Media Bina Ilmiah
Vol. 17 No. 10: Mei 2023

THE IMPLEMENTATION OF INFORMATION TECHNOLOGY PRODUCT SECURITY CERTIFICATION POLICY ON THE EFFECTIVENESS OF INFORMATION SECURITY ASSURANCE IN INDONESIA

Ratih Mumpuni Arti (School of Government and Public Policy, Bogor)
Novianto Budi Kurniawan (School of Government and Public Policy, Bogor, West Java, Indonesia)
Astrid Meilasari Sugiyana (School of Government and Public Policy, Bogor, West Java, Indonesia)



Article Info

Publish Date
27 May 2023

Abstract

The information technology product security certification policy in Indonesia is implemented based on BSSN Regulation 15 of 2019 concerning the Indonesian Common Criteria Scheme (SCCI). The products used in data processing should be certified for its security to guarantee information security. However, almost three years since the regulation was implemented, effect on information security has not been achieved. The focus of this study is to analyse the influence of the implementation of information technology product security certification policy on the effectiveness of information security assurance in Indonesia. Policy implementation was analysed using the theory of Edward III. Edward III's policy implementation model consists of 4 variables: communication, resources, disposition, and bureaucratic structure. Effectiveness consists of 3 variables: goal achievement, adaptation, and integration. This study used the mixed-method approach. The findings showed that simultaneously communication, resources, disposition, and bureaucratic structure have a significant effect and very strong correlation on effectiveness. From these results, it can be recommended to develop a policy communication strategy that is more effective in providing information to the public, make a timeframe and concrete target for resources variable, establish communication, coordination, and consensus with the public and private sectors to achieve a willingness and commitment to implement an IT product security certification policy, and set a timeframe and concrete targets regarding the formation of an organization that has the duties, functions and authority of IT product security certification, business processes and organizational implementation procedures.

Copyrights © 2023






Journal Info

Abbrev

MBI

Publisher

Subject

Humanities Social Sciences Other

Description

Media Bina Ilmiah, ISSN 1978-3787 (print) | 2615-3505 (online), diterbitkan 12 (Dua Belas) nomor dalam setahun (Januari-Desember) oleh BINA PATRIA. Jurnal ini merupakan sarana komunikasi dan penyebarluasan informasi hasil-hasil penelitian dan pengembangan, kajian serta pemikiran dalam bidang ...