ISO 27001 · Indonesia

ISO 27001 Requirements Under Indonesian Regulation

The Short Answer

Four instruments apply in Indonesia: PP 71/2019 on electronic systems, PSE registration with Kominfo, BSSN technical standards — whose security assessments include ISO/IEC 27001 readiness checks — and the UU PDP (Law 27/2022) with its 72-hour breach notification. All four require operating capability rather than documentation, and an ISO 27001 ISMS is the single structure that evidences them.

The four regulatory hooks in Indonesia

Four instruments apply to an electronic system serving Indonesian users. Each asks a different question, and a security questionnaire from a regulator or enterprise customer usually touches all four.

Instrument What it is What it requires
PP 71/2019 Government Regulation on Electronic Systems and Transactions Secure and reliable operation of your electronic system — the umbrella instrument
PSE registration Registration of Electronic System Operators with Kominfo Registration with the Ministry of Communication and Informatics
BSSN technical standards The National Cyber and Crypto Agency sets technical standards and runs security assessments Meeting the standards, with BSSN’s assessments including ISO/IEC 27001 readiness checks
UU PDP (Law 27/2022) Indonesia’s personal data protection law Maintaining confidentiality, integrity and availability of personal data; notifying authorities and affected users within 72 hours of a breach

PP 71/2019 is the starting point. It governs electronic systems and transactions, and PSE registration with Kominfo sits under it. Registration identifies the operator to the state, and unregistered operators are the ones regulators pursue, but registration establishes nothing about the security of the systems.

BSSN carries the security substance. The agency sets the technical standards and runs the security assessments, and those assessments include ISO/IEC 27001 readiness checks — so the body assessing your security measures it against the structure of ISO 27001. Preparing for BSSN and preparing for certification are largely the same work.

The UU PDP sets the operational requirement. Maintaining confidentiality, integrity and availability of personal data is a continuous duty, and the 72-hour notification window is short. Notification within 72 hours is unachievable for a breach detected three weeks after it occurred, which makes detection rather than documentation the binding requirement.

How an ISO 27001 ISMS maps to those obligations

The UU PDP’s core duty — confidentiality, integrity, availability — is the triad ISO 27001 uses to define information security, so the two use the same terms.

Indonesian obligation Where the ISMS answers it
Secure and reliable operation (PP 71/2019) Risk assessment across all 93 Annex A controls, with applicability documented in the Statement of Applicability
BSSN standards and security assessments The ISMS is what a readiness check examines: policies, operating controls, internal audit results, and evidence that all of it runs
Confidentiality, integrity and availability of personal data (UU PDP) The stated objective of the ISMS — access control, supplier controls, and the technological controls protecting the data
72-hour breach notification (UU PDP) Incident management with detection in front of it: continuous logging and monitoring, an assessment step, and a notification decision that fits inside the window

Two limits apply. Registration is administrative, so an ISMS does not register you with Kominfo; it means the regulator finds operating capability behind the registration. And certification is not a legal safe harbour: the ISMS has to carry the Indonesian instruments as recorded legal requirements, so the risk assessment and controls are built against them rather than against the standard alone.

Scope, certification body and residency

The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by an accredited certification body rather than by Secure60. Audit fees are set by the certification body and vary with the size and scope of what is being certified, which makes scope the first decision.

Where the Indonesian operation is part of a wider group, a standalone certificate is not required: one ISMS can carry Indonesian sites inside a multi-country scope, which is generally cheaper to run and easier to keep consistent. Where data resides is a separate question from where you are certified, and Indonesian customers and regulators frequently ask about the former, so the ISMS needs a documented answer. Secure60 runs delivery infrastructure in-country via Rackcorp, with 2 datacentres in Indonesia, so collection and monitoring can stay onshore where that is required.

The 72-hour window is an engineering constraint

Building the ISMS for the certificate, recording a 72-hour notification commitment in a document, and treating the UU PDP as addressed leaves the requirement unmet.

Seventy-two hours has to accommodate detection, triage, an assessment of what data was accessed, and notification of both the authorities and the affected users. Where nothing is monitoring the logs, the window closes before the incident is identified. Monitoring built for the law also produces the auditor’s evidence requirements, and the reverse sequence does not hold.

How Secure60 handles this

We build the ISMS, implement the controls, and run the security operations behind them — logging, monitoring, vulnerability management — on one security platform, with the evidence trail that a BSSN readiness check and a Stage 2 auditor both examine. Delivery runs on in-country infrastructure via Rackcorp where residency is required. The certification audit belongs to an accredited certification body, and our work is making sure everything they sample is operating on arrival. Secure60 holds ISO 27001:2022 certification and operates the same system we build for clients.

Frequently Asked Questions

Is ISO 27001 legally mandatory in Indonesia?

The regulations set security obligations rather than naming a certificate. BSSN’s security assessments include ISO/IEC 27001 readiness checks, so the agency conducting the assessment measures against the standard’s structure, which makes certification the practical route to arriving prepared.

What is PSE registration?

Under PP 71/2019, Electronic System Operators (PSEs) must register with the Ministry of Communication and Informatics (Kominfo). Registration is administrative: it records the operator with the regulator and does not evidence that the systems are secure.

What does the UU PDP require after a data breach?

Law 27/2022 requires operators to notify the authorities and affected users within 72 hours of a breach. It also requires the confidentiality, integrity and availability of personal data to be maintained day to day, which makes it a security law as well as a privacy law.

Who performs the ISO 27001 certification audit in Indonesia?

An accredited certification body, and not Secure60. Audit fees are set by the certification body and vary with the size and scope of the system being certified. We build and run the ISMS that the auditor examines.

Does our data have to stay in Indonesia?

Residency depends on your sector, your regulator and your contracts. It is a legal question rather than one ISO 27001 determines. The ISMS records where data resides and under whose control; the distinction is covered in our data residency guide.

Can Secure60 deliver in Indonesia?

Yes. We have delivery infrastructure in-country via Rackcorp, with 2 datacentres in Indonesia, so log collection, monitoring and evidence can run on Indonesian infrastructure where that is required. We have no local offices, and we do not perform the certification audit.

Indonesian Electronic System Operator Readiness

A readiness call maps PP 71/2019, BSSN expectations and the UU PDP against the environment and sets out what an ISMS engagement covers.

30 days, every feature switched on. No credit card.