Four hooks matter in Indonesia: PP 71/2019 on electronic systems, PSE registration with Kominfo, BSSN technical standards — whose security assessments include ISO/IEC 27001 readiness checks — and the UU PDP (Law 27/2022) with its 72-hour breach notification. None of them is answered by a policy folder. An ISO 27001 ISMS is the one structure that evidences all four.
If you operate an electronic system serving Indonesian users, four instruments shape what’s expected of you. Each asks a different question, and a security questionnaire from a regulator or enterprise customer will usually touch all four.
| Instrument | What it is | What it asks of you |
|---|---|---|
| PP 71/2019 | Government Regulation on Electronic Systems and Transactions | Operate your electronic system securely and reliably — the umbrella the rest hangs from |
| PSE registration | Registration of Electronic System Operators with Kominfo | Register with the Ministry of Communication and Informatics |
| BSSN technical standards | The National Cyber and Crypto Agency sets technical standards and runs security assessments | Meet the standards — and note that BSSN’s assessments include ISO/IEC 27001 readiness checks |
| UU PDP (Law 27/2022) | Indonesia’s personal data protection law | Ensure the confidentiality, integrity and availability of personal data; notify authorities and affected users within 72 hours of a breach |
PP 71/2019 is the starting point. It governs electronic systems and transactions, and PSE registration with Kominfo sits under it. Registration matters — unregistered operators are the ones regulators go looking for — but it’s paperwork, not security. It tells the state who you are, not whether your systems would survive contact with an attacker.
BSSN is where the security substance lives. The agency sets the technical standards and runs the security assessments, and those assessments include ISO/IEC 27001 readiness checks. That’s the clearest signal in the whole stack: the body assessing your security measures it against the shape of ISO 27001. Preparing for BSSN and preparing for certification are largely the same work.
The UU PDP raises the operational bar. Ensuring confidentiality, integrity and availability of personal data is a continuous duty, and the 72-hour notification window is short. You can’t notify within 72 hours of a breach you took three weeks to detect — the clock makes detection, not documentation, the real requirement.
The mapping is unusually clean, because the UU PDP’s core duty — confidentiality, integrity, availability — is the same triad ISO 27001 defines information security by. You’re not translating between two languages; it’s the same sentence.
| Indonesian obligation | Where the ISMS answers it |
|---|---|
| Secure and reliable operation (PP 71/2019) | Risk assessment across all 93 Annex A controls, with applicability documented in the Statement of Applicability |
| BSSN standards and security assessments | The ISMS is what a readiness check reads: policies, operating controls, internal audit results, evidence that it all actually runs |
| Confidentiality, integrity and availability of personal data (UU PDP) | The stated objective of the ISMS — access control, supplier controls, and the technological controls protecting the data itself |
| 72-hour breach notification (UU PDP) | Incident management with detection in front of it: logging and monitoring running continuously, an assessment step, and a notification decision that fits inside the window |
Two honest caveats. Registration is administrative — an ISMS doesn’t register you with Kominfo, it just means that when the regulator looks past the registration, there’s something real behind it. And certification isn’t a legal safe harbour: the ISMS has to carry the Indonesian instruments as recorded legal requirements, so the risk assessment and controls are built against them, not just against the standard.
The certification audit — Stage 1 documentation review, then Stage 2 interviews and evidence — is performed by an accredited certification body, never by Secure60. Audit fees are set by the certification body and vary with the size and scope of what’s being certified, so get the scope right before you get quotes.
If your Indonesian operation is part of a wider group, you don’t need a standalone certificate: one ISMS can carry Indonesian sites inside a multi-country scope, which is usually cheaper to run and easier to keep consistent. And where data lives is a separate question from where you’re certified — Indonesian customers and regulators may care a great deal about the former, and your ISMS needs a written answer. Secure60 runs delivery infrastructure in-country via Rackcorp, with 2 datacentres in Indonesia, so collection and monitoring can stay onshore where that’s the expectation.
The 72-hour clock gets treated as a paragraph in the incident-response policy. Teams build the ISMS for the certificate, write “notify within 72 hours” in a document, and consider the UU PDP handled.
The window is an engineering constraint, not a policy sentence. Seventy-two hours has to fit detection, triage, an assessment of what data was touched, and notification of both the authorities and the affected users. If nothing is watching your logs, the clock runs out before you know it started. Build the monitoring for the law, and the auditor’s evidence requirements come along for free — not the other way round.
We build the ISMS, implement the controls, and run the security operations behind them — logging, monitoring, vulnerability management — on one security platform, with the evidence trail that both a BSSN readiness check and a Stage 2 auditor want to see. Delivery runs on in-country infrastructure via Rackcorp where residency is expected. The certification audit belongs to an accredited certification body; our job is making sure that when they arrive, everything they sample is actually running. We’re ISO 27001:2022 certified ourselves and operate the same system we build for clients.
Is ISO 27001 legally mandatory in Indonesia?
The regulations set security obligations rather than naming a certificate. But BSSN’s security assessments include ISO/IEC 27001 readiness checks, so the agency measuring you is measuring against the standard’s shape — which makes certification the practical way to arrive prepared.
What is PSE registration?
Under PP 71/2019, Electronic System Operators (PSEs) must register with the Ministry of Communication and Informatics (Kominfo). Registration is administrative — it puts you on the regulator’s map; it doesn’t by itself evidence that your systems are secure.
What does the UU PDP require after a data breach?
Law 27/2022 requires operators to notify the authorities and affected users within 72 hours of a breach. It also requires you to ensure the confidentiality, integrity and availability of personal data day to day — it’s a security law as much as a privacy law.
Who performs the ISO 27001 certification audit in Indonesia?
An accredited certification body — not Secure60. Audit fees are set by the certification body and vary with the size and scope of the system being certified. What we do is build and run the ISMS that the auditor then examines.
Does our data have to stay in Indonesia?
Residency depends on your sector, your regulator and your contracts — it’s a legal question, not something ISO 27001 decides. Your ISMS records where data lives and under whose control; the distinction is covered in our data residency guide.
Can Secure60 deliver in Indonesia?
Yes — we have delivery infrastructure in-country via Rackcorp, with 2 datacentres in Indonesia. Log collection, monitoring and evidence can run on Indonesian infrastructure where that’s expected. We don’t have local offices, and we never perform the certification audit.