AUDIT KEAMANAN SISTEM PENGELOLAAN DATA DI DINAS KEPENDUDUKAN DAN PENCATATAN SIPIL BENGKULU UTARA MENGGUNAKAN FRAMEWORK NIST (National Institute Of Standard and Technology)
DOI:
https://doi.org/10.23969/jp.v11i02.50612Keywords:
Cybersecurity, Population Data, NIST CSF 2.0, Security Audit, Public ServiceAbstract
This study aims to analyze the security level of the population data management system at the Department of Population and Civil Registration of North Bengkulu Regency using the NIST Cybersecurity Framework 2.0. This study employed a descriptive quantitative approach with 44 respondents selected through purposive sampling. Data were collected using a closed-ended questionnaire consisting of 25 items based on six NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, and Recover. The data were analyzed using descriptive statistics by calculating the average score and percentage of each function, then classifying the results into Implementation Tiers. The results show that all functions are in the Repeatable category. The Protect function obtained the highest score of 3.2 or 64%, followed by Govern at 3.1 or 62%, Identify at 3.0 or 60%, Detect at 2.8 or 56%, Respond at 2.7 or 54%, and Recover at 2.6 or 52%. These findings indicate that technical protection, system maintenance, database security, and basic governance have been implemented consistently. However, detection, incident response, and recovery functions remain less optimal. Therefore, the Department of Population and Civil Registration of North Bengkulu Regency needs to strengthen detection procedures, incident response mechanisms, disaster recovery planning, and employee capacity to ensure more secure, reliable, and sustainable protection of population data.
Downloads
References
Fadila, V., Mutiah, N., & Sari, R. P. (2023). Audit keamanan siber menggunakan kerangka kerja CIS CSC, NIST CSF, dan COBIT 2019. Journal of Computing Engineering, System and Science, 8(2), 271–283. https://doi.org/10.24114/cess.v8i2.43257
Gimnastiar, R., & Nursyanti, R. (2024). Audit keamanan dan manajemen risiko dengan menggunakan framework NIST (Studi kasus: E-Learning UNIBI). Seminar Nasional. https://corisindo.utb-univ.ac.id/index.php/penelitian/article/view/61
Hamzah, M. R. (2018). Audit keamanan sistem informasi dengan menggunakan standar ISO/IEC 27002:2013 dan ISO/IEC 27001:2013 pada Sub Bagian Data dan Informasi Direktorat Jenderal Kebudayaan Republik Indonesia [Skripsi, UIN Syarif Hidayatullah Jakarta]. UIN Repository. https://repository.uinjkt.ac.id/dspace/handle/123456789/68155
Handoyo, A., & Nigrum, R. (2024). Implementasi NIST CSF untuk penilaian risiko keamanan siber di perguruan tinggi. Jurnal Sistem Informasi dan Teknologi, 14(1), 88–102. https://doi.org/10.37859/coscitech.v4i3.5628
Indrajit, R. E. (2016). Konsep dan strategi electronic government. Preinexus.
Jogiyanto, H. M. (2018). Konsep dasar sistem dan informasi: Sistem informasi manajemen (Edisi 3). Yayasan Cendikia Mulia Mandiri.
Moore, T. (2024). The NIST cybersecurity framework 2.0. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29
Muthi’atur Rofi’ah, D. (2025). NIST cybersecurity framework in the lens of Indonesian internal auditors. Indonesian Interdisciplinary Journal of Sharia Economics, 8(2), 3349–3367. https://doi.org/10.31538/iijse.v8i2.6027
Ndraha, T. (2003). Kybernologi: Ilmu pemerintahan. Rineka Cipta.
Peraturan Bupati Bengkulu Utara Nomor 31 Tahun 2023 tentang Arsitektur Sistem Pemerintahan Berbasis Elektronik (SPBE).
Peraturan Menteri Dalam Negeri Nomor 72 Tahun 2022 tentang Standar dan Spesifikasi Perangkat Keras, Perangkat Lunak, dan Identitas Kependudukan Digital.
Peraturan Menteri Dalam Negeri Nomor 102 Tahun 2019 tentang Pemberian Hak Akses dan Pemanfaatan Data Kependudukan.
Peraturan Menteri Komunikasi dan Informatika Nomor 16 Tahun 2022 tentang Kebijakan Umum Penyelenggaraan Audit Teknologi Informasi dan Komunikasi.
Peraturan Presiden Nomor 95 Tahun 2018 tentang Sistem Pemerintahan Berbasis Elektronik.
Peraturan Presiden Nomor 82 Tahun 2022 tentang Percepatan Transformasi Digital dan Penyelenggaraan Sistem Pemerintahan Berbasis Elektronik.
Rahman, R., Ananta, A., & Surianti, B. (2025). Analisis perbandingan framework keamanan jaringan (NIST CSF, CIS Controls, ISO 27001). Technology Sciences Insights Journal, 12(3), 45–60. https://doi.org/10.60036/z05cpv06
Raimondo, G. M. (2024). NIST cybersecurity framework 2.0: Small business quick-start guide. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.1300
Ross, R., & Pillitteri, V. (2024). NIST cybersecurity framework 2.0: Managing risk in the digital era. National Institute of Standards and Technology.
Saputra Rambe, A., & Oktalisa, E. (2021). Inovasi dalam pelayanan publik: Studi kasus implementasi e-government di negara-negara berkembang. Sengkuni Journal: Social Sciences and Humanities, 2(2), 165–170. https://doi.org/10.37638/sengkuni.2.2.165-170
Stallings, W. (2022). Effective cybersecurity: A guide to using best practices and standards. Addison-Wesley.
Tipton, H. F., & Krause, M. (2022). Information security management handbook (Edisi 7). CRC Press.
Undang-Undang Nomor 11 Tahun 2008 tentang Informasi dan Transaksi Elektronik.
Undang-Undang Nomor 24 Tahun 2013 tentang Administrasi Kependudukan.
Undang-Undang Nomor 27 Tahun 2022 tentang Perlindungan Data Pribadi.
Von Solms, R., & Van Niekerk, J. (2021). Information security governance. Springer.
Whitman, M. E., & Mattord, H. J. (2023). Principles of information security (Edisi 7). Cengage Learning.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Pendas : Jurnal Ilmiah Pendidikan Dasar

This work is licensed under a Creative Commons Attribution 4.0 International License.