IMPLEMENTATION OF THE MINISTRY OF DEFENSE'S CYBER
DEFENSE RISK MANAGEMENT TO SUPPORT NATIONAL
DEFENSE
Introduction
The current globalization that occurs throughout the world has brought the world to the
development of information and communication technology so as to create a digital era or
digital world. In this case, the development of computer technology and the internet has
become a new means for countries in the world to be utilized as a tool to carry out various
penetrations, influences and infiltrations into various countries so as to greatly encourage the
world to complex, diverse and pluralistic developments.4 The rapid development of
information and communication technology has created a huge dependence on people's life
activities. The development of information technology that includes technology
communication technology using the internet network makes interactions between people
more free without being limited by time and space.
The development of the internet network is part of human culture that continues to evolve
in search of infinite perfection in achieving convenience in communication. Interconnection
Networking (Internet) began to be developed in 1969 by the United States Department of
Defense (US Department of Defense) through a project called the Advanced Research
Project Agency Network (ARPANET) with the aim of designing and creating a computer
network that is scattered but connected to one another and centralizing information in only
one station, so that in the event of war, data and information can be accessed. It can be
quickly moved from one station to another and is not easily destroyed.
The wider and increasing utilization of information and communication technology (ICT)
through the internet network has made United States the 5th active internet user in the world
after China, India, the United States and Brazil, this can lead to increased threats such as
efforts to break data confidentiality, hijack information on websites, damage electronic
systems such as viruses, malware and ransomware and actions that can harm and against
other laws (Minister of Defense Regulation No. 82 of 2014).
Meanwhile, based on the results of the Polling United States study in collaboration with
the United States Internet Service Providers Association (APJII) in 2018, out of a total of
264 million United States, 171.17 million people or around 64.8 percent of the United States
population have connected to the Internet.6 This proving that the development of technology
and information has spread almost all circles. The development of information and
communication technology has been able to eliminate geographical barriers, which has an
impact on the increasing forms of threats to the defense and sovereignty of a country. This
global threat from technological advances not only threatens aspects of human life, such as
economics, politics, social, and culture, but also attacks strategic government and military
agencies.
The phenomenon of cyberspace illustrates the reality that the activities of modern society
are now interconnected through cyberspace and the internet. From the perspective of cyber
defense, the use of the internet is also possible for negative or destructive purposes by
parties who have the ability. Facilities available on the internet can be used to disrupt,
disrupt, and paralyze a country's crisis infrastructure.7
Ghemaoti said that the development of information technology has significantly changed
the concept of security.8 Now the interaction space cannot only be limited physically but
also extends to cyberspace. The consequence is that the state must adapt to this
development. This will lead to a new threat pattern that the state must face, namely cyber
threats. Cyber threats and attacks can be carried out by actors representing the government
(State Actors) or non-government (Non State Actors), so the perpetrators can be individuals,
groups, groups, organizations, or even a country.
It is conceivable that there is a division of troops who are computer and network experts
who then use their skills to operate and hijack the computer networks of public facilities
such as government sites, bases military bases, banks, telecommunications networks,
transportation infrastructure and services. Of course this will cause chaos and losses from all
walks of life.
The description is an example of the impact caused by cyber attacks that can be more
devastating and disruptive than physical attacks. There are many definitions of cyber attacks,
but in Minister of Defense Regulation number 82 of 2014 concerning Cyber Defense
Guidelines, it is explained that cyber attacks are all forms of actions, words, thoughts either
intentionally or unintentionally carried out by any party, with any motive and purpose,
carried out in any location, targeted at electronic systems or their contents (information) or
equipment that is highly dependent on technology and networks on any scale, against vital
and nonvital objects in the military and non-military spheres, which threaten state
sovereignty, territorial integrity and national safety.
Cyber attacks can attack any country, several cases of large-scale cyber attacks have been
recorded in the world, such as: the Titan Rain attack in 2003 which attacked important
institutions in the world. America such as the National Aeronautics and Space
Administration (NASA) and Lockheed Martin; the crippling of national critical
infrastructure in Estonia in 2007 and Georgia in 2008; the attack on the United States
Command Center in 2008; the spynet (Ghostnet) attack which was a data theft program by
the Chinese government against 103 countries in 2008; operation Aurora in 2009 which
successfully attacked major companies such as Google and Adobe System; Stuxnet attack in
2010 which paralyzed the Bushwer nuclear plant; Flame attack in 2012 which attacked the
computer network handling Iran's oil sector; cyber attack incident on Saudi Aramco Oil
Company's data in Saudi Arabia in August 2012; Panama papers incident in April 2016,
WannaCry ransomware in May 2017 and many other cases of cyber attacks on a global
scale.9
United States is not free from cyber-attacks, United States has experienced Norton,
announced that United States was second only to Iran among the 10 countries that
experienced the Stuxnet worm attack; the WannaCry Ransomware cyberattack in May 2017
that caused disruption to companies and hospitals in more than 150 countries including
United States;10 In addition, one of the official websites of the Ministry of Defense of the
Republic of United States (Kemhan RI) was broken into by hackers, namely the website of
the Directorate General of Defense Potential (DG Pothan) which experienced page changes
called defacing. The DG Pothan website was breached by CVT (Cyber Vampire Team) in
2018.
In recent years, there has also been a cyber war between United States and Malaysia.
Mutual infiltration between hackers of both countries colored this feud. This action usually
occurs when there is political conflict or competition between the two countries. Although it
does not involve the governments of both countries, the hackers attacked cyber facilities
belonging to the Malaysian and United States governments.
Another case of cyber crime is social engineering. In a document leaked by
whistleblower Edward Snowden, a former contractor of the United States National Security
Agency (NSA) published by The Guardian and ABC in November 2013, United States 6th
President Susilo Bambang Yudhoyono (SBY) along with Vice President Boediono and
several officials within the presidency were tapped by the Australian government in 2009. In
the document, it was written that Australia's electronic intelligence (Defence In another page
titled "United States President Voice Events", written by the BBC, it is mentioned that there
are allegations of spying on call data records (CDR) or a list of call recordings by Australian
intelligence against the United States head of state.
Based on the internet security monitoring report of the National Cyber and Crypto
Agency (BSSN), there were 232,447,974 cyber attacks on United States during 2018.
According to Anton Setiawan, Directorate of Digital Economy Protection of BSSN, almost
half of the attacks were malware attacks. The increase in attacks that occurs every year is a
result of the increasingly sophisticated attacks developed by cyber criminal actors. In
addition, around 60 to 70 percent of the targets of cyber attacks are the public sector.
Government sites with the .go.id domain are easy targets with port 123 being the most
frequently attacked port.
These incidents prove that United States is still vulnerable to cyber attacks. Impacts
arising from cyber attacks can be in the form of system damage, information theft,
manipulation of information or devices, information dissemination, and others.
In some countries, cyber defense is applied in all sectors, especially those with strategic
or critical data/information. The strategic sector can be illustrated by the following figure, In
the figure above, it can be seen that the intended strategic sector can be the Government
sector, Energy and Mineral Resources, Transportation, Financial Services, Health,
Information and Communication Technology, Food, Defense, Defense Industry and other
strategic sectors.
The Ministry of Defense as the leading sector of United States defense is also still
vulnerable to cyber attacks that continue to evolve with technological developments.
Therefore, these risks need to be managed by implementing management risk management at
the Ministry of Defense to support national defense.
Research Methods
The qualitative method with a phenomenological approach is indispensable in relation to
the analysis of the problem under study, so that its limits, scope, background and
significance are clear. This paper is the result of field research that examines the
implementation of cyber defense risk management Cyber Ministry of Defense to support
national defense. The data obtained is then condensed and analyzed using qualitative
description analysis techniques in order to get a meeting point in this research.
Results and Discussion
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.
Overview of the Ministry of Defense Cyber Defense Center
The Cyber Defense Center (Pushansiber) is an implementing element of the duties and
functions of the Defense Strategic Installation Agency (Bainstrahan) of the Ministry of
Defense (Kemhan). Pushansiber is led by the Head of Cyber Defense Center
(KaPushansiber). Pushansiber is located at Jl. RS Fatmawati No.1, RT.06/RW.06, Pondok
Labu, Kec. Cilandak, South New York City, South New York Area.
In carry out tasks as referred to in the Regulation of the Minister of Defense of the
Republic of United States article 1177 Number 14 of 2019 concerning Organization and
Work Procedures of the Ministry of Defense, Pushansiber organizes the following functions:
Formulation of technical policies, programs and budgets in the field of governance,
cooperation, operations, and assurance cyber defense security;
Implementation of cyber defense governance, cooperation, operations and security
assurance;
Monitoring, evaluation, control and reporting in the fields of cyber defense
governance, cooperation, operations and security assurance;
Establishment of Computer Emergency Response Team (CERT) in order to respond
to cyber attacks, as well as monitoring and evaluation in every implementation of
CERT tasks; and
Management of central administration and housekeeping.
Pushansiber employees are Civil Servants (CS), soldiers of the United States Armed
Forces (USNA). United States National Army (USNA), and personnel contract assigned to
the Ministry of Defense. The organizational structure of Pushansiber consists of three fields,
namely:
The field of governance and cooperation is in charge of preparing cyber defense
governance and cooperation including governance, cooperation, planning, cyber
implementation and maintenance;
The cyber operations field functions
o Set up preparation of technical policies in the field of cyber operations
including monitoring, analysis and reporting of cyber threats, prosecution,
digital forensics and recovery;
o Carry out cyber operations including monitoring, analyzing and reporting
cyber threats, prosecution, digital forensics and recovery;
o Monitoring, evaluation, control and reporting in the field of cyber operations;
and
o Establishment Computer Emergency Response Team (CERT) in order to
respond to cyber attacks, as well as monitoring and evaluating in every
implementation of CERT tasks.
The security guarantor field is tasked with carrying out cyber defense security
guarantees from external threats.
Implementation of Cyber Defense Risk Management at the Ministry of Defense
Cyber defense is a computer network defense mechanism that involves reaction to actions
and protection of critical infrastructure, as well as assurance of information owned by an
organization or government entity. Basically, the concept of cyber defense focuses on
preventing, detecting and mitigating cyber attacks appropriately, so that no infrastructure or
information will suffer damage.
Policy implementation is the execution of basic policy decisions, usually in the form of
laws, but can also take the form of orders or decrees important executive decisions or
judicial decisions. Typically, such decisions identify the problem to be addressed, specify
the goal or objectives to be achieved and various ways to structure or organize the
implementation process.
Implementation is an expansion of activities that adjust the interaction process between
goals and actions to achieve it requires a network of implementers, and an effective
bureaucracy.
In policy implementation, there will always be supporting and inhibiting factors for a
policy, both internal and external. George C. Edward III in his theory, suggests four factors
that determine the success of a policy, namely Communication, Resources, Disposition and
Bureaucratic Structure. This process is a performance of a policy which is basically carried
out to achieve good public policy implementation performance, that takes place in the
relationship of various factors.
Communication
Communication determines the success of achieving the objectives of policy
implementation. Implementation can occur if decision makers already know what they will
do. Knowledge of what will be done can only work if communication goes well, so that
every policy decision and regulation on implementation must be transmitted through
communication to the right parts. In addition, the communicated policies must be precise,
accurate and consistent. Communication or information transmission is needed so that
decision makers and implementers are more consistent in implementing each policy to be
implemented.
A good way to explain communication is to fulfill the five elements that are present in
communication,19 these elements are:
The messenger, namely someone who gives a message to the recipient of the
message. In this case the messenger must be able to understand what he wants to
convey to the recipient of the message.
Message, namely the message to be conveyed must be a message that is easy to
understand and has a meaning that is easy to understand so that the recipient of the
message understands what is conveyed by the messenger.
Media, which is a means or tool to convey messages. In this case as a bridge
between the messenger and the recipient of the message.
The recipient of the message, namely the party addressed by the messenger. A
communication is said to be successful if the message is delivered and can be
received properly by the recipient of the message.
Communication established by the Ministry of Defense both internally and externally
between stakeholders inside and outside the Ministry of Defense is still not optimal. Internal
communication conducted by Pushansiber in supporting this communication aspect is by
meeting face-to-face between personnel and interested leaders. While external
communication is carried out to external parties through correspondence between agencies
and using electronic communication such as E-mail. Pushansiber and BSSN are not in one
line of command, so cyber-related coordination is carried out through correspondence and
E- mail. As for the FGD and Cyber Drill Test activities from BSSN, only a few Pushansiber
delegates participated.
In connection with this communication, Pushansiber also applies defense management
principles in the form of the Coordination Function. The coordination task is concerned with
uniting and combining the efforts of all parts of the organization or all members of the work
group, in the achievement of common goals defined in the planning stage. This involves
integrating the various parts involved in the tasks, ordering and linking the various parts
activities that need to be done, and maintaining effective communication.
In responding to effective cyber defense development policies in the defense
environment, the Ministry of Defense, especially Pushansiber, coordinates with each other in
formulating strong cyber defense policies within the Ministry of Defense, of course in
making these policies it involves people who are experts in their fields. At the internal level,
coordination is carried out directly in accordance with the substance and subject matter to be
carried out or through meetings that invite related work units within the Ministry of Defense.
At the external level, coordination is carried out through meetings between ministries or
other institutions related to the substance discussed or with seminar activities involving
other related ministries / institutions in order to obtain constructive input for mutual benefit.
Coordination both at the internal and external levels of the Ministry of Defense is carried out
through the medium of Leadership Coordination Meetings and Work Meetings.
The flow of coordination has been regulated by the government by making BSSN the
leading sector of cyber defense. Cyber management by BSSN covers the cyberspace of
Polri, Ministry of Defense, Attorney General's Office, USNA, Kominfo and other
ministries/agencies. Therefore, BSSN must have a National Command and Control Center
System in the cyber field. While other institutions take care of a different field, such as
Pushansiber within the Ministry of Defense, Satsiber within the USNA, Polri in the field of
cyber crime, and so on.
Resources
The resource factor plays a very important role in implementation. If an implementation
has clear provisions and rules, but if the resources that will carry out the implementation
cannot carry out the policy effectively, the implementation that was running effectively will
be ineffective. The resources owned will determine the success or failure of the
implementation if these resources are able to facilitate the effective implementation of the
implementation. .Pushansiber in carrying out points the has implement several points very
well to support cyber defense at the ministry of defense. The resource factors owned by
Pushansiber include human resources, budget resources, and facility resources.
Human Resources
Edward III in Widodo (2010: 98) states that perhaps the most important resource in policy
implementation is human resources.21 Human resources are the main supporting pillar as
well as the driving force of the organization's wheels in efforts to realize the vision and
mission of the organization.
In order to carry out their duties properly, there are several general requirements that must
be considered by cyber defense institutions in HR development such as in terms of HR
recruitment. The recruitment process must pass a mental readiness test through a
psychological test to be in accordance with profile of HR for cyber defense. Selected human
resources must have competencies in accordance with the needs, in terms of knowledge and
skills according to their placement and assignments in cyber defense as well as ensuring the
career development of the HR concerned. For special tasks that are confidential and
strategic, the selected HR must have an employment status that does not violate the
principles of defense organizations, especially for offensive tasks or in cyber war conditions.
Budget Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget resources will
affect success cannot be implemented optimally.
Budgets are concerned with the adequacy of investments or capital to ensure the
implementation of a policy program. Because without the support of an adequate budget, the
policy will not run effectively in achieving goals and objectives.
The budget resources owned by Pushansiber are currently the biggest source of
constraints. In this budget resource problem, it turns out that Pushansiber does not yet have a
stand-alone budget. This is because Pushansiber has only been established for two years.
Pushansiber used to be a fraction of Pusdatin Kemhan. For this reason, until now the
existing budget is still a spillover from Pusdatin until 2018, while for 2019 the budget
received is no longer available.
Facility Resources
Edward III states that the limited budget available causes the quality of services that
should be provided to the community to be limited. Limited resources budget will affect the
success of policy implementation because it cannot be implemented optimally.
According to Richardus Eko Indrajid (2014) there are aspects related to the physical
environment that must be really considered by companies to support data security, namely:
Access to the organization, the environment around the organization, the information center
area, the server room, the workstation area, wireless access points, facsimile and other
electronic media, access control entities, computer asset management, eavesdropping, and
remote access.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, cyber defense institutions require technological/infrastructure support such as:
(1) Building infrastructure/location of data center, NOC, laboratory and other supporting
facilities, (2) Data Center and Disaster Recovery Center (DRC), (3) Data Network, (4)
Cyber defense administration applications, (5) Cyber defense technical applications,
(6) Specialized technology (Hardware and software supporting specific cyber defense
activities)
For the surrounding environment, the Pushansiber office is in a public area and close to a
traditional market. Until now, there are still no mess facilities for Pushansiber personnel.
Building which used The current Pushansiber used to be a building owned by Pusdatin
Kemhan. However, with the new organizational structure, this building was finally handed
over to Bainstrahan, and was converted to Pushansiber as it is today. The condition of the
building for organizational activities is quite good with many closed rooms. The condition
of the building is also well organized and has neatly arranged room divisions. All special
rooms have access cards installed and only certain people can enter the room.
Disposition (Attitude/Commitment)
The disposition or attitude of policy implementers according to Edward III (1980) is the
third important factor in approaching the implementation of a policy. If the policy is to be
effective, then the policy implementers must not only know what to do but also have the
ability to carry it out One of the factors that influence policy implementation is the attitude
of the implementer. If the implementers agree with the content parts of the policy then they
will implement happily but if their views differ from the policy makers then the
implementation process will experience many problems. It is the same in the Ministry of
Defense, in all ministries and other institutions that the commitment and vision of the leader
is very important in running the wheels of the organization through the planned programs.
In implementing the implementation in terms of this disposition, Pushansiber also at the
same time implementing function Briefing. The directing function in Defense management
is the process of motivating, leading and influencing people in achieving common goals in
defense. Direction requires organizational sense and skills, and the capacity of leadership to
motivate subordinates through a pleasant working atmosphere.
Policies and regulations are also needed to maintain the direction of development
activities. development activities and cyber defense development and implementation
activities so that they are always in accordance with the laws and regulations. At the
operational level, regulatory policies are in the form of guidelines, implementation
instructions, technical instructions which are the main reference for cyber defense. The
procedure for formulating the determination and implementation of cyber defense policies
follows the procedures based on laws and regulations and is carried out by considering
national needs, the development of cyber defense situations and conditions and
technological developments.
Based on Minister of Defense Regulation No. 82 of 2014 concerning Cyber Defense
Guidelines, the operational policy for the implementation of cyber defense is Form:
(Information Security Planning), Incident Response, IT Risk Management, Disaster
Recovery, Rehabilitation and Reconstruction, Vendor Management, Network Operations,
System and Application Security, Access Control, Change Control, Disaster Recovery,
Disaster Rehabilitation and Reconstruction. Rehabilitation and Reconstruction, Vendor
Management, Network Operations, System and Application Security, Access Control,
Change Control, Physical Security, Data Classification, Handling, and Disposal, Personnel
Security, System Access and Acceptable Use, Online Privacy, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness, Security Training and Awareness, Security
Training and Awareness, Security Training and Awareness, Security Training and
Awareness, Security Training and Awareness Security Training and Awareness, Self-
Assessment, Security Metrics and Measurement, Security Training and Awareness, Self-
Assessment and Self-Assessment (Security Metrics and Measurement, Mobile Computing,
Wireless Security.
The handling that will be carried out by Pushansiber in the future is that if Pushansiber
already has a budget, Pushansiber will be audited first in terms of people, processes, and
technology. How are the personnel who there is, the current process, to the technology used.
Based on the results of the audit, Pushansiber will take action. Whether later each personnel
must have certifications including CCNE, CCNP, Ethical Hacker, forensics and so on. After
that, training will be proposed for existing personnel. Then in terms of the process, because
Pushansiber still does not have a Standard Operational Procedure (SOP), later Pushansiber
will propose an SOP, Pushansiber plans to make 32 SOPs in each laboratory. After that,
Pushansiber will adopt ISO 27001, ISO 27005, Cobit, Cosco, NIST and others, while in
terms of technology it will be audited, whether the technology used today is still relevant to
the times, or the existing technology must be upgraded.
Conclusions
The implementation of cyber defense risk management at the Ministry of Defense is still
considered less than optimal in terms of to The success of policy implementation includes
communication, resources, bureaucratic structure, and disposition. In the aspect of
communication, there is still no further cooperative relationship between the Cyber Defense
Center and other agencies that are also engaged in cyber handling. In the aspect of resources,
the Cyber Defense Center (Pushansiber) is still constrained by the number of personnel, the
qualifications of personnel who still do not have certification and the limited budget
available. In the aspect of attitude / commitment, Pushansiber has shown an attitude and
commitment in its efforts as an organization engaged in securing networks within the
Ministry of Defense. It's just that in this case Pushansiber still doesn't have a Standard
Operational Procedure (SOP) related to risk management.