Tinjauan Literatur Keamanan Siber pada Infrastruktur Kritis di Indonesia
Keywords:
Keamanan Siber, Infrastruktur Kritis Nasional, Manajemen Risiko Siber, Tata Kelola Siber, Resiliensi SiberAbstract
Infrastruktur kritis nasional, seperti sektor energi, telekomunikasi, transportasi, perbankan, kesehatan, dan layanan pemerintahan, semakin bergantung pada sistem siber-fisik yang saling terhubung melalui jaringan digital. Ketergantungan tersebut memberikan manfaat berupa peningkatan efisiensi operasional, namun di sisi lain memperluas attack surface sehingga meningkatkan risiko terhadap berbagai ancaman siber, seperti ransomware, serangan distributed denial-of-service (DDoS), pencurian data, hingga sabotase terhadap layanan publik. Oleh karena itu, keamanan siber menjadi isu strategis yang berperan penting dalam menjaga keberlangsungan operasional infrastruktur kritis dan stabilitas nasional. Artikel ini bertujuan menyajikan tinjauan literatur sistematis mengenai kondisi terkini, tantangan, kebijakan, serta strategi penguatan keamanan siber pada infrastruktur kritis di Indonesia tanpa melibatkan pengumpulan data primer. Metode penelitian yang digunakan adalah studi pustaka terhadap publikasi ilmiah nasional dan internasional, laporan resmi Badan Siber dan Sandi Negara (BSSN), Kementerian Komunikasi dan Digital, serta berbagai standar internasional, seperti NIST Cybersecurity Framework, ISO/IEC 27001, dan ENISA, yang diterbitkan dalam kurun waktu sepuluh tahun terakhir. Hasil kajian menunjukkan bahwa meskipun Indonesia telah memiliki landasan regulasi, termasuk Peraturan Presiden Nomor 82 Tahun 2022 tentang Pelindungan Infrastruktur Informasi Vital, implementasinya masih menghadapi berbagai tantangan, antara lain tata kelola lintas sektor yang belum terintegrasi secara optimal, keterbatasan sumber daya manusia yang memiliki kompetensi dan sertifikasi keamanan siber, rendahnya tingkat kematangan manajemen risiko siber pada sebagian operator infrastruktur kritis, serta belum optimalnya mekanisme pertukaran informasi ancaman secara real-time. Perbandingan dengan praktik terbaik di Jepang menunjukkan bahwa keberadaan lembaga koordinasi nasional yang kuat, kewajiban pelaporan insiden, pelaksanaan simulasi keamanan secara berkala, serta kolaborasi yang erat antara pemerintah dan sektor swasta mampu meningkatkan efektivitas respons terhadap insiden siber. Berdasarkan hasil tinjauan tersebut, artikel ini menyimpulkan bahwa penguatan tata kelola keamanan siber nasional, harmonisasi regulasi, peningkatan kapasitas sumber daya manusia, pengembangan mekanisme berbagi informasi ancaman, serta penerapan kerangka manajemen risiko berbasis standar internasional merupakan langkah strategis untuk meningkatkan resiliensi infrastruktur kritis Indonesia dalam menghadapi ancaman siber yang semakin kompleks di masa depan.
References
Abdallah, W. M., Mahmoud, M. M., & Shen, X. (2022). Cybersecurity for critical infrastructures: A survey of emerging threats and defense mechanisms. IEEE Access, 10, 134924–134951.
Agyepong, E., Addo, A., & Boateng, R. (2024). Cyber supply chain risk management in critical infrastructure: A systematic literature review. Journal of Information Security and Applications.
Ahmad, T., Alsmadi, I., & Alzahrani, A. (2022). Cybersecurity threats and critical infrastructure protection: A systematic review. Computers & Security, 121, 102883. https://doi.org/10.1016/j.cose.2022.102883
Ahmad, T., Alsmadi, I., & Alzahrani, A. (2023). Cybersecurity challenges and protection strategies for critical infrastructure: A review. Journal of Network and Computer Applications, 223, 103787. https://doi.org/10.1016/j.jnca.2023.103787
Alcaraz, C., & Lopez, J. (2021). Critical infrastructure protection: Requirements and challenges for the 21st century. Computer Standards & Interfaces, 77, 103545. https://doi.org/10.1016/j.csi.2021.103545
Alcaraz, C., Fernández-Gago, C., & Lopez, J. (2023). Cyber risk management in critical infrastructures: Challenges and future research directions. Computers & Security.
Alfath, T. P., & Cahya, W. (2024). Bridging the gap between policy and practice: Evaluating Indonesia's cybersecurity regulatory framework (2020–2023). Data: Journal of Information Systems and Management, 2(1), 14–24. https://doi.org/10.61978/data.v2i1.695
Alshamrani, A., Myneni, S., Chowdhary, A., & Huang, D. (2023). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials, 25(1), 680–713.
Alshamrani, A., Myneni, S., Chowdhary, A., & Huang, D. (2023). A survey on advanced persistent threats: Techniques, solutions, challenges, and research opportunities. IEEE Communications Surveys & Tutorials.
Alzahrani, A., Alqahtani, F., & Alharbi, S. (2024). Cybersecurity workforce challenges and competency development for critical infrastructure protection. IEEE Access.
Ardebili, A. A., Lezzi, M., & Pourmadadkar, M. (2024). Risk assessment for cyber resilience of critical infrastructures: Methods, governance, and standards. Applied Sciences, 14(24), 11807.
Bada, A., Nurse, J. R. C., & Goldsmith, M. (2023). Cybersecurity governance for critical national infrastructure: Challenges and opportunities. Government Information Quarterly.
Boyes, H., Hallaq, B., Cunningham, J., & Watson, T. (2022). The industrial internet of things, cybersecurity and supply chain resilience. Sensors.
Fuady, A., Hasibuan, F. Y., & Kotto, Z. (2025). Strengthening cybersecurity and data protection legal framework in Indonesia: A normative analysis of current challenges and future directions. Law and Justice Research Journal, 1(3), 15–27. https://doi.org/10.70062/ljrj.v1i3.87
Gunawan, A., & Aji, R. F. (2023). Cybersecurity improvement design in critical infrastructure PT XYZ case study. The Indonesian Journal of Computer Science, 12(6).
Humayed, A., Lin, J., Li, F., & Luo, B. (2017). Cyber-physical systems security—A survey. IEEE Internet of Things Journal, 4(6), 1802–1831. https://doi.org/10.1109/JIOT.2017.2703172
Khalid, A., Javaid, N., Almogren, A., & Javed, M. U. (2023). Cybersecurity for critical infrastructure: Challenges and future directions. Journal of Network and Computer Applications, 220, 103728. https://doi.org/10.1016/j.jnca.2023.103728
Khan, M. A., Salah, K., Jayaraman, R., Omar, M., & Ellahham, S. (2024). Cybersecurity challenges and resilience for critical infrastructure: A comprehensive review. Journal of Information Security and Applications, 81, 103730.
Kim, D., & Kim, S. (2021). Reframing South Korea's national cybersecurity governance system in critical information infrastructure. The Korean Journal of Defense Analysis, 33(4), 689–713.
Krishnan, R., et al. (2021). Cascading effects of cyber-attacks on interconnected critical infrastructure. Cybersecurity, 4(8).
Kurniawan, A., & Sfenrianto. (2023). Cybersecurity readiness assessment in Indonesian public sector organizations. International Journal of Advanced Computer Science and Applications.
Linnenluecke, M. K., Marrone, M., & Singh, A. K. (2020). Conducting systematic literature reviews and bibliometric analyses. Australian Journal of Management, 45(2), 175–194. https://doi.org/10.1177/0312896219877678
Maglaras, L., Kantzavelou, I., & Ferrag, M. A. (2021). Digital transformation and cybersecurity of critical infrastructures. Applied Sciences, 11(18), 8357.
Mahmood, Z., Javaid, N., & Almogren, A. (2022). Security challenges in IT/OT convergence for industrial cyber-physical systems: A review. Sensors, 22(18), 6942. https://doi.org/10.3390/s22186942
Nazir, S., Patel, S., & Patel, D. (2017). Assessing and augmenting SCADA cyber security: A survey of techniques. Computers & Security, 70, 436–454. https://doi.org/10.1016/j.cose.2017.06.010
Paul, J., & Criado, A. R. (2020). The art of writing literature review: What do we know and what do we need to know? International Business Review, 29(4), 101717. https://doi.org/10.1016/j.ibusrev.2020.101717
Radanliev, P., De Roure, D., Burnap, P., Van Kleek, M., Santos, O., Ani, U., & Montalvo, R. M. (2021). Future developments in cyber risk assessment for the Internet of Things and critical infrastructures. Computers in Industry, 128, 103404.
Roshanaei, M. (2021). Resilience at the core: Critical infrastructure protection challenges, priorities, and cybersecurity assessment strategies. Journal of Computer and Communications, 9(8).
Sensuse, D. I., Putro, P. A. W., Rachmawati, R., & Sunindyo, W. D. (2022). Initial cybersecurity framework in the new capital city of Indonesia: Factors, objectives, and technology. Information, 13(12), 580.
Sharma, P., Singh, R., & Kim, T. (2024). Cyber resilience in critical infrastructure: Emerging threats and mitigation strategies. Computers & Security, 139, 103687. https://doi.org/10.1016/j.cose.2024.103687
Sithole, E., & Louw, L. (2021). Cybersecurity capabilities for critical infrastructure resilience. Information and Computer Security, 30(2), 255–279.
Snyder, H. (2019). Literature review as a research methodology: An overview and guidelines. Journal of Business Research, 104, 333–339. https://doi.org/10.1016/j.jbusres.2019.07.039
Xiao, Y., & Watson, M. (2021). Guidance on conducting a systematic literature review. Journal of Planning Education and Research, 41(1), 93–112.
Yaqoob, I., Salah, K., Jayaraman, R., & Al-Hammadi, Y. (2022). Blockchain for healthcare data management: Opportunities, challenges, and future recommendations. Neural Computing and Applications, 34(14), 11475–11490.





