Claim Missing Document
Check
Articles

Found 3 Documents
Search

Bank Indonesia's It Audit Guidelines For Payment Service Providers In The SME Category: an Integrated ISO 27001:2022 Annex A, and Cloud-Based Solution Architecture Design Suarjan; Moh. A. Amin Soetomo; Heru Purnomo Ipung
Jurnal Penelitian Pendidikan IPA Vol 11 No 10 (2025): October
Publisher : Postgraduate, University of Mataram

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.29303/jppipa.v11i10.12899

Abstract

Small and Medium Enterprises (SMEs) in Indonesia face significant challenges in complying with Bank Indonesia's (BI) stringent Payment Service Provider (PJPP) licensing requirements, including cybersecurity mandates (BI 23/6/PBI/2021). This study addresses these challenges by designing a cost-effective, cloud-based solution architecture aligned with ISO 27001:2022 Annex A, simplifying compliance for resource-constrained SMEs. This framework helps SMEs prepare for IT audits with guidelines aligned with Bank Indonesia requirements and the ISO 27001:2022 Annex A standard, and replaces complex enterprise architectures with lightweight, cloud-centric models that leverage Indonesian cloud providers while still meeting Bank Indonesia requirements. Validation through a pilot study with SMEs demonstrated lower compliance costs compared to traditional approaches, achieved through open source tools and hybrid cloud deployments. The combination of IT audit guidelines and solution architecture impacted the results of the IT audit, with only a few findings identified by the external auditor and PT XYZ passing the IT audit. This suggests that the conclusions drawn from the results and discussion indicate that this framework has a significant impact on PSPs, particularly at the SME level. The novelty of this research contributes to practical implementation guidelines for SMEs and the design of cloud-based solution architectures that meet Bank Indonesia requirements.
A structured process model to optimize detection capabilities in security operations centers (SOCs) Adi Nugroho; Charles Lim; Heru Purnomo Ipung
Indonesian Journal of Electrical Engineering and Computer Science Vol 42, No 2: May 2026
Publisher : Institute of Advanced Engineering and Science

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.11591/ijeecs.v42.i2.pp518-530

Abstract

The security operations center (SOC) is essential for protecting organizational assets and maintaining operational continuity against rapidly changing cyber threats. Despite its significance, numerous SOCs establish detection capabilities lacking of a systematic framework, frequently culminating in inefficiencies and constrained efficacy. This paper presents a process model aimed at improving SOC detection capabilities by aligning them with business objectives, pertinent risks, and the evolving character of contemporary threats. The study includes an evaluation of current detection methodologies, utilizing the MITRE ATT&CK architecture and threat intelligence data to pinpoint relevant risks and detection deficiencies. A case study was performed at the XYZ Organization to evaluate current detection capabilities and implement the recommended process model. The model was validated through interviews with experts in the SOC field, verifying the findings' credibility. The findings demonstrate that the model efficiently helps SOC in synchronizing detection methods with organizational objectives, prioritizing pertinent threats, and promoting the enhancement of more targeted and adaptable detection capabilities. This research provides theoretical insights into SOC detection modeling and practical assistance for enterprises aiming to enhance their cybersecurity operations.
Integrating LLM Chatbot in HR Business Process of Small it Enterprise Adrian Siaril; Heru Purnomo Ipung; Tanika D. Sofianti
Eduvest - Journal of Universal Studies Vol. 5 No. 12 (2025): Eduvest - Journal of Universal Studies
Publisher : Green Publisher Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59188/eduvest.v5i12.51876

Abstract

The purpose of this study is to design an LLM-powered chatbot that can assist small businesses in their HR business process, specifically to document knowledge. Employing the Design Science Research (DSR) methodology, the research progresses through problem identification, solution design, artifact development, demonstration, and evaluation phases. The proposed chatbot artifact is evaluated using the Retrieval Augmented Generation Assessment (RAGA) framework for technical performance and the Unified Theory of Acceptance and Use of Technology (UTAUT) for user acceptance. RAGA evaluation demonstrates strong performance, with average scores of 0.95 for context recall, 0.98 for response relevancy, and 1.00 for faithfulness, indicating the chatbot successfully maintains conversational focus and adheres to design specifications. UTAUT results reveal positive user acceptance, particularly in effort expectancy (average 3.30) and facilitating conditions (average 4.08), though employees continue preferring human interaction for complex knowledge-sharing tasks. This study uniquely contributes by developing the first LLM-based chatbot specifically designed for knowledge documentation in small IT enterprise HR contexts, combining technical rigor with practical implementation insights. The artifact design can be replicated and enhanced by future researchers exploring LLM applications in organizational knowledge management, with implications for democratizing advanced knowledge management capabilities in resource-constrained environments.