Perpres 82/2022 Pelindungan IIV | Protection of vital information infrastructure — electronic systems using information and/or operational technology in strategic sectors, where disruption would seriously affect public interest, public services, defence or the national economy. BSSN coordinates; operators must stand up an organisational cyber incident response team beneath the sectoral and national tiers. | Organisational CSIRT stand-up that functions on a plant schedule, and the assessment that establishes what within your estate is actually in scope. | Operating CSIRT, scoped asset register |
Perpres 47/2023 Presiden RI | National Cyber Security Strategy across eight pillars, with protection of vital information infrastructure and operational resilience among them. | Resilience treated as something exercised rather than documented, with the plant's own people in the exercise. | Tested playbooks, trained responders |
IEC 62443 International | Security for industrial automation and control systems: zone and conduit architecture, and a target Security Level from SL 1 to SL 4 set by the capability of the adversary you must withstand. | Zone and conduit design, target SL agreed per zone, and assessment that does not require putting traffic on a control network to reach a conclusion. | Zone model, per-zone target SL, gap register |
NIST SP 800-82 Guidance | Operational technology security guidance — the reference for method where IEC 62443 sets the architecture. | Method aligned to it, with the safety and availability constraints written into the test plan rather than discovered during it. | Documented method, agreed constraints |
UU PDP Republik Indonesia | Personal data obligations, including notification within 72 hours. Utilities hold customer records at national scale alongside the plant estate. | Governance across both estates, because the customer database and the control network are almost never the same team and the clock does not care. | DPIA records, cross-team runbook |
ISO 27001 Certifiable | Information security management system covering the organisation, increasingly demanded by lenders, offtakers and joint-venture partners. | Assessment and implementation scoped so the OT estate is addressed honestly rather than excluded to make certification easier. | Certifiable ISMS with OT in scope |