indonesia. The causes vary from simply
hacking security to rejection of government discourse. For example, in the 2014 presidential
election, news spread that the General Election Commission (KPU) website had been hacked
by hackers. The indication is that the KPU site could not be accessed.20
Not only in the government sector, but private parties often experience hacking by hackers.
Recently, Telkomsel Company was hacked by hackers. On the page, the hacker protested the
price of the Telkomsel data package which was considered too expensive. The description
also contains harsh words complaining about it.
Cracking:
Cracking cases occurred in Indonesia by way of "carders" who only snooping on credit cards
then crackers snoop on customer deposits at various banks or other sensitive data centers for
personal gain. Experienced crackers create their own scripts or programs for cracking, which
are targeted, namely credit card databases, bank account databases, customer information
databases, and purchases of goods with fake credit cards.
Cyber Sabotage:
Cyber sabotage is carried out by disrupting, damaging or destroying data, computer network
systems connected to the internet. Cyber sabotage is the most feared mode by almost major
industries in the world. At least the 'beautiful' modes at play vary from malicious network
posts and social vilification, all the way to consumer information, hacking, and leaking of
company systems such as card numbers or industry secrets.
Spyware:
Spyware is a program that can secretly record any online activity of the user, such as
recording cookies or registry. The recorded data will be sent or sold to companies or
individuals who will send advertisements or spread viruses.24 Malware cases occur in
Indonesian people who use online banks. Perpetrators spread malware to trick their victims.
Malware is spread to customers' cell phones through fake internet banking software
advertisements that often appear on a number of internet pages.
When the customer downloads the fake software, the malware will automatically enter
the cell phone and manipulate the appearance of the internet banking page as if the page
really came from the perpetrator spreading malware to trick their victims. Internet banking
malware as if the page really came from the bank.
National Defense in the Face of Cyber Crime:
In the military aspect, cyber is used as a tool to attack the opponent's strength or find out the
opponent's weakness and damage the defense network. In achieving a power, cyber depends
on a country's strategy and policy to develop cyber security.
Establishment of cyberarmy is part of the development of the Cyber Defense Center
(cyber defense) The risk of cyber threats is growing is increasing. Pusdatin of the Indonesian
Ministry of Defense said that the cyberwar cold war is running in a global context. Sooner or later,
Indonesia will be involved in it where this cyberwar can be carried out by nation-state actors.
Cyberwar is seen as a situation where a country penetrates a computer or other device
which includes the defense of the Ministry of Defense's communication and information
systems. Cyberarmy consists of the military, namely the Army, Air Force, and Navy as well
as civilians who participate in national defense in the field of Technology and Information.
Cyberarmy is needed as a national defense that can fend off all attacks in cyberspace that can
interfere at any time the integrity of the Republic of Indonesia.25 Cyberarmy is also required
to have the ability to attack that can keep up with the advancement of technology and
information of other countries.
In national defense, both military and non-military, it is very important to have a new
system as a modern generation and future war, in the field of technology and information
defense. In addition to strong national defense, legal support is also needed that influences
and is interconnected in dealing with the threat of cyber crime. Law is needed to create order
and justice in society.
Technology, law and society are now inseparable. Along with technological advances,
society is required to continue to develop and often results in the emergence of new crimes in
technology. Therefore, the law is the most important part to overcome criminality that can
damage national defense.
Cyber crime in Indonesia is rampant, whether committed by individuals or groups.
There are various types of cyber-related crimes, ranging from copyright, piracy, misuse of
access to defamation of individuals and institutions. However, this is in stark contrast to the
17
4
laws governing cybercrime, which still have very few restrictions which can be used as a
reference to ensnare the perpetrator in committing a crime. This imbalance makes the law less
strong. Law enforcement in Indonesia regarding computer misuse is influenced by several
factors, namely the law, the mentality of the officials, community behavior, facilities and
culture.
The Indonesian Ministry of Communication and Information notes that there are 21
laws and 25 bills that will be affected by laws regulating cybercrime. Harmonization external
in the form of adjustments to the formulation of cybercrime articles with similar provisions
from other countries, especially with the Draft Convention on Cyber Crime and cybercrime
regulations from other countries. The world of internet technology has revolutionized and
innovated human communication.
The ITE Law is a law that specifically regulates cyber crimes in both criminal law and
criminal procedure law. The new law is cyberlaw. Cyberlaw itself is used for law
enforcement related to the use of information technology in anticipating people's behavior on
information technology, as a limitation to commit crimes (Law of Information Technology)
and cyberspace law.
IT HR Planning to Face the Threat of Cyber Crime
The preparations that Indonesia must have in facing cyber crime are human resources and
state security production facilities. Competency-based human resources are expected to be
able to create a positive way of thinking about the dynamics of global environmental change
so as to increase awareness of technological and information developments that have various
impacts on people's lives, especially with regard to cyber threats.
In order to anticipate cyber crime, technology experts are needed that can support a
sophisticated and modern national defense system. Therefore, it is necessary to cooperate
with the Indonesian defense industry that can make a modern defense system information and
communication system program that can compete with other countries. The increasing role of
the military in developing a cyber defense system in Indonesia is undeniable. Cyber military
defense prepares operations and resources to improve national cyber security.
The development of a cyber defense system in Indonesia is influenced by two factors.
The first factor is regulation and the second is the existence of a cyber command center. The
government needs to make a good and appropriate regulation related to the development of
national cyber security. As a comparison, regulations made by the American government are
the USA cyber attack convention, the draft cyber warfare international law manual and the
council of Europe convention on cyber crime 2001.30
Another important thing is to build a cyber defense security command center. The
Indonesian government will implement a cyber operation command that aims to become a
cyber defense command center in Indonesia. When the command center can be run, there is
great hope for the Indonesian people who are ready to anticipate non-traditional threats,
namely cyber crime, which is increasingly having an impact on the sovereignty of the
Republic of Indonesia. This is a big step that needs to be continued to run optimally. The
need for proper regulation and Cooperation with all parties, both government and private, can
be the key in facing the increasingly complex challenges of the cyber world.31
The IT HR planning process is part and function of personnel development within the
Ministry of Defense and its ranks.32 This function is carried out by the Personnel Bureau, in
accordance with Minister of Defense Regulation No. 16/2010, article 41, paragraph 2 that the
Procurement of Ministry of Defense, TNI Headquarters and Forces civil servants and the
development of Ministry of Defense employees. The IT HR planning process is based on
certain criteria, such as educational background, administration, physical, health, and HR
psychology, must be taken into consideration. The procurement process of civil servants
within the Ministry of Defense has several stages starting from the procurement process,
education, use, maintenance and separation.
Efforts to realize competency-based HR are the main capital in facing various changes
in the strategic environment and technological advances today. IT HR planning pays more
attention to quality than quantity to meet personnel needs. Understanding the educational
background of IT HR both formal and informal education is very helpful for organizations in
producing quality IT HR. Therefore, the preparation of IT HR requires capabilities on
national defense systems, network systems, applications, and policies related to cyber.
3.0 Conclusion:
The threat of cybercrime in the form of theft of confidential information and data is
aimed at attacking individuals, government agencies and the military with the defense of
a country. The government through the Ministry of Defense needs to prepare itself in
facing this cyber threat. The Ministry of Defense needs to prepare Human Resources
17
6
who are reliable in mastering technology, reliable infrastructure systems, and supported
by legislation or policies in carrying out cyber warfare operations.
Risk management in the field of information and communication that relates to the lives
of many citizens or that is confidential is something that is done to reduce the level of
vulnerability of misuse of information and data in cyberspace. Risk management is a
fundamental element of a strategy. Risk is a combination of likelihood and consequence.
It answers the question of how likely a probability is to occur and how bad the
consequences are. Therefore, risk management is important to prepare a good national defense
system.
Achieving cyber power depends on a country's strategy and policy to develop cyber
security. In addition to a strong national defense, it also requires legal support that
influences and is interconnected in facing the threat of cyber crime. The need for proper
regulation and cooperation with all parties, both government and private, can be the key
in facing the increasingly complex challenges of the cyber world.
The era of globalization encourages some countries to no longer use traditional and
conventional ways of warfare traditional and unconventional ways of war. As a result, the
strength of the state is no longer seen in the strength of weapons, but also in terms of culture,
economy, politics, and technology. This makes competition and warfare increasingly
invisible. Wars and conflicts that occur in a country are not only dominated by military
forces, but non-military forces are also carried out by non-state actors. Threats that evolve
into cyberattacks are not just a concept. The vulnerability of information exchange in
cyberspace has encouraged countries to build security systems that can overcome these
threats. The events in Estonia in 2007 and Georgia in 2008 are examples of cybercrime
attacks using Distributed Denial of Service (DdoS), which paralyzed the country's activities
because many critical sectors were attacked.3 Another attack that has been noted to be quite
alarming is the Stuxnet attack. Stuxnet is an example of highly sophisticated malware that
managed to paralyze one-fifth of the nuclear enrichment control systems of Iran's nuclear
power plants.4
Threats in cyberspace are dominated by non-state actors such as individual hackers,
hacker groups, hacker activities, non-government organizations (NGOs), terrorism,
organized criminal groups and the private sector (such as internet companies and carries,
security companies) can also threaten the defense and sovereignty of the state cybercrime has
occurred in the case of interception of personal communications of the President of Indonesia and
several high-ranking state officials by Australia based on documents leaked by Edward Snowden, a
former contractor of the National Security Agency (NSA) from America.6 In addition, one of the
official websites of the Ministry of Defense of the Republic of Indonesia (Kemhan RI) was broken
into by hackers, namely the website belonging to the Directorate General of Defense Potential (Ditjen
Pothan) which experienced a page change called defacing7 . The site was broken into by CVT (Cyber
Vampire Team) by writing the site page "Oops Myanmar Hacker was here". Then write a sentence in
English, namely:
Hello Indonesia Government, you should be proud with uneducated Indo script kiddies.
Coz they believe (defacing / Ddosing) to other country website is the best solution for them. If
you would sympathize the white programmers/ developers of your country and how they are
feeling. You can catch such script kiddies. Coz CVT are ready to provide those kiddies
information.
Global threats, advances in technology and information are not only aimed at attacking
government and military agencies, but can also threaten all aspects of human life, such as the
economy, politics, culture, and security of a country. Recently, a cyberattack also occurred on
the website of the government-owned telecommunications industry. The threat of cybercrime
can occur due to the interests of various individuals or groups. This threat in the aspect of
people's lives poses various real or unreal physical threats by using computer codes
(software) to steal information and data that can threaten a country.
The increase in the threat of cybercrime committed by both state and non-state actors
has an impact on the occurrence of cyber warfare or cyber violence. The country's
dependence on communication networks brings its own challenges and threats. Therefore,
risk management analysis is needed in the face of cyber crime attacks with the aim of
maintaining the defense and sovereignty of the Republic of Indonesia in realizing national
goals. Risk management can be interpreted as a series of procedures and methodologies used
to identify, measure, monitor and control risks arising from organizational activities. Risk
management in the field of information and communication that relates to the lives of many
citizens or is confidential, is something that is done to reduce the level of vulnerability of
misuse of information and data in cyberspace.
Risks that occur in facing the threat of cyber crime come from within and outside the
country by utilizing social, political, cultural, ideological conditions and technological
developments. Many ways are done by various parties to obtain information in the State
Defense Information System (Sisfohanneg). Some attacks have even been carried out, for
example, hacking action by defacing the website of the Director General of Pothan Kemhan.
17
8
The leaking of information related to national defense contained in Sisfohanneg can threaten
state sovereignty, especially information sovereignty. The concept of risk management in
defense is an important element to analyze how much a threat impacts national defense.
In the context of facing the threat of cyber crime attacks, it cannot be solved by using
only the power of weapons. But it requires the integration of all national forces under the
command and control (Kodal) of the Ministry of Foreign Affairs. Defense (MoD). The risks
faced in overcoming the threat of cyber crime are no less than conventional warfare. The use
of cyber technology has a broad impact because it can cover various aspects of social and
state life, including the fields of ideology, politics, economics, socio-culture, and security.
Cyber crime is increasing which is utilized by certain parties either individually or in groups
or countries with a specific purpose to be able to weaken their opponents. This condition
needs to be watched out for because it does not rule out the possibility that a country can be
paralyzed and destroyed by technological warfare or through cyber.11
As a sovereign and civilized nation, it is necessary to maintain the integrity of a country
by building a strong national defense in order to achieve the goals of national interests. The
various conditions above illustrate the importance of risk management identification in
dealing with the threat of cyber crime in the management of national defense development.
1.1 Definition of Cyber Crime:
Technology is an activity that is born by humans with planning and creating material
objects of practical value, such as cars, airplanes, televisions are the result of technological
development. Judging from the function and importance of technology, all circles of society
and government agencies are very dependent on technology both used for positive and
negative things. The words cyber and technology are described from the origin of the word
technique, from the Greek word Technikos which means art or skill in and logos is limo or
the main principles of cyber (software).12 The increasing use of cyberspace in all lines of
people's lives in the current era of globalization in parallel, will connect to the use of an
internet technology network in certain objects or sectors according to the purpose of its
operation.
Cyberspace is a space where communities are interconnected using networks (e.g. the
internet) to carry out various daily activities.13 Cyber is defined by another term, cyberspace,
which is derived from cybermetrics data. Initially, the term cyberspace was not intended to
describe interactions that occur through computer networks. John Perry Barlow in 1990
applied the term cyber to the internet network. In its development, cyber Internet applications
can bring positive and negative impacts that can lead to crimes in the development of the
cyber world. Crimes that are born as a negative impact of the development of applications on
the internet are called cyber crimes, which include all types of crimes and their modus
operandi carried out as a negative impact of internet applications.
In the opinion of Mcdonnell and Sayers, cyber threats are of three types,14 namely:
Hardware threat
This threat is a threat caused by the installation of certain devices that function to perform
certain activities in a system, so that the equipment is a disruption to network systems and
other hardware.
Software threat:
This threat is a threat caused by the introduction of software software that functions to carry
out theft, destruction, and manipulation of information.
Data/information threats (data/ information threat):
This threat is a threat caused by the dissemination of certain data/information aimed at the
interests of the community.
In the Strategic Cyber Security study National, defines the threat of cybercrime as every
condition and situation as well as the ability that is considered to be able to perform actions
or interference or attacks that are capable of damaging or everything that is detrimental so as
to threaten the confidentiality, integrity, and availability of systems and information.15 Cyber
threats can occur due to the interests of various individuals or groups in certain aspects of
community life that can cause various physical threats, both real and unreal by using
computer codes (software) to steal information (information theft), system destruction,
information manipulation (information corruption) or hardware (hardware) to disrupt the
system (network instruction) or disseminate certain data and information to carry out
propaganda activities.16
The sources of cyber threats can come from various sources, such as foreign
intelligence services, disaffected employees, investigation journalists, extremist
organizations, and hacktivist activities, and groups crime groups organized crime groups.
18
0
The risk of cyber crime has the potential to lose data information systems, military
activities and other disruptions that use computer networks and the internet. In looking at the
sources of threats above, the government through the Ministry of Defense (Kemhan) needs to
prepare itself in facing this cyber threat. The Ministry of Defense needs to prepare Human
Resources who are reliable in mastering technology, reliable infrastructure systems, and
supported by legislation or policies in carrying out cyber warfare operations.
2.0 Discussion:
Indonesia is among the top five countries that use social media and is considered a
potential positive (strength) or potential negative (vulnerability/weakness) when it comes to
the potential for cyber warfare. The use of social media among the public can potentially
threaten state sovereignty. But on the other hand, social media can also be a source of
knowledge about the world of information, communication and digital technology, so that
people can be digitally literate. The activities of Indonesian people who use digital
technology will eventually become a potential in cyber warfare. The use of information
technology will be easily tapped or hacked by hackers and crackers from foreign countries,
thus creating vulnerability, especially intelligence information that uses cyberspace as a
means of transmission. Rapidly advancing wiretapping technology to hack various social
media users will be very dangerous in the era of cyber warfare.
Risk management is defined as "the process of understanding and managing the risks
that an organization is inevitably subject to in attempting to achieve its corporate
objectives".17 Risk management is also defined as "the essence of risk management lies in
maximizing the areas where we can mitigate risk have some control over the outcome while
minimizing the areas where we have absolutely no control over the outcome, and the linkage
between effect and cause is hidden from us".18
Referring to the two definitions above, risk management is a continuous process,
carried out during defense management activities in the face of cybercrime threats. Risk
management is management that plans advanced plans in the face of risk and uncertainty in
order to maximize the achievement of objectives.
Elements of risk management according to the Institute of Risk Management include
Risk Assessment, which is the process of identifying, describing and estimating; Risk
Evaluation, decision-making about significant risks that should be assigned to a risk
management program. Risk treatment depends on risk appetite; risk treatment, risk appetite is
carried out response or treatment which is a process of selection and implementation. The several
stages in the risk management process that can be implemented in dealing with the threat of cyber
crime are described below: 19
Identify:
In this stage, the identification of cybercrime risks should be carried out periodically against
the triggers of cybercrime. In this process, all aspects that have the potential to cause harm
are carefully identified. All identified risks are then measured. The risk measure for this
threat refers to two measures, namely Probability and Impact Probability.
Assess:
In this stage, assess or assessment basically assesses the level of risk posed by cybercrime
that impacts all aspects of life, especially national defense. The assessment of cybercrime
cannot be measured directly but can use a matrix table in measuring the risks posed by
cybercrime.
Treat:
After identifying and Risk measurement is then used as a basis for determining the treatment
and response to risk, whether the risk will be accepted, transferred, minimized or avoided. In
this case, it is necessary to minimize the theft of information and data that often occurs both
individually and institutionally.
Control:
Continuous monitoring and adjustments should be made to assess the success of risk
management. In the monitoring process, there should be an early warning mechanism for
security controllers such as the Ministry of Defense of the Republic of Indonesia, so that
controllers can take the necessary actions to anticipate cybercrime.
Risk Matrix:
The potential threat of cyber crime leads to cyber warfare. The potential threats of cyber
crime in Indonesia are as follows.
Hacking
Hacking cases have occurred several times in Indonesia. The causes vary from simply
hacking security to rejection of government discourse. For example, in the 2014 presidential
election, news spread that the General Election Commission (KPU) website had been hacked
18
2
by hackers. The indication is that the KPU site could not be accessed.20
Not only in the government sector, but private parties often experience hacking by hackers.
Recently, Telkomsel Company was hacked by hackers. On the page, the hacker protested the
price of the Telkomsel data package which was considered too expensive. The description
also contains harsh words complaining about it.
Cracking:
Cracking cases occurred in Indonesia by way of "carders" who only snooping on credit cards
then crackers snoop on customer deposits at various banks or other sensitive data centers for
personal gain. Experienced crackers create their own scripts or programs for cracking, which
are targeted, namely credit card databases, bank account databases, customer information
databases, and purchases of goods with fake credit cards.
Cyber Sabotage:
Cyber sabotage is carried out by disrupting, damaging or destroying data, computer network
systems connected to the internet. Cyber sabotage is the most feared mode by almost major
industries in the world. At least the 'beautiful' modes at play vary from malicious network
posts and social vilification, all the way to consumer information, hacking, and leaking of
company systems such as card numbers or industry secrets.
Spyware:
Spyware is a program that can secretly record any online activity of the user, such as
recording cookies or registry. The recorded data will be sent or sold to companies or
individuals who will send advertisements or spread viruses.24 Malware cases occur in
Indonesian people who use online banks. Perpetrators spread malware to trick their victims.
Malware is spread to customers' cell phones through fake internet banking software
advertisements that often appear on a number of internet pages.
When the customer downloads the fake software, the malware will automatically enter
the cell phone and manipulate the appearance of the internet banking page as if the page
really came from the perpetrator spreading malware to trick their victims. Internet banking
malware as if the page really came from the bank.
National Defense in the Face of Cyber Crime:
In the military aspect, cyber is used as a tool to attack the opponent's strength or find out the
opponent's weakness and damage the defense network. In achieving a power, cyber depends
on a country's strategy and policy to develop cyber security.
Establishment of cyberarmy is part of the development of the Cyber Defense Center
(cyber defense) The risk of cyber threats is growing is increasing. Pusdatin of the Indonesian
Ministry of Defense said that the cyberwar cold war is running in a global context. Sooner or later,
Indonesia will be involved in it where this cyberwar can be carried out by nation-state actors.
Cyberwar is seen as a situation where a country penetrates a computer or other device
which includes the defense of the Ministry of Defense's communication and information
systems. Cyberarmy consists of the military, namely the Army, Air Force, and Navy as well
as civilians who participate in national defense in the field of Technology and Information.
Cyberarmy is needed as a national defense that can fend off all attacks in cyberspace that can
interfere at any time the integrity of the Republic of Indonesia.25 Cyberarmy is also required
to have the ability to attack that can keep up with the advancement of technology and
information of other countries.
In national defense, both military and non-military, it is very important to have a new
system as a modern generation and future war, in the field of technology and information
defense. In addition to strong national defense, legal support is also needed that influences
and is interconnected in dealing with the threat of cyber crime. Law is needed to create order
and justice in society.
Technology, law and society are now inseparable. Along with technological advances,
society is required to continue to develop and often results in the emergence of new crimes in
technology. Therefore, the law is the most important part to overcome criminality that can
damage national defense.
Cyber crime in Indonesia is rampant, whether committed by individuals or groups.
There are various types of cyber-related crimes, ranging from copyright, piracy, misuse of
access to defamation of individuals and institutions. However, this is in stark contrast to the
laws governing cybercrime, which still have very few restrictions which can be used as a
reference to ensnare the perpetrator in committing a crime. This imbalance makes the law less
strong. Law enforcement in Indonesia regarding computer misuse is influenced by several
18
4
factors, namely the law, the mentality of the officials, community behavior, facilities and
culture.
The Indonesian Ministry of Communication and Information notes that there are 21
laws and 25 bills that will be affected by laws regulating cybercrime. Harmonization external
in the form of adjustments to the formulation of cybercrime articles with similar provisions
from other countries, especially with the Draft Convention on Cyber Crime and cybercrime
regulations from other countries. The world of internet technology has revolutionized and
innovated human communication.
The ITE Law is a law that specifically regulates cyber crimes in both criminal law and
criminal procedure law. The new law is cyberlaw. Cyberlaw itself is used for law
enforcement related to the use of information technology in anticipating people's behavior on
information technology, as a limitation to commit crimes (Law of Information Technology)
and cyberspace law.
IT HR Planning to Face the Threat of Cyber Crime
The preparations that Indonesia must have in facing cyber crime are human resources and
state security production facilities. Competency-based human resources are expected to be
able to create a positive way of thinking about the dynamics of global environmental change
so as to increase awareness of technological and information developments that have various
impacts on people's lives, especially with regard to cyber threats.
In order to anticipate cyber crime, technology experts are needed that can support a
sophisticated and modern national defense system. Therefore, it is necessary to cooperate
with the Indonesian defense industry that can make a modern defense system information and
communication system program that can compete with other countries. The increasing role of
the military in developing a cyber defense system in Indonesia is undeniable. Cyber military
defense prepares operations and resources to improve national cyber security.
The development of a cyber defense system in Indonesia is influenced by two factors.
The first factor is regulation and the second is the existence of a cyber command center. The
government needs to make a good and appropriate regulation related to the development of
national cyber security. As a comparison, regulations made by the American government are
the USA cyber attack convention, the draft cyber warfare international law manual and the
council of Europe convention on cyber crime 2001.30
Another important thing is to build a cyber defense security command center. The
Indonesian government will implement a cyber operation command that aims to become a
cyber defense command center in Indonesia. When the command center can be run, there is
great hope for the Indonesian people who are ready to anticipate non-traditional threats,
namely cyber crime, which is increasingly having an impact on the sovereignty of the
Republic of Indonesia. This is a big step that needs to be continued to run optimally. The
need for proper regulation and Cooperation with all parties, both government and private, can
be the key in facing the increasingly complex challenges of the cyber world.31
The IT HR planning process is part and function of personnel development within the
Ministry of Defense and its ranks.32 This function is carried out by the Personnel Bureau, in
accordance with Minister of Defense Regulation No. 16/2010, article 41, paragraph 2 that the
Procurement of Ministry of Defense, TNI Headquarters and Forces civil servants and the
development of Ministry of Defense employees. The IT HR planning process is based on
certain criteria, such as educational background, administration, physical, health, and HR
psychology, must be taken into consideration. The procurement process of civil servants
within the Ministry of Defense has several stages starting from the procurement process,
education, use, maintenance and separation.
Efforts to realize competency-based HR are the main capital in facing various changes
in the strategic environment and technological advances today. IT HR planning pays more
attention to quality than quantity to meet personnel needs. Understanding the educational
background of IT HR both formal and informal education is very helpful for organizations in
producing quality IT HR. Therefore, the preparation of IT HR requires capabilities on
national defense systems, network systems, applications, and policies related to cyber.
3.0 Conclusion:
The threat of cybercrime in the form of theft of confidential information and data is
aimed at attacking individuals, government agencies and the military with the defense of
a country. The government through the Ministry of Defense needs to prepare itself in
facing this cyber threat. The Ministry of Defense needs to prepare Human Resources
who are reliable in mastering technology, reliable infrastructure systems, and supported
by legislation or policies in carrying out cyber warfare operations.
Risk management in the field of information and communication that relates to the lives
18
6
of many citizens or that is confidential is something that is done to reduce the level of
vulnerability of misuse of information and data in cyberspace. Risk management is a
fundamental element of a strategy. Risk is a combination of likelihood and consequence.
It answers the question of how likely a probability is to occur and how bad the
consequences are. Therefore, risk management is important to prepare a good national defense
system.
Achieving cyber power depends on a country's strategy and policy to develop cyber
security. In addition to a strong national defense, it also requires legal support that
influences and is interconnected in facing the threat of cyber crime. The need for proper
regulation and cooperation with all parties, both government and private, can be the key
in facing the increasingly complex challenges of the cyber world.
The era of globalization encourages some countries to no longer use traditional and
conventional ways of warfare traditional and unconventional ways of war. As a result, the
strength of the state is no longer seen in the strength of weapons, but also in terms of culture,
economy, politics, and technology. This makes competition and warfare increasingly
invisible. Wars and conflicts that occur in a country are not only dominated by military
forces, but non-military forces are also carried out by non-state actors. Threats that evolve
into cyberattacks are not just a concept. The vulnerability of information exchange in
cyberspace has encouraged countries to build security systems that can overcome these
threats. The events in Estonia in 2007 and Georgia in 2008 are examples of cybercrime
attacks using Distributed Denial of Service (DdoS), which paralyzed the country's activities
because many critical sectors were attacked.3 Another attack that has been noted to be quite
alarming is the Stuxnet attack. Stuxnet is an example of highly sophisticated malware that
managed to paralyze one-fifth of the nuclear enrichment control systems of Iran's nuclear
power plants.4
Threats in cyberspace are dominated by non-state actors such as individual hackers,
hacker groups, hacker activities, non-government organizations (NGOs), terrorism,
organized criminal groups and the private sector (such as internet companies and carries,
security companies) can also threaten the defense and sovereignty of the state cybercrime has
occurred in the case of interception of personal communications of the President of Indonesia and
several high-ranking state officials by Australia based on documents leaked by Edward Snowden, a
former contractor of the National Security Agency (NSA) from America.6 In addition, one of the
official websites of the Ministry of Defense of the Republic of Indonesia (Kemhan RI) was broken
into by hackers, namely the website belonging to the Directorate General of Defense Potential (Ditjen
Pothan) which experienced a page change called defacing7 . The site was broken into by CVT (Cyber
Vampire Team) by writing the site page "Oops Myanmar Hacker was here". Then write a sentence in
English, namely:
Hello Indonesia Government, you should be proud with uneducated Indo script kiddies.
Coz they believe (defacing / Ddosing) to other country website is the best solution for them. If
you would sympathize the white programmers/ developers of your country and how they are
feeling. You can catch such script kiddies. Coz CVT are ready to provide those kiddies
information.
Global threats, advances in technology and information are not only aimed at attacking
government and military agencies, but can also threaten all aspects of human life, such as the
economy, politics, culture, and security of a country. Recently, a cyberattack also occurred on
the website of the government-owned telecommunications industry. The threat of cybercrime
can occur due to the interests of various individuals or groups. This threat in the aspect of
people's lives poses various real or unreal physical threats by using computer codes
(software) to steal information and data that can threaten a country.
The increase in the threat of cybercrime committed by both state and non-state actors
has an impact on the occurrence of cyber warfare or cyber violence. The country's
dependence on communication networks brings its own challenges and threats. Therefore,
risk management analysis is needed in the face of cyber crime attacks with the aim of
maintaining the defense and sovereignty of the Republic of Indonesia in realizing national
goals. Risk management can be interpreted as a series of procedures and methodologies used
to identify, measure, monitor and control risks arising from organizational activities. Risk
management in the field of information and communication that relates to the lives of many
citizens or is confidential, is something that is done to reduce the level of vulnerability of
misuse of information and data in cyberspace.
Risks that occur in facing the threat of cyber crime come from within and outside the
country by utilizing social, political, cultural, ideological conditions and technological
developments. Many ways are done by various parties to obtain information in the State
Defense Information System (Sisfohanneg). Some attacks have even been carried out, for
example, hacking action by defacing the website of the Director General of Pothan Kemhan.
The leaking of information related to national defense contained in Sisfohanneg can threaten
state sovereignty, especially information sovereignty. The concept of risk management in
18
8
defense is an important element to analyze how much a threat impacts national defense.
In the context of facing the threat of cyber crime attacks, it cannot be solved by using
only the power of weapons. But it requires the integration of all national forces under the
command and control (Kodal) of the Ministry of Foreign Affairs. Defense (MoD). The risks
faced in overcoming the threat of cyber crime are no less than conventional warfare. The use
of cyber technology has a broad impact because it can cover various aspects of social and
state life, including the fields of ideology, politics, economics, socio-culture, and security.
Cyber crime is increasing which is utilized by certain parties either individually or in groups
or countries with a specific purpose to be able to weaken their opponents. This condition
needs to be watched out for because it does not rule out the possibility that a country can be
paralyzed and destroyed by technological warfare or through cyber.11
As a sovereign and civilized nation, it is necessary to maintain the integrity of a country
by building a strong national defense in order to achieve the goals of national interests. The
various conditions above illustrate the importance of risk management identification in
dealing with the threat of cyber crime in the management of national defense development.
1.1 Definition of Cyber Crime:
Technology is an activity that is born by humans with planning and creating material
objects of practical value, such as cars, airplanes, televisions are the result of technological
development. Judging from the function and importance of technology, all circles of society
and government agencies are very dependent on technology both used for positive and
negative things. The words cyber and technology are described from the origin of the word
technique, from the Greek word Technikos which means art or skill in and logos is limo or
the main principles of cyber (software).12 The increasing use of cyberspace in all lines of
people's lives in the current era of globalization in parallel, will connect to the use of an
internet technology network in certain objects or sectors according to the purpose of its
operation.
Cyberspace is a space where communities are interconnected using networks (e.g. the
internet) to carry out various daily activities.13 Cyber is defined by another term, cyberspace,
which is derived from cybermetrics data. Initially, the term cyberspace was not intended to
describe interactions that occur through computer networks. John Perry Barlow in 1990
applied the term cyber to the internet network. In its development, cyber Internet applications
can bring positive and negative impacts that can lead to crimes in the development of the
cyber world. Crimes that are born as a negative impact of the development of applications on
the internet are called cyber crimes, which include all types of crimes and their modus
operandi carried out as a negative impact of internet applications.
In the opinion of Mcdonnell and Sayers, cyber threats are of three types,14 namely:
Hardware threat
This threat is a threat caused by the installation of certain devices that function to perform
certain activities in a system, so that the equipment is a disruption to network systems and
other hardware.
Software threat:
This threat is a threat caused by the introduction of software software that functions to carry
out theft, destruction, and manipulation of information.
Data/information threats (data/ information threat):
This threat is a threat caused by the dissemination of certain data/information aimed at the
interests of the community.
In the Strategic Cyber Security study National, defines the threat of cybercrime as every
condition and situation as well as the ability that is considered to be able to perform actions
or interference or attacks that are capable of damaging or everything that is detrimental so as
to threaten the confidentiality, integrity, and availability of systems and information.15 Cyber
threats can occur due to the interests of various individuals or groups in certain aspects of
community life that can cause various physical threats, both real and unreal by using
computer codes (software) to steal information (information theft), system destruction,
information manipulation (information corruption) or hardware (hardware) to disrupt the
system (network instruction) or disseminate certain data and information to carry out
propaganda activities.16
The sources of cyber threats can come from various sources, such as foreign
intelligence services, disaffected employees, investigation journalists, extremist
organizations, and hacktivist activities, and groups crime groups organized crime groups.
The risk of cyber crime has the potential to lose data information systems, military
activities and other disruptions that use computer networks and the internet. In looking at the
19
0
sources of threats above, the government through the Ministry of Defense (Kemhan) needs to
prepare itself in facing this cyber threat. The Ministry of Defense needs to prepare Human
Resources who are reliable in mastering technology, reliable infrastructure systems, and
supported by legislation or policies in carrying out cyber warfare operations.
2.0 Discussion:
Indonesia is among the top five countries that use social media and is considered a
potential positive (strength) or potential negative (vulnerability/weakness) when it comes to
the potential for cyber warfare. The use of social media among the public can potentially
threaten state sovereignty. But on the other hand, social media can also be a source of
knowledge about the world of information, communication and digital technology, so that
people can be digitally literate. The activities of Indonesian people who use digital
technology will eventually become a potential in cyber warfare. The use of information
technology will be easily tapped or hacked by hackers and crackers from foreign countries,
thus creating vulnerability, especially intelligence information that uses cyberspace as a
means of transmission. Rapidly advancing wiretapping technology to hack various social
media users will be very dangerous in the era of cyber warfare.
Risk management is defined as "the process of understanding and managing the risks
that an organization is inevitably subject to in attempting to achieve its corporate
objectives".17 Risk management is also defined as "the essence of risk management lies in
maximizing the areas where we can mitigate risk have some control over the outcome while
minimizing the areas where we have absolutely no control over the outcome, and the linkage
between effect and cause is hidden from us".18
Referring to the two definitions above, risk management is a continuous process,
carried out during defense management activities in the face of cybercrime threats. Risk
management is management that plans advanced plans in the face of risk and uncertainty in
order to maximize the achievement of objectives.
Elements of risk management according to the Institute of Risk Management include
Risk Assessment, which is the process of identifying, describing and estimating; Risk
Evaluation, decision-making about significant risks that should be assigned to a risk
management program. Risk treatment depends on risk appetite; risk treatment, risk appetite is
carried out response or treatment which is a process of selection and implementation. The several
stages in the risk management process that can be implemented in dealing with the threat of cyber
crime are described below: 19
Identify:
In this stage, the identification of cybercrime risks should be carried out periodically against
the triggers of cybercrime. In this process, all aspects that have the potential to cause harm
are carefully identified. All identified risks are then measured. The risk measure for this
threat refers to two measures, namely Probability and Impact Probability.
Assess:
In this stage, assess or assessment basically assesses the level of risk posed by cybercrime
that impacts all aspects of life, especially national defense. The assessment of cybercrime
cannot be measured directly but can use a matrix table in measuring the risks posed by
cybercrime.
Treat:
After identifying and Risk measurement is then used as a basis for determining the treatment
and response to risk, whether the risk will be accepted, transferred, minimized or avoided. In
this case, it is necessary to minimize the theft of information and data that often occurs both
individually and institutionally.
Control:
Continuous monitoring and adjustments should be made to assess the success of risk
management. In the monitoring process, there should be an early warning mechanism for
security controllers such as the Ministry of Defense of the Republic of Indonesia, so that
controllers can take the necessary actions to anticipate cybercrime.
Risk Matrix:
The potential threat of cyber crime leads to cyber warfare. The potential threats of cyber
crime in Indonesia are as follows.
Hacking
Hacking cases have occurred several times in Indonesia. The causes vary from simply
hacking security to rejection of government discourse. For example, in the 2014 presidential
election, news spread that the General Election Commission (KPU) website had been hacked
by hackers. The indication is that the KPU site could not be accessed.20
19
2
Not only in the government sector, but private parties often experience hacking by hackers.
Recently, Telkomsel Company was hacked by hackers. On the page, the hacker protested the
price of the Telkomsel data package which was considered too expensive. The description
also contains harsh words complaining about it.
Cracking:
Cracking cases occurred in Indonesia by way of "carders" who only snooping on credit cards
then crackers snoop on customer deposits at various banks or other sensitive data centers for
personal gain. Experienced crackers create their own scripts or programs for cracking, which
are targeted, namely credit card databases, bank account databases, customer information
databases, and purchases of goods with fake credit cards.
Cyber Sabotage:
Cyber sabotage is carried out by disrupting, damaging or destroying data, computer network
systems connected to the internet. Cyber sabotage is the most feared mode by almost major
industries in the world. At least the 'beautiful' modes at play vary from malicious network
posts and social vilification, all the way to consumer information, hacking, and leaking of
company systems such as card numbers or industry secrets.
Spyware:
Spyware is a program that can secretly record any online activity of the user, such as
recording cookies or registry. The recorded data will be sent or sold to companies or
individuals who will send advertisements or spread viruses.24 Malware cases occur in
Indonesian people who use online banks. Perpetrators spread malware to trick their victims.
Malware is spread to customers' cell phones through fake internet banking software
advertisements that often appear on a number of internet pages.
When the customer downloads the fake software, the malware will automatically enter
the cell phone and manipulate the appearance of the internet banking page as if the page
really came from the perpetrator spreading malware to trick their victims. Internet banking
malware as if the page really came from the bank.
National Defense in the Face of Cyber Crime:
In the military aspect, cyber is used as a tool to attack the opponent's strength or find out the
opponent's weakness and damage the defense network. In achieving a power, cyber depends
on a country's strategy and policy to develop cyber security.
Establishment of cyberarmy is part of the development of the Cyber Defense Center
(cyber defense) The risk of cyber threats is growing is increasing. Pusdatin of the Indonesian
Ministry of Defense said that the cyberwar cold war is running in a global context. Sooner or later,
Indonesia will be involved in it where this cyberwar can be carried out by nation-state actors.
Cyberwar is seen as a situation where a country penetrates a computer or other device
which includes the defense of the Ministry of Defense's communication and information
systems. Cyberarmy consists of the military, namely the Army, Air Force, and Navy as well
as civilians who participate in national defense in the field of Technology and Information.
Cyberarmy is needed as a national defense that can fend off all attacks in cyberspace that can
interfere at any time the integrity of the Republic of Indonesia.25 Cyberarmy is also required
to have the ability to attack that can keep up with the advancement of technology and
information of other countries.
In national defense, both military and non-military, it is very important to have a new
system as a modern generation and future war, in the field of technology and information
defense. In addition to strong national defense, legal support is also needed that influences
and is interconnected in dealing with the threat of cyber crime. Law is needed to create order
and justice in society.
Technology, law and society are now inseparable. Along with technological advances,
society is required to continue to develop and often results in the emergence of new crimes in
technology. Therefore, the law is the most important part to overcome criminality that can
damage national defense.
Cyber crime in Indonesia is rampant, whether committed by individuals or groups.
There are various types of cyber-related crimes, ranging from copyright, piracy, misuse of
access to defamation of individuals and institutions. However, this is in stark contrast to the
laws governing cybercrime, which still have very few restrictions which can be used as a
reference to ensnare the perpetrator in committing a crime. This imbalance makes the law less
strong. Law enforcement in Indonesia regarding computer misuse is influenced by several
factors, namely the law, the mentality of the officials, community behavior, facilities and
19
4
culture.
The Indonesian Ministry of Communication and Information notes that there are 21
laws and 25 bills that will be affected by laws regulating cybercrime. Harmonization external
in the form of adjustments to the formulation of cybercrime articles with similar provisions
from other countries, especially with the Draft Convention on Cyber Crime and cybercrime
regulations from other countries. The world of internet technology has revolutionized and
innovated human communication.
The ITE Law is a law that specifically regulates cyber crimes in both criminal law and
criminal procedure law. The new law is cyberlaw. Cyberlaw itself is used for law
enforcement related to the use of information technology in anticipating people's behavior on
information technology, as a limitation to commit crimes (Law of Information Technology)
and cyberspace law.
IT HR Planning to Face the Threat of Cyber Crime
The preparations that Indonesia must have in facing cyber crime are human resources and
state security production facilities. Competency-based human resources are expected to be
able to create a positive way of thinking about the dynamics of global environmental change
so as to increase awareness of technological and information developments that have various
impacts on people's lives, especially with regard to cyber threats.
In order to anticipate cyber crime, technology experts are needed that can support a
sophisticated and modern national defense system. Therefore, it is necessary to cooperate
with the Indonesian defense industry that can make a modern defense system information and
communication system program that can compete with other countries. The increasing role of
the military in developing a cyber defense system in Indonesia is undeniable. Cyber military
defense prepares operations and resources to improve national cyber security.
The development of a cyber defense system in Indonesia is influenced by two factors.
The first factor is regulation and the second is the existence of a cyber command center. The
government needs to make a good and appropriate regulation related to the development of
national cyber security. As a comparison, regulations made by the American government are
the USA cyber attack convention, the draft cyber warfare international law manual and the
council of Europe convention on cyber crime 2001.30
Another important thing is to build a cyber defense security command center. The
Indonesian government will implement a cyber operation command that aims to become a
cyber defense command center in Indonesia. When the command center can be run, there is
great hope for the Indonesian people who are ready to anticipate non-traditional threats,
namely cyber crime, which is increasingly having an impact on the sovereignty of the
Republic of Indonesia. This is a big step that needs to be continued to run optimally. The
need for proper regulation and Cooperation with all parties, both government and private, can
be the key in facing the increasingly complex challenges of the cyber world.31
The IT HR planning process is part and function of personnel development within the
Ministry of Defense and its ranks.32 This function is carried out by the Personnel Bureau, in
accordance with Minister of Defense Regulation No. 16/2010, article 41, paragraph 2 that the
Procurement of Ministry of Defense, TNI Headquarters and Forces civil servants and the
development of Ministry of Defense employees. The IT HR planning process is based on
certain criteria, such as educational background, administration, physical, health, and HR
psychology, must be taken into consideration. The procurement process of civil servants
within the Ministry of Defense has several stages starting from the procurement process,
education, use, maintenance and separation.
Efforts to realize competency-based HR are the main capital in facing various changes
in the strategic environment and technological advances today. IT HR planning pays more
attention to quality than quantity to meet personnel needs. Understanding the educational
background of IT HR both formal and informal education is very helpful for organizations in
producing quality IT HR. Therefore, the preparation of IT HR requires capabilities on
national defense systems, network systems, applications, and policies related to cyber.
3.0 Conclusion:
The threat of cybercrime in the form of theft of confidential information and data is
aimed at attacking individuals, government agencies and the military with the defense of
a country. The government through the Ministry of Defense needs to prepare itself in
facing this cyber threat. The Ministry of Defense needs to prepare Human Resources
who are reliable in mastering technology, reliable infrastructure systems, and supported
by legislation or policies in carrying out cyber warfare operations.
Risk management in the field of information and communication that relates to the lives
19
6
of many citizens or that is confidential is something that is done to reduce the level of
vulnerability of misuse of information and data in cyberspace. Risk management is a
fundamental element of a strategy. Risk is a combination of likelihood and consequence.
It answers the question of how likely a probability is to occur and how bad the
consequences are. Therefore, risk management is important to prepare a good national defense
system.
Achieving cyber power depends on a country's strategy and policy to develop cyber
security. In addition to a strong national defense, it also requires legal support that
influences and is interconnected in facing the threat of cyber crime. The need for proper
regulation and cooperation with all parties, both government and private, can be the key
in facing the increasingly complex challenges of the cyber world.
The era of globalization encourages some countries to no longer use traditional and
conventional ways of warfare traditional and unconventional ways of war. As a result, the
strength of the state is no longer seen in the strength of weapons, but also in terms of culture,
economy, politics, and technology. This makes competition and warfare increasingly
invisible. Wars and conflicts that occur in a country are not only dominated by military
forces, but non-military forces are also carried out by non-state actors. Threats that evolve
into cyberattacks are not just a concept. The vulnerability of information exchange in
cyberspace has encouraged countries to build security systems that can overcome these
threats. The events in Estonia in 2007 and Georgia in 2008 are examples of cybercrime
attacks using Distributed Denial of Service (DdoS), which paralyzed the country's activities
because many critical sectors were attacked.3 Another attack that has been noted to be quite
alarming is the Stuxnet attack. Stuxnet is an example of highly sophisticated malware that
managed to paralyze one-fifth of the nuclear enrichment control systems of Iran's nuclear
power plants.4
Threats in cyberspace are dominated by non-state actors such as individual hackers,
hacker groups, hacker activities, non-government organizations (NGOs), terrorism,
organized criminal groups and the private sector (such as internet companies and carries,
security companies) can also threaten the defense and sovereignty of the state cybercrime has
occurred in the case of interception of personal communications of the President of Indonesia and
several high-ranking state officials by Australia based on documents leaked by Edward Snowden, a
former contractor of the National Security Agency (NSA) from America.6 In addition, one of the
official websites of the Ministry of Defense of the Republic of Indonesia (Kemhan RI) was broken
into by hackers, namely the website belonging to the Directorate General of Defense Potential (Ditjen
Pothan) which experienced a page change called defacing7 . The site was broken into by CVT (Cyber
Vampire Team) by writing the site page "Oops Myanmar Hacker was here". Then write a sentence in
English, namely:
Hello Indonesia Government, you should be proud with uneducated Indo script kiddies.
Coz they believe (defacing / Ddosing) to other country website is the best solution for them. If
you would sympathize the white programmers/ developers of your country and how they are
feeling. You can catch such script kiddies. Coz CVT are ready to provide those kiddies
information.
Global threats, advances in technology and information are not only aimed at attacking
government and military agencies, but can also threaten all aspects of human life, such as the
economy, politics, culture, and security of a country. Recently, a cyberattack also occurred on
the website of the government-owned telecommunications industry. The threat of cybercrime
can occur due to the interests of various individuals or groups. This threat in the aspect of
people's lives poses various real or unreal physical threats by using computer codes
(software) to steal information and data that can threaten a country.
The increase in the threat of cybercrime committed by both state and non-state actors
has an impact on the occurrence of cyber warfare or cyber violence. The country's
dependence on communication networks brings its own challenges and threats. Therefore,
risk management analysis is needed in the face of cyber crime attacks with the aim of
maintaining the defense and sovereignty of the Republic of Indonesia in realizing national
goals. Risk management can be interpreted as a series of procedures and methodologies used
to identify, measure, monitor and control risks arising from organizational activities. Risk
management in the field of information and communication that relates to the lives of many
citizens or is confidential, is something that is done to reduce the level of vulnerability of
misuse of information and data in cyberspace.
Risks that occur in facing the threat of cyber crime come from within and outside the
country by utilizing social, political, cultural, ideological conditions and technological
developments. Many ways are done by various parties to obtain information in the State
Defense Information System (Sisfohanneg). Some attacks have even been carried out, for
example, hacking action by defacing the website of the Director General of Pothan Kemhan.
The leaking of information related to national defense contained in Sisfohanneg can threaten
state sovereignty, especially information sovereignty. The concept of risk management in
19
8
defense is an important element to analyze how much a threat impacts national defense.
In the context of facing the threat of cyber crime attacks, it cannot be solved by using
only the power of weapons. But it requires the integration of all national forces under the
command and control (Kodal) of the Ministry of Foreign Affairs. Defense (MoD). The risks
faced in overcoming the threat of cyber crime are no less than conventional warfare. The use
of cyber technology has a broad impact because it can cover various aspects of social and
state life, including the fields of ideology, politics, economics, socio-culture, and security.
Cyber crime is increasing which is utilized by certain parties either individually or in groups
or countries with a specific purpose to be able to weaken their opponents. This condition
needs to be watched out for because it does not rule out the possibility that a country can be
paralyzed and destroyed by technological warfare or through cyber.11
As a sovereign and civilized nation, it is necessary to maintain the integrity of a country
by building a strong national defense in order to achieve the goals of national interests. The
various conditions above illustrate the importance of risk management identification in
dealing with the threat of cyber crime in the management of national defense development.
1.1 Definition of Cyber Crime:
Technology is an activity that is born by humans with planning and creating material
objects of practical value, such as cars, airplanes, televisions are the result of technological
development. Judging from the function and importance of technology, all circles of society
and government agencies are very dependent on technology both used for positive and
negative things. The words cyber and technology are described from the origin of the word
technique, from the Greek word Technikos which means art or skill in and logos is limo or
the main principles of cyber (software).12 The increasing use of cyberspace in all lines of
people's lives in the current era of globalization in parallel, will connect to the use of an
internet technology network in certain objects or sectors according to the purpose of its
operation.
Cyberspace is a space where communities are interconnected using networks (e.g. the
internet) to carry out various daily activities.13 Cyber is defined by another term, cyberspace,
which is derived from cybermetrics data. Initially, the term cyberspace was not intended to
describe interactions that occur through computer networks. John Perry Barlow in 1990
applied the term cyber to the internet network. In its development, cyber Internet applications
can bring positive and negative impacts that can lead to crimes in the development of the
cyber world. Crimes that are born as a negative impact of the development of applications on
the internet are called cyber crimes, which include all types of crimes and their modus
operandi carried out as a negative impact of internet applications.
In the opinion of Mcdonnell and Sayers, cyber threats are of three types,14 namely:
Hardware threat
This threat is a threat caused by the installation of certain devices that function to perform
certain activities in a system, so that the equipment is a disruption to network systems and
other hardware.
Software threat:
This threat is a threat caused by the introduction of software software that functions to carry
out theft, destruction, and manipulation of information.
Data/information threats (data/ information threat):
This threat is a threat caused by the dissemination of certain data/information aimed at the
interests of the community.
In the Strategic Cyber Security study National, defines the threat of cybercrime as every
condition and situation as well as the ability that is considered to be able to perform actions
or interference or attacks that are capable of damaging or everything that is detrimental so as
to threaten the confidentiality, integrity, and availability of systems and information.15 Cyber
threats can occur due to the interests of various individuals or groups in certain aspects of
community life that can cause various physical threats, both real and unreal by using
computer codes (software) to steal information (information theft), system destruction,
information manipulation (information corruption) or hardware (hardware) to disrupt the
system (network instruction) or disseminate certain data and information to carry out
propaganda activities.16
The sources of cyber threats can come from various sources, such as foreign
intelligence services, disaffected employees, investigation journalists, extremist
organizations, and hacktivist activities, and groups crime groups organized crime groups.
The risk of cyber crime has the potential to lose data information systems, military
activities and other disruptions that use computer networks and the internet. In looking at the
20
0
sources of threats above, the government through the Ministry of Defense (Kemhan) needs to
prepare itself in facing this cyber threat. The Ministry of Defense needs to prepare Human
Resources who are reliable in mastering technology, reliable infrastructure systems, and
supported by legislation or policies in carrying out cyber warfare operations.
2.0 Discussion:
Indonesia is among the top five countries that use social media and is considered a
potential positive (strength) or potential negative (vulnerability/weakness) when it comes to
the potential for cyber warfare. The use of social media among the public can potentially
threaten state sovereignty. But on the other hand, social media can also be a source of
knowledge about the world of information, communication and digital technology, so that
people can be digitally literate. The activities of Indonesian people who use digital
technology will eventually become a potential in cyber warfare. The use of information
technology will be easily tapped or hacked by hackers and crackers from foreign countries,
thus creating vulnerability, especially intelligence information that uses cyberspace as a
means of transmission. Rapidly advancing wiretapping technology to hack various social
media users will be very dangerous in the era of cyber warfare.
Risk management is defined as "the process of understanding and managing the risks
that an organization is inevitably subject to in attempting to achieve its corporate
objectives".17 Risk management is also defined as "the essence of risk management lies in
maximizing the areas where we can mitigate risk have some control over the outcome while
minimizing the areas where we have absolutely no control over the outcome, and the linkage
between effect and cause is hidden from us".18
Referring to the two definitions above, risk management is a continuous process,
carried out during defense management activities in the face of cybercrime threats. Risk
management is management that plans advanced plans in the face of risk and uncertainty in
order to maximize the achievement of objectives.
Elements of risk management according to the Institute of Risk Management include
Risk Assessment, which is the process of identifying, describing and estimating; Risk
Evaluation, decision-making about significant risks that should be assigned to a risk
management program. Risk treatment depends on risk appetite; risk treatment, risk appetite is
carried out response or treatment which is a process of selection and implementation. The several
stages in the risk management process that can be implemented in dealing with the threat of cyber
crime are described below: 19
Identify:
In this stage, the identification of cybercrime risks should be carried out periodically against
the triggers of cybercrime. In this process, all aspects that have the potential to cause harm
are carefully identified. All identified risks are then measured. The risk measure for this
threat refers to two measures, namely Probability and Impact Probability.
Assess:
In this stage, assess or assessment basically assesses the level of risk posed by cybercrime
that impacts all aspects of life, especially national defense. The assessment of cybercrime
cannot be measured directly but can use a matrix table in measuring the risks posed by
cybercrime.
Treat:
After identifying and Risk measurement is then used as a basis for determining the treatment
and response to risk, whether the risk will be accepted, transferred, minimized or avoided. In
this case, it is necessary to minimize the theft of information and data that often occurs both
individually and institutionally.
Control:
Continuous monitoring and adjustments should be made to assess the success of risk
management. In the monitoring process, there should be an early warning mechanism for
security controllers such as the Ministry of Defense of the Republic of Indonesia, so that
controllers can take the necessary actions to anticipate cybercrime.
Risk Matrix:
The potential threat of cyber crime leads to cyber warfare. The potential threats of cyber
crime in Indonesia are as follows.
Hacking
Hacking cases have occurred several times in Indonesia. The causes vary from simply
hacking security to rejection of government discourse. For example, in the 2014 presidential
election, news spread that the General Election Commission (KPU) website had been hacked
by hackers. The indication is that the KPU site could not be accessed.20
20
2
Not only in the government sector, but private parties often experience hacking by hackers.
Recently, Telkomsel Company was hacked by hackers. On the page, the hacker protested the
price of the Telkomsel data package which was considered too expensive. The description
also contains harsh words complaining about it.
Cracking:
Cracking cases occurred in Indonesia by way of "carders" who only snooping on credit cards
then crackers snoop on customer deposits at various banks or other sensitive data centers for
personal gain. Experienced crackers create their own scripts or programs for cracking, which
are targeted, namely credit card databases, bank account databases, customer information
databases, and purchases of goods with fake credit cards.
Cyber Sabotage:
Cyber sabotage is carried out by disrupting, damaging or destroying data, computer network
systems connected to the internet. Cyber sabotage is the most feared mode by almost major
industries in the world. At least the 'beautiful' modes at play vary from malicious network
posts and social vilification, all the way to consumer information, hacking, and leaking of
company systems such as card numbers or industry secrets.
Spyware:
Spyware is a program that can secretly record any online activity of the user, such as
recording cookies or registry. The recorded data will be sent or sold to companies or
individuals who will send advertisements or spread viruses.24 Malware cases occur in
Indonesian people who use online banks. Perpetrators spread malware to trick their victims.
Malware is spread to customers' cell phones through fake internet banking software
advertisements that often appear on a number of internet pages.
When the customer downloads the fake software, the malware will automatically enter
the cell phone and manipulate the appearance of the internet banking page as if the page
really came from the perpetrator spreading malware to trick their victims. Internet banking
malware as if the page really came from the bank.
National Defense in the Face of Cyber Crime:
In the military aspect, cyber is used as a tool to attack the opponent's strength or find out the
opponent's weakness and damage the defense network. In achieving a power, cyber depends
on a country's strategy and policy to develop cyber security.
Establishment of cyberarmy is part of the development of the Cyber Defense Center
(cyber defense) The risk of cyber threats is growing is increasing. Pusdatin of the Indonesian
Ministry of Defense said that the cyberwar cold war is running in a global context. Sooner or later,
Indonesia will be involved in it where this cyberwar can be carried out by nation-state actors.
Cyberwar is seen as a situation where a country penetrates a computer or other device
which includes the defense of the Ministry of Defense's communication and information
systems. Cyberarmy consists of the military, namely the Army, Air Force, and Navy as well
as civilians who participate in national defense in the field of Technology and Information.
Cyberarmy is needed as a national defense that can fend off all attacks in cyberspace that can
interfere at any time the integrity of the Republic of Indonesia.25 Cyberarmy is also required
to have the ability to attack that can keep up with the advancement of technology and
information of other countries.
In national defense, both military and non-military, it is very important to have a new
system as a modern generation and future war, in the field of technology and information
defense. In addition to strong national defense, legal support is also needed that influences
and is interconnected in dealing with the threat of cyber crime. Law is needed to create order
and justice in society.
Technology, law and society are now inseparable. Along with technological advances,
society is required to continue to develop and often results in the emergence of new crimes in
technology. Therefore, the law is the most important part to overcome criminality that can
damage national defense.
Cyber crime in Indonesia is rampant, whether committed by individuals or groups.
There are various types of cyber-related crimes, ranging from copyright, piracy, misuse of
access to defamation of individuals and institutions. However, this is in stark contrast to the
laws governing cybercrime, which still have very few restrictions which can be used as a
reference to ensnare the perpetrator in committing a crime. This imbalance makes the law less
strong. Law enforcement in Indonesia regarding computer misuse is influenced by several
factors, namely the law, the mentality of the officials, community behavior, facilities and
20
4
culture.
The Indonesian Ministry of Communication and Information notes that there are 21
laws and 25 bills that will be affected by laws regulating cybercrime. Harmonization external
in the form of adjustments to the formulation of cybercrime articles with similar provisions
from other countries, especially with the Draft Convention on Cyber Crime and cybercrime
regulations from other countries. The world of internet technology has revolutionized and
innovated human communication.
The ITE Law is a law that specifically regulates cyber crimes in both criminal law and
criminal procedure law. The new law is cyberlaw. Cyberlaw itself is used for law
enforcement related to the use of information technology in anticipating people's behavior on
information technology, as a limitation to commit crimes (Law of Information Technology)
and cyberspace law.
IT HR Planning to Face the Threat of Cyber Crime
The preparations that Indonesia must have in facing cyber crime are human resources and
state security production facilities. Competency-based human resources are expected to be
able to create a positive way of thinking about the dynamics of global environmental change
so as to increase awareness of technological and information developments that have various
impacts on people's lives, especially with regard to cyber threats.
In order to anticipate cyber crime, technology experts are needed that can support a
sophisticated and modern national defense system. Therefore, it is necessary to cooperate
with the Indonesian defense industry that can make a modern defense system information and
communication system program that can compete with other countries. The increasing role of
the military in developing a cyber defense system in Indonesia is undeniable. Cyber military
defense prepares operations and resources to improve national cyber security.
The development of a cyber defense system in Indonesia is influenced by two factors.
The first factor is regulation and the second is the existence of a cyber command center. The
government needs to make a good and appropriate regulation related to the development of
national cyber security. As a comparison, regulations made by the American government are
the USA cyber attack convention, the draft cyber warfare international law manual and the
council of Europe convention on cyber crime 2001.30
Another important thing is to build a cyber defense security command center. The
Indonesian government will implement a cyber operation command that aims to become a
cyber defense command center in Indonesia. When the command center can be run, there is
great hope for the Indonesian people who are ready to anticipate non-traditional threats,
namely cyber crime, which is increasingly having an impact on the sovereignty of the
Republic of Indonesia. This is a big step that needs to be continued to run optimally. The
need for proper regulation and Cooperation with all parties, both government and private, can
be the key in facing the increasingly complex challenges of the cyber world.31
The IT HR planning process is part and function of personnel development within the
Ministry of Defense and its ranks.32 This function is carried out by the Personnel Bureau, in
accordance with Minister of Defense Regulation No. 16/2010, article 41, paragraph 2 that the
Procurement of Ministry of Defense, TNI Headquarters and Forces civil servants and the
development of Ministry of Defense employees. The IT HR planning process is based on
certain criteria, such as educational background, administration, physical, health, and HR
psychology, must be taken into consideration. The procurement process of civil servants
within the Ministry of Defense has several stages starting from the procurement process,
education, use, maintenance and separation.
Efforts to realize competency-based HR are the main capital in facing various changes
in the strategic environment and technological advances today. IT HR planning pays more
attention to quality than quantity to meet personnel needs. Understanding the educational
background of IT HR both formal and informal education is very helpful for organizations in
producing quality IT HR. Therefore, the preparation of IT HR requires capabilities on
national defense systems, network systems, applications, and policies related to cyber.
3.0 Conclusion:
The threat of cybercrime in the form of theft of confidential information and data is
aimed at attacking individuals, government agencies and the military with the defense of
a country. The government through the Ministry of Defense needs to prepare itself in
facing this cyber threat. The Ministry of Defense needs to prepare Human Resources
who are reliable in mastering technology, reliable infrastructure systems, and supported
by legislation or policies in carrying out cyber warfare operations.
Risk management in the field of information and communication that relates to the lives
20
6
of many citizens or that is confidential is something that is done to reduce the level of
vulnerability of misuse of information and data in cyberspace. Risk management is a
fundamental element of a strategy. Risk is a combination of likelihood and consequence.
It answers the question of how likely a probability is to occur and how bad the
consequences are. Therefore, risk management is important to prepare a good national defense
system.
Achieving cyber power depends on a country's strategy and policy to develop cyber
security. In addition to a strong national defense, it also requires legal support that
influences and is interconnected in facing the threat of cyber crime. The need for proper
regulation and cooperation with all parties, both government and private, can be the key
in facing the increasingly complex challenges of the cyber world.
The era of globalization encourages some countries to no longer use traditional and
conventional ways of warfare traditional and unconventional ways of war. As a result, the
strength of the state is no longer seen in the strength of weapons, but also in terms of culture,
economy, politics, and technology. This makes competition and warfare increasingly
invisible. Wars and conflicts that occur in a country are not only dominated by military
forces, but non-military forces are also carried out by non-state actors. Threats that evolve
into cyberattacks are not just a concept. The vulnerability of information exchange in
cyberspace has encouraged countries to build security systems that can overcome these
threats. The events in Estonia in 2007 and Georgia in 2008 are examples of cybercrime
attacks using Distributed Denial of Service (DdoS), which paralyzed the country's activities
because many critical sectors were attacked.3 Another attack that has been noted to be quite
alarming is the Stuxnet attack. Stuxnet is an example of highly sophisticated malware that
managed to paralyze one-fifth of the nuclear enrichment control systems of Iran's nuclear
power plants.4
Threats in cyberspace are dominated by non-state actors such as individual hackers,
hacker groups, hacker activities, non-government organizations (NGOs), terrorism,
organized criminal groups and the private sector (such as internet companies and carries,
security companies) can also threaten the defense and sovereignty of the state cybercrime has
occurred in the case of interception of personal communications of the President of Indonesia and
several high-ranking state officials by Australia based on documents leaked by Edward Snowden, a
former contractor of the National Security Agency (NSA) from America.6 In addition, one of the
official websites of the Ministry of Defense of the Republic of Indonesia (Kemhan RI) was broken
into by hackers, namely the website belonging to the Directorate General of Defense Potential (Ditjen
Pothan) which experienced a page change called defacing7 . The site was broken into by CVT (Cyber
Vampire Team) by writing the site page "Oops Myanmar Hacker was here". Then write a sentence in
English, namely:
Hello Indonesia Government, you should be proud with uneducated Indo script kiddies.
Coz they believe (defacing / Ddosing) to other country website is the best solution for them. If
you would sympathize the white programmers/ developers of your country and how they are
feeling. You can catch such script kiddies. Coz CVT are ready to provide those kiddies
information.
Global threats, advances in technology and information are not only aimed at attacking
government and military agencies, but can also threaten all aspects of human life, such as the
economy, politics, culture, and security of a country. Recently, a cyberattack also occurred on
the website of the government-owned telecommunications industry. The threat of cybercrime
can occur due to the interests of various individuals or groups. This threat in the aspect of
people's lives poses various real or unreal physical threats by using computer codes
(software) to steal information and data that can threaten a country.
The increase in the threat of cybercrime committed by both state and non-state actors
has an impact on the occurrence of cyber warfare or cyber violence. The country's
dependence on communication networks brings its own challenges and threats. Therefore,
risk management analysis is needed in the face of cyber crime attacks with the aim of
maintaining the defense and sovereignty of the Republic of Indonesia in realizing national
goals. Risk management can be interpreted as a series of procedures and methodologies used
to identify, measure, monitor and control risks arising from organizational activities. Risk
management in the field of information and communication that relates to the lives of many
citizens or is confidential, is something that is done to reduce the level of vulnerability of
misuse of information and data in cyberspace.
Risks that occur in facing the threat of cyber crime come from within and outside the
country by utilizing social, political, cultural, ideological conditions and technological
developments. Many ways are done by various parties to obtain information in the State
Defense Information System (Sisfohanneg). Some attacks have even been carried out, for
example, hacking action by defacing the website of the Director General of Pothan Kemhan.
The leaking of information related to national defense contained in Sisfohanneg can threaten
state sovereignty, especially information sovereignty. The concept of risk management in
20
8
defense is an important element to analyze how much a threat impacts national defense.
In the context of facing the threat of cyber crime attacks, it cannot be solved by using
only the power of weapons. But it requires the integration of all national forces under the
command and control (Kodal) of the Ministry of Foreign Affairs. Defense (MoD). The risks
faced in overcoming the threat of cyber crime are no less than conventional warfare. The use
of cyber technology has a broad impact because it can cover various aspects of social and
state life, including the fields of ideology, politics, economics, socio-culture, and security.
Cyber crime is increasing which is utilized by certain parties either individually or in groups
or countries with a specific purpose to be able to weaken their opponents. This condition
needs to be watched out for because it does not rule out the possibility that a country can be
paralyzed and destroyed by technological warfare or through cyber.11
As a sovereign and civilized nation, it is necessary to maintain the integrity of a country
by building a strong national defense in order to achieve the goals of national interests. The
various conditions above illustrate the importance of risk management identification in
dealing with the threat of cyber crime in the management of national defense development.
1.1 Definition of Cyber Crime:
Technology is an activity that is born by humans with planning and creating material
objects of practical value, such as cars, airplanes, televisions are the result of technological
development. Judging from the function and importance of technology, all circles of society
and government agencies are very dependent on technology both used for positive and
negative things. The words cyber and technology are described from the origin of the word
technique, from the Greek word Technikos which means art or skill in and logos is limo or
the main principles of cyber (software).12 The increasing use of cyberspace in all lines of
people's lives in the current era of globalization in parallel, will connect to the use of an
internet technology network in certain objects or sectors according to the purpose of its
operation.
Cyberspace is a space where communities are interconnected using networks (e.g. the
internet) to carry out various daily activities.13 Cyber is defined by another term, cyberspace,
which is derived from cybermetrics data. Initially, the term cyberspace was not intended to
describe interactions that occur through computer networks. John Perry Barlow in 1990
applied the term cyber to the internet network. In its development, cyber Internet applications
can bring positive and negative impacts that can lead to crimes in the development of the
cyber world. Crimes that are born as a negative impact of the development of applications on
the internet are called cyber crimes, which include all types of crimes and their modus
operandi carried out as a negative impact of internet applications.
In the opinion of Mcdonnell and Sayers, cyber threats are of three types,14 namely:
Hardware threat
This threat is a threat caused by the installation of certain devices that function to perform
certain activities in a system, so that the equipment is a disruption to network systems and
other hardware.
Software threat:
This threat is a threat caused by the introduction of software software that functions to carry
out theft, destruction, and manipulation of information.
Data/information threats (data/ information threat):
This threat is a threat caused by the dissemination of certain data/information aimed at the
interests of the community.
In the Strategic Cyber Security study National, defines the threat of cybercrime as every
condition and situation as well as the ability that is considered to be able to perform actions
or interference or attacks that are capable of damaging or everything that is detrimental so as
to threaten the confidentiality, integrity, and availability of systems and information.15 Cyber
threats can occur due to the interests of various individuals or groups in certain aspects of
community life that can cause various physical threats, both real and unreal by using
computer codes (software) to steal information (information theft), system destruction,
information manipulation (information corruption) or hardware (hardware) to disrupt the
system (network instruction) or disseminate certain data and information to carry out
propaganda activities.16
The sources of cyber threats can come from various sources, such as foreign
intelligence services, disaffected employees, investigation journalists, extremist
organizations, and hacktivist activities, and groups crime groups organized crime groups.
The risk of cyber crime has the potential to lose data information systems, military
activities and other disruptions that use computer networks and the internet. In looking at the
21
0
sources of threats above, the government through the Ministry of Defense (Kemhan) needs to
prepare itself in facing this cyber threat. The Ministry of Defense needs to prepare Human
Resources who are reliable in mastering technology, reliable infrastructure systems, and
supported by legislation or policies in carrying out cyber warfare operations.
2.0 Discussion:
Indonesia is among the top five countries that use social media and is considered a
potential positive (strength) or potential negative (vulnerability/weakness) when it comes to
the potential for cyber warfare. The use of social media among the public can potentially
threaten state sovereignty. But on the other hand, social media can also be a source of
knowledge about the world of information, communication and digital technology, so that
people can be digitally literate. The activities of Indonesian people who use digital
technology will eventually become a potential in cyber warfare. The use of information
technology will be easily tapped or hacked by hackers and crackers from foreign countries,
thus creating vulnerability, especially intelligence information that uses cyberspace as a
means of transmission. Rapidly advancing wiretapping technology to hack various social
media users will be very dangerous in the era of cyber warfare.
Risk management is defined as "the process of understanding and managing the risks
that an organization is inevitably subject to in attempting to achieve its corporate
objectives".17 Risk management is also defined as "the essence of risk management lies in
maximizing the areas where we can mitigate risk have some control over the outcome while
minimizing the areas where we have absolutely no control over the outcome, and the linkage
between effect and cause is hidden from us".18
Referring to the two definitions above, risk management is a continuous process,
carried out during defense management activities in the face of cybercrime threats. Risk
management is management that plans advanced plans in the face of risk and uncertainty in
order to maximize the achievement of objectives.
Elements of risk management according to the Institute of Risk Management include
Risk Assessment, which is the process of identifying, describing and estimating; Risk
Evaluation, decision-making about significant risks that should be assigned to a risk
management program. Risk treatment depends on risk appetite; risk treatment, risk appetite is
carried out response or treatment which is a process of selection and implementation. The several
stages in the risk management process that can be implemented in dealing with the threat of cyber
crime are described below: 19
Identify:
In this stage, the identification of cybercrime risks should be carried out periodically against
the triggers of cybercrime. In this process, all aspects that have the potential to cause harm
are carefully identified. All identified risks are then measured. The risk measure for this
threat refers to two measures, namely Probability and Impact Probability.
Assess:
In this stage, assess or assessment basically assesses the level of risk posed by cybercrime
that impacts all aspects of life, especially national defense. The assessment of cybercrime
cannot be measured directly but can use a matrix table in measuring the risks posed by
cybercrime.
Treat:
After identifying and Risk measurement is then used as a basis for determining the treatment
and response to risk, whether the risk will be accepted, transferred, minimized or avoided. In
this case, it is necessary to minimize the theft of information and data that often occurs both
individually and institutionally.
Control:
Continuous monitoring and adjustments should be made to assess the success of risk
management. In the monitoring process, there should be an early warning mechanism for
security controllers such as the Ministry of Defense of the Republic of Indonesia, so that
controllers can take the necessary actions to anticipate cybercrime.
Risk Matrix:
The potential threat of cyber crime leads to cyber warfare. The potential threats of cyber
crime in Indonesia are as follows.
Hacking
Hacking cases have occurred several times in Indonesia. The causes vary from simply
hacking security to rejection of government discourse. For example, in the 2014 presidential
election, news spread that the General Election Commission (KPU) website had been hacked
by hackers. The indication is that the KPU site could not be accessed.20
21
2
Not only in the government sector, but private parties often experience hacking by hackers.
Recently, Telkomsel Company was hacked by hackers. On the page, the hacker protested the
price of the Telkomsel data package which was considered too expensive. The description
also contains harsh words complaining about it.
Cracking:
Cracking cases occurred in Indonesia by way of "carders" who only snooping on credit cards
then crackers snoop on customer deposits at various banks or other sensitive data centers for
personal gain. Experienced crackers create their own scripts or programs for cracking, which
are targeted, namely credit card databases, bank account databases, customer information
databases, and purchases of goods with fake credit cards.
Cyber Sabotage:
Cyber sabotage is carried out by disrupting, damaging or destroying data, computer network
systems connected to the internet. Cyber sabotage is the most feared mode by almost major
industries in the world. At least the 'beautiful' modes at play vary from malicious network
posts and social vilification, all the way to consumer information, hacking, and leaking of
company systems such as card numbers or industry secrets.
Spyware:
Spyware is a program that can secretly record any online activity of the user, such as
recording cookies or registry. The recorded data will be sent or sold to companies or
individuals who will send advertisements or spread viruses.24 Malware cases occur in
Indonesian people who use online banks. Perpetrators spread malware to trick their victims.
Malware is spread to customers' cell phones through fake internet banking software
advertisements that often appear on a number of internet pages.
When the customer downloads the fake software, the malware will automatically enter
the cell phone and manipulate the appearance of the internet banking page as if the page
really came from the perpetrator spreading malware to trick their victims. Internet banking
malware as if the page really came from the bank.
National Defense in the Face of Cyber Crime:
In the military aspect, cyber is used as a tool to attack the opponent's strength or find out the
opponent's weakness and damage the defense network. In achieving a power, cyber depends
on a country's strategy and policy to develop cyber security.
Establishment of cyberarmy is part of the development of the Cyber Defense Center
(cyber defense) The risk of cyber threats is growing is increasing. Pusdatin of the Indonesian
Ministry of Defense said that the cyberwar cold war is running in a global context. Sooner or later,
Indonesia will be involved in it where this cyberwar can be carried out by nation-state actors.
Cyberwar is seen as a situation where a country penetrates a computer or other device
which includes the defense of the Ministry of Defense's communication and information
systems. Cyberarmy consists of the military, namely the Army, Air Force, and Navy as well
as civilians who participate in national defense in the field of Technology and Information.
Cyberarmy is needed as a national defense that can fend off all attacks in cyberspace that can
interfere at any time the integrity of the Republic of Indonesia.25 Cyberarmy is also required
to have the ability to attack that can keep up with the advancement of technology and
information of other countries.
In national defense, both military and non-military, it is very important to have a new
system as a modern generation and future war, in the field of technology and information
defense. In addition to strong national defense, legal support is also needed that influences
and is interconnected in dealing with the threat of cyber crime. Law is needed to create order
and justice in society.
Technology, law and society are now inseparable. Along with technological advances,
society is required to continue to develop and often results in the emergence of new crimes in
technology. Therefore, the law is the most important part to overcome criminality that can
damage national defense.
Cyber crime in Indonesia is rampant, whether committed by individuals or groups.
There are various types of cyber-related crimes, ranging from copyright, piracy, misuse of
access to defamation of individuals and institutions. However, this is in stark contrast to the
laws governing cybercrime, which still have very few restrictions which can be used as a
reference to ensnare the perpetrator in committing a crime. This imbalance makes the law less
strong. Law enforcement in Indonesia regarding computer misuse is influenced by several
factors, namely the law, the mentality of the officials, community behavior, facilities and
21
4
culture.
The Indonesian Ministry of Communication and Information notes that there are 21
laws and 25 bills that will be affected by laws regulating cybercrime. Harmonization external
in the form of adjustments to the formulation of cybercrime articles with similar provisions
from other countries, especially with the Draft Convention on Cyber Crime and cybercrime
regulations from other countries. The world of internet technology has revolutionized and
innovated human communication.
The ITE Law is a law that specifically regulates cyber crimes in both criminal law and
criminal procedure law. The new law is cyberlaw. Cyberlaw itself is used for law
enforcement related to the use of information technology in anticipating people's behavior on
information technology, as a limitation to commit crimes (Law of Information Technology)
and cyberspace law.
IT HR Planning to Face the Threat of Cyber Crime
The preparations that Indonesia must have in facing cyber crime are human resources and
state security production facilities. Competency-based human resources are expected to be
able to create a positive way of thinking about the dynamics of global environmental change
so as to increase awareness of technological and information developments that have various
impacts on people's lives, especially with regard to cyber threats.
In order to anticipate cyber crime, technology experts are needed that can support a
sophisticated and modern national defense system. Therefore, it is necessary to cooperate
with the Indonesian defense industry that can make a modern defense system information and
communication system program that can compete with other countries. The increasing role of
the military in developing a cyber defense system in Indonesia is undeniable. Cyber military
defense prepares operations and resources to improve national cyber security.
The development of a cyber defense system in Indonesia is influenced by two factors.
The first factor is regulation and the second is the existence of a cyber command center. The
government needs to make a good and appropriate regulation related to the development of
national cyber security. As a comparison, regulations made by the American government are
the USA cyber attack convention, the draft cyber warfare international law manual and the
council of Europe convention on cyber crime 2001.30
Another important thing is to build a cyber defense security command center. The
Indonesian government will implement a cyber operation command that aims to become a
cyber defense command center in Indonesia. When the command center can be run, there is
great hope for the Indonesian people who are ready to anticipate non-traditional threats,
namely cyber crime, which is increasingly having an impact on the sovereignty of the
Republic of Indonesia. This is a big step that needs to be continued to run optimally. The
need for proper regulation and Cooperation with all parties, both government and private, can
be the key in facing the increasingly complex challenges of the cyber world.31
The IT HR planning process is part and function of personnel development within the
Ministry of Defense and its ranks.32 This function is carried out by the Personnel Bureau, in
accordance with Minister of Defense Regulation No. 16/2010, article 41, paragraph 2 that the
Procurement of Ministry of Defense, TNI Headquarters and Forces civil servants and the
development of Ministry of Defense employees. The IT HR planning process is based on
certain criteria, such as educational background, administration, physical, health, and HR
psychology, must be taken into consideration. The procurement process of civil servants
within the Ministry of Defense has several stages starting from the procurement process,
education, use, maintenance and separation.
Efforts to realize competency-based HR are the main capital in facing various changes
in the strategic environment and technological advances today. IT HR planning pays more
attention to quality than quantity to meet personnel needs. Understanding the educational
background of IT HR both formal and informal education is very helpful for organizations in
producing quality IT HR. Therefore, the preparation of IT HR requires capabilities on
national defense systems, network systems, applications, and policies related to cyber.
3.0 Conclusion:
The threat of cybercrime in the form of theft of confidential information and data is
aimed at attacking individuals, government agencies and the military with the defense of
a country. The government through the Ministry of Defense needs to prepare itself in
facing this cyber threat. The Ministry of Defense needs to prepare Human Resources
who are reliable in mastering technology, reliable infrastructure systems, and supported
by legislation or policies in carrying out cyber warfare operations.
Risk management in the field of information and communication that relates to the lives
21
6
of many citizens or that is confidential is something that is done to reduce the level of
vulnerability of misuse of information and data in cyberspace. Risk management is a
fundamental element of a strategy. Risk is a combination of likelihood and consequence.
It answers the question of how likely a probability is to occur and how bad the
consequences are. Therefore, risk management is important to prepare a good national defense
system.
Achieving cyber power depends on a country's strategy and policy to develop cyber
security. In addition to a strong national defense, it also requires legal support that
influences and is interconnected in facing the threat of cyber crime. The need for proper
regulation and cooperation with all parties, both government and private, can be the key
in facing the increasingly complex challenges of the cyber world.
The era of globalization encourages some countries to no longer use traditional and
conventional ways of warfare traditional and unconventional ways of war. As a result, the
strength of the state is no longer seen in the strength of weapons, but also in terms of culture,
economy, politics, and technology. This makes competition and warfare increasingly
invisible. Wars and conflicts that occur in a country are not only dominated by military
forces, but non-military forces are also carried out by non-state actors. Threats that evolve
into cyberattacks are not just a concept. The vulnerability of information exchange in
cyberspace has encouraged countries to build security systems that can overcome these
threats. The events in Estonia in 2007 and Georgia in 2008 are examples of cybercrime
attacks using Distributed Denial of Service (DdoS), which paralyzed the country's activities
because many critical sectors were attacked.3 Another attack that has been noted to be quite
alarming is the Stuxnet attack. Stuxnet is an example of highly sophisticated malware that
managed to paralyze one-fifth of the nuclear enrichment control systems of Iran's nuclear
power plants.4
Threats in cyberspace are dominated by non-state actors such as individual hackers,
hacker groups, hacker activities, non-government organizations (NGOs), terrorism,
organized criminal groups and the private sector (such as internet companies and carries,
security companies) can also threaten the defense and sovereignty of the state cybercrime has
occurred in the case of interception of personal communications of the President of Indonesia and
several high-ranking state officials by Australia based on documents leaked by Edward Snowden, a
former contractor of the National Security Agency (NSA) from America.6 In addition, one of the
official websites of the Ministry of Defense of the Republic of Indonesia (Kemhan RI) was broken
into by hackers, namely the website belonging to the Directorate General of Defense Potential (Ditjen
Pothan) which experienced a page change called defacing7 . The site was broken into by CVT (Cyber
Vampire Team) by writing the site page "Oops Myanmar Hacker was here". Then write a sentence in
English, namely:
Hello Indonesia Government, you should be proud with uneducated Indo script kiddies.
Coz they believe (defacing / Ddosing) to other country website is the best solution for them. If
you would sympathize the white programmers/ developers of your country and how they are
feeling. You can catch such script kiddies. Coz CVT are ready to provide those kiddies
information.
Global threats, advances in technology and information are not only aimed at attacking
government and military agencies, but can also threaten all aspects of human life, such as the
economy, politics, culture, and security of a country. Recently, a cyberattack also occurred on
the website of the government-owned telecommunications industry. The threat of cybercrime
can occur due to the interests of various individuals or groups. This threat in the aspect of
people's lives poses various real or unreal physical threats by using computer codes
(software) to steal information and data that can threaten a country.
The increase in the threat of cybercrime committed by both state and non-state actors
has an impact on the occurrence of cyber warfare or cyber violence. The country's
dependence on communication networks brings its own challenges and threats. Therefore,
risk management analysis is needed in the face of cyber crime attacks with the aim of
maintaining the defense and sovereignty of the Republic of Indonesia in realizing national
goals. Risk management can be interpreted as a series of procedures and methodologies used
to identify, measure, monitor and control risks arising from organizational activities. Risk
management in the field of information and communication that relates to the lives of many
citizens or is confidential, is something that is done to reduce the level of vulnerability of
misuse of information and data in cyberspace.
Risks that occur in facing the threat of cyber crime come from within and outside the
country by utilizing social, political, cultural, ideological conditions and technological
developments. Many ways are done by various parties to obtain information in the State
Defense Information System (Sisfohanneg). Some attacks have even been carried out, for
example, hacking action by defacing the website of the Director General of Pothan Kemhan.
The leaking of information related to national defense contained in Sisfohanneg can threaten
state sovereignty, especially information sovereignty. The concept of risk management in
21
8
defense is an important element to analyze how much a threat impacts national defense.
In the context of facing the threat of cyber crime attacks, it cannot be solved by using
only the power of weapons. But it requires the integration of all national forces under the
command and control (Kodal) of the Ministry of Foreign Affairs. Defense (MoD). The risks
faced in overcoming the threat of cyber crime are no less than conventional warfare. The use
of cyber technology has a broad impact because it can cover various aspects of social and
state life, including the fields of ideology, politics, economics, socio-culture, and security.
Cyber crime is increasing which is utilized by certain parties either individually or in groups
or countries with a specific purpose to be able to weaken their opponents. This condition
needs to be watched out for because it does not rule out the possibility that a country can be
paralyzed and destroyed by technological warfare or through cyber.11
As a sovereign and civilized nation, it is necessary to maintain the integrity of a country
by building a strong national defense in order to achieve the goals of national interests. The
various conditions above illustrate the importance of risk management identification in
dealing with the threat of cyber crime in the management of national defense development.
1.1 Definition of Cyber Crime:
Technology is an activity that is born by humans with planning and creating material
objects of practical value, such as cars, airplanes, televisions are the result of technological
development. Judging from the function and importance of technology, all circles of society
and government agencies are very dependent on technology both used for positive and
negative things. The words cyber and technology are described from the origin of the word
technique, from the Greek word Technikos which means art or skill in and logos is limo or
the main principles of cyber (software).12 The increasing use of cyberspace in all lines of
people's lives in the current era of globalization in parallel, will connect to the use of an
internet technology network in certain objects or sectors according to the purpose of its
operation.
Cyberspace is a space where communities are interconnected using networks (e.g. the
internet) to carry out various daily activities.13 Cyber is defined by another term, cyberspace,
which is derived from cybermetrics data. Initially, the term cyberspace was not intended to
describe interactions that occur through computer networks. John Perry Barlow in 1990
applied the term cyber to the internet network. In its development, cyber Internet applications
can bring positive and negative impacts that can lead to crimes in the development of the
cyber world. Crimes that are born as a negative impact of the development of applications on
the internet are called cyber crimes, which include all types of crimes and their modus
operandi carried out as a negative impact of internet applications.
In the opinion of Mcdonnell and Sayers, cyber threats are of three types,14 namely:
Hardware threat
This threat is a threat caused by the installation of certain devices that function to perform
certain activities in a system, so that the equipment is a disruption to network systems and
other hardware.
Software threat:
This threat is a threat caused by the introduction of software software that functions to carry
out theft, destruction, and manipulation of information.
Data/information threats (data/ information threat):
This threat is a threat caused by the dissemination of certain data/information aimed at the
interests of the community.
In the Strategic Cyber Security study National, defines the threat of cybercrime as every
condition and situation as well as the ability that is considered to be able to perform actions
or interference or attacks that are capable of damaging or everything that is detrimental so as
to threaten the confidentiality, integrity, and availability of systems and information.15 Cyber
threats can occur due to the interests of various individuals or groups in certain aspects of
community life that can cause various physical threats, both real and unreal by using
computer codes (software) to steal information (information theft), system destruction,
information manipulation (information corruption) or hardware (hardware) to disrupt the
system (network instruction) or disseminate certain data and information to carry out
propaganda activities.16
The sources of cyber threats can come from various sources, such as foreign
intelligence services, disaffected employees, investigation journalists, extremist
organizations, and hacktivist activities, and groups crime groups organized crime groups.
The risk of cyber crime has the potential to lose data information systems, military
activities and other disruptions that use computer networks and the internet. In looking at the
22
0
sources of threats above, the government through the Ministry of Defense (Kemhan) needs to
prepare itself in facing this cyber threat. The Ministry of Defense needs to prepare Human
Resources who are reliable in mastering technology, reliable infrastructure systems, and
supported by legislation or policies in carrying out cyber warfare operations.
2.0 Discussion:
Indonesia is among the top five countries that use social media and is considered a
potential positive (strength) or potential negative (vulnerability/weakness) when it comes to
the potential for cyber warfare. The use of social media among the public can potentially
threaten state sovereignty. But on the other hand, social media can also be a source of
knowledge about the world of information, communication and digital technology, so that
people can be digitally literate. The activities of Indonesian people who use digital
technology will eventually become a potential in cyber warfare. The use of information
technology will be easily tapped or hacked by hackers and crackers from foreign countries,
thus creating vulnerability, especially intelligence information that uses cyberspace as a
means of transmission. Rapidly advancing wiretapping technology to hack various social
media users will be very dangerous in the era of cyber warfare.
Risk management is defined as "the process of understanding and managing the risks
that an organization is inevitably subject to in attempting to achieve its corporate
objectives".17 Risk management is also defined as "the essence of risk management lies in
maximizing the areas where we can mitigate risk have some control over the outcome while
minimizing the areas where we have absolutely no control over the outcome, and the linkage
between effect and cause is hidden from us".18
Referring to the two definitions above, risk management is a continuous process,
carried out during defense management activities in the face of cybercrime threats. Risk
management is management that plans advanced plans in the face of risk and uncertainty in
order to maximize the achievement of objectives.
Elements of risk management according to the Institute of Risk Management include
Risk Assessment, which is the process of identifying, describing and estimating; Risk
Evaluation, decision-making about significant risks that should be assigned to a risk
management program. Risk treatment depends on risk appetite; risk treatment, risk appetite is
carried out response or treatment which is a process of selection and implementation. The several
stages in the risk management process that can be implemented in dealing with the threat of cyber
crime are described below: 19
Identify:
In this stage, the identification of cybercrime risks should be carried out periodically against
the triggers of cybercrime. In this process, all aspects that have the potential to cause harm
are carefully identified. All identified risks are then measured. The risk measure for this
threat refers to two measures, namely Probability and Impact Probability.
Assess:
In this stage, assess or assessment basically assesses the level of risk posed by cybercrime
that impacts all aspects of life, especially national defense. The assessment of cybercrime
cannot be measured directly but can use a matrix table in measuring the risks posed by
cybercrime.
Treat:
After identifying and Risk measurement is then used as a basis for determining the treatment
and response to risk, whether the risk will be accepted, transferred, minimized or avoided. In
this case, it is necessary to minimize the theft of information and data that often occurs both
individually and institutionally.
Control:
Continuous monitoring and adjustments should be made to assess the success of risk
management. In the monitoring process, there should be an early warning mechanism for
security controllers such as the Ministry of Defense of the Republic of Indonesia, so that
controllers can take the necessary actions to anticipate cybercrime.
Risk Matrix:
The potential threat of cyber crime leads to cyber warfare. The potential threats of cyber
crime in Indonesia are as follows.
Hacking
Hacking cases have occurred several times in Indonesia. The causes vary from simply
hacking security to rejection of government discourse. For example, in the 2014 presidential
election, news spread that the General Election Commission (KPU) website had been hacked
by hackers. The indication is that the KPU site could not be accessed.20
22
2
Not only in the government sector, but private parties often experience hacking by hackers.
Recently, Telkomsel Company was hacked by hackers. On the page, the hacker protested the
price of the Telkomsel data package which was considered too expensive. The description
also contains harsh words complaining about it.
Cracking:
Cracking cases occurred in Indonesia by way of "carders" who only snooping on credit cards
then crackers snoop on customer deposits at various banks or other sensitive data centers for
personal gain. Experienced crackers create their own scripts or programs for cracking, which
are targeted, namely credit card databases, bank account databases, customer information
databases, and purchases of goods with fake credit cards.
Cyber Sabotage:
Cyber sabotage is carried out by disrupting, damaging or destroying data, computer network
systems connected to the internet. Cyber sabotage is the most feared mode by almost major
industries in the world. At least the 'beautiful' modes at play vary from malicious network
posts and social vilification, all the way to consumer information, hacking, and leaking of
company systems such as card numbers or industry secrets.
Spyware:
Spyware is a program that can secretly record any online activity of the user, such as
recording cookies or registry. The recorded data will be sent or sold to companies or
individuals who will send advertisements or spread viruses.24 Malware cases occur in
Indonesian people who use online banks. Perpetrators spread malware to trick their victims.
Malware is spread to customers' cell phones through fake internet banking software
advertisements that often appear on a number of internet pages.
When the customer downloads the fake software, the malware will automatically enter
the cell phone and manipulate the appearance of the internet banking page as if the page
really came from the perpetrator spreading malware to trick their victims. Internet banking
malware as if the page really came from the bank.
National Defense in the Face of Cyber Crime:
In the military aspect, cyber is used as a tool to attack the opponent's strength or find out the
opponent's weakness and damage the defense network. In achieving a power, cyber depends
on a country's strategy and policy to develop cyber security.
Establishment of cyberarmy is part of the development of the Cyber Defense Center
(cyber defense) The risk of cyber threats is growing is increasing. Pusdatin of the Indonesian
Ministry of Defense said that the cyberwar cold war is running in a global context. Sooner or later,
Indonesia will be involved in it where this cyberwar can be carried out by nation-state actors.
Cyberwar is seen as a situation where a country penetrates a computer or other device
which includes the defense of the Ministry of Defense's communication and information
systems. Cyberarmy consists of the military, namely the Army, Air Force, and Navy as well
as civilians who participate in national defense in the field of Technology and Information.
Cyberarmy is needed as a national defense that can fend off all attacks in cyberspace that can
interfere at any time the integrity of the Republic of Indonesia.25 Cyberarmy is also required
to have the ability to attack that can keep up with the advancement of technology and
information of other countries.
In national defense, both military and non-military, it is very important to have a new
system as a modern generation and future war, in the field of technology and information
defense. In addition to strong national defense, legal support is also needed that influences
and is interconnected in dealing with the threat of cyber crime. Law is needed to create order
and justice in society.
Technology, law and society are now inseparable. Along with technological advances,
society is required to continue to develop and often results in the emergence of new crimes in
technology. Therefore, the law is the most important part to overcome criminality that can
damage national defense.
Cyber crime in Indonesia is rampant, whether committed by individuals or groups.
There are various types of cyber-related crimes, ranging from copyright, piracy, misuse of
access to defamation of individuals and institutions. However, this is in stark contrast to the
laws governing cybercrime, which still have very few restrictions which can be used as a
reference to ensnare the perpetrator in committing a crime. This imbalance makes the law less
strong. Law enforcement in Indonesia regarding computer misuse is influenced by several
factors, namely the law, the mentality of the officials, community behavior, facilities and
22
4
culture.
The Indonesian Ministry of Communication and Information notes that there are 21
laws and 25 bills that will be affected by laws regulating cybercrime. Harmonization external
in the form of adjustments to the formulation of cybercrime articles with similar provisions
from other countries, especially with the Draft Convention on Cyber Crime and cybercrime
regulations from other countries. The world of internet technology has revolutionized and
innovated human communication.
The ITE Law is a law that specifically regulates cyber crimes in both criminal law and
criminal procedure law. The new law is cyberlaw. Cyberlaw itself is used for law
enforcement related to the use of information technology in anticipating people's behavior on
information technology, as a limitation to commit crimes (Law of Information Technology)
and cyberspace law.
IT HR Planning to Face the Threat of Cyber Crime
The preparations that Indonesia must have in facing cyber crime are human resources and
state security production facilities. Competency-based human resources are expected to be
able to create a positive way of thinking about the dynamics of global environmental change
so as to increase awareness of technological and information developments that have various
impacts on people's lives, especially with regard to cyber threats.
In order to anticipate cyber crime, technology experts are needed that can support a
sophisticated and modern national defense system. Therefore, it is necessary to cooperate
with the Indonesian defense industry that can make a modern defense system information and
communication system program that can compete with other countries. The increasing role of
the military in developing a cyber defense system in Indonesia is undeniable. Cyber military
defense prepares operations and resources to improve national cyber security.
The development of a cyber defense system in Indonesia is influenced by two factors.
The first factor is regulation and the second is the existence of a cyber command center. The
government needs to make a good and appropriate regulation related to the development of
national cyber security. As a comparison, regulations made by the American government are
the USA cyber attack convention, the draft cyber warfare international law manual and the
council of Europe convention on cyber crime 2001.30
Another important thing is to build a cyber defense security command center. The
Indonesian government will implement a cyber operation command that aims to become a
cyber defense command center in Indonesia. When the command center can be run, there is
great hope for the Indonesian people who are ready to anticipate non-traditional threats,
namely cyber crime, which is increasingly having an impact on the sovereignty of the
Republic of Indonesia. This is a big step that needs to be continued to run optimally. The
need for proper regulation and Cooperation with all parties, both government and private, can
be the key in facing the increasingly complex challenges of the cyber world.31
The IT HR planning process is part and function of personnel development within the
Ministry of Defense and its ranks.32 This function is carried out by the Personnel Bureau, in
accordance with Minister of Defense Regulation No. 16/2010, article 41, paragraph 2 that the
Procurement of Ministry of Defense, TNI Headquarters and Forces civil servants and the
development of Ministry of Defense employees. The IT HR planning process is based on
certain criteria, such as educational background, administration, physical, health, and HR
psychology, must be taken into consideration. The procurement process of civil servants
within the Ministry of Defense has several stages starting from the procurement process,
education, use, maintenance and separation.
Efforts to realize competency-based HR are the main capital in facing various changes
in the strategic environment and technological advances today. IT HR planning pays more
attention to quality than quantity to meet personnel needs. Understanding the educational
background of IT HR both formal and informal education is very helpful for organizations in
producing quality IT HR. Therefore, the preparation of IT HR requires capabilities on
national defense systems, network systems, applications, and policies related to cyber.
3.0 Conclusion:
The threat of cybercrime in the form of theft of confidential information and data is
aimed at attacking individuals, government agencies and the military with the defense of
a country. The government through the Ministry of Defense needs to prepare itself in
facing this cyber threat. The Ministry of Defense needs to prepare Human Resources
who are reliable in mastering technology, reliable infrastructure systems, and supported
by legislation or policies in carrying out cyber warfare operations.
Risk management in the field of information and communication that relates to the lives
22
6
of many citizens or that is confidential is something that is done to reduce the level of
vulnerability of misuse of information and data in cyberspace. Risk management is a
fundamental element of a strategy. Risk is a combination of likelihood and consequence.
It answers the question of how likely a probability is to occur and how bad the
consequences are. Therefore, risk management is important to prepare a good national defense
system.
Achieving cyber power depends on a country's strategy and policy to develop cyber
security. In addition to a strong national defense, it also requires legal support that
influences and is interconnected in facing the threat of cyber crime. The need for proper
regulation and cooperation with all parties, both government and private, can be the key
in facing the increasingly complex challenges of the cyber world.