ISO 27001: An ISMS Implementation Guide for Regulated Industries in Indonesia
ISO 27001 implementation in Indonesia has shifted from "nice-to-have" to an urgent business necessity. With the Personal Data Protection Law (UU PDP) in force and OJK's cybersecurity regulation for financial services tightening, ISO 27001:2022 certification has become the internationally recognised foundation of information security credibility. The road to certification is demanding, though — many Indonesian organisations fail or stall through the wrong approach, an inadequate gap assessment, and too little understanding of how to align an ISMS with local regulation.
This article works clause by clause through implementing ISO 27001:2022, covering Annex A controls, gap assessment methodology, alignment with the POJK cybersecurity regulation, a realistic certification timeline, and the common mistakes we see across Indonesian implementations.
ISO 27001:2022 — What Changed?
ISO 27001:2022 is the latest revision of the Information Security Management System (ISMS) standard, superseding the 2013 version. The main change is not in the clause requirements (clauses 4-10 remain largely similar) but in the substantially restructured Annex A controls:
- From 114 controls across 14 domains (2013) to 93 controls across 4 themes (2022)
- The 4 new themes: Organizational (37 controls), People (8 controls), Physical (14 controls), Technological (34 controls)
- 11 new controls added, including: Threat Intelligence, Information Security for Cloud Services, ICT Readiness for Business Continuity, Physical Security Monitoring, Configuration Management, Information Deletion, Data Masking, Data Leakage Prevention, Monitoring Activities, Web Filtering, and Secure Coding
- Controls that overlapped in the 2013 version have been consolidated
Organisations certified against the 2013 version must complete transition to 2022 by 31 October 2025. Those starting now should implement the 2022 version directly.
Clause by Clause: What You Need to Prepare
Clause 4: Context of the Organization
The first step, and frequently underestimated. You must document:
- Internal and external issues: Factors affecting the ISMS — from industry regulation (POJK, UU PDP) through to the threat landscape specific to Indonesia
- Interested parties: Who are the ISMS stakeholders and what do they expect? For a bank: customers, OJK, Bank Indonesia, auditors, shareholders, vendors
- Scope: The ISMS boundary — a strategic decision. Too broad and effort and cost balloon. Too narrow and the certification carries little value. Many Indonesian organisations start with IT and the data centre, then expand in stages.
A lesson from the field: A regional bank in Indonesia initially defined its ISMS scope as the whole organisation including 120 branches. After 6 months with no meaningful progress, overwhelmed by the complexity, the scope was narrowed to head office and the data centre. Certification followed within 10 months, and the scope was then extended in stages to regional offices. That phased approach is far more effective than a big bang.
Clause 5: Leadership
Top management must demonstrate genuine commitment, not merely sign a policy. That means:
- An information security policy: A high-level document stating the organisation's commitment to information security
- Roles and responsibilities: Appointing a CISO or Information Security Manager and establishing an Information Security Committee
- Resource commitment: Budget, people, and time allocated to the ISMS
Clause 6: Planning
This clause covers risk assessment and risk treatment — the heart of an ISMS. The process to run:
- Risk assessment methodology: Choose an appropriate approach — qualitative (high/medium/low), quantitative (monetary value), or hybrid. For most Indonesian organisations, a qualitative approach on a 5-point scale is sufficient.
- Asset identification: Identify information assets — data, software, hardware, people, facilities. Every asset needs an accountable owner.
- Threat and vulnerability assessment: Identify threats (hackers, insider threat, natural disaster, ransomware) and vulnerabilities (unpatched systems, weak passwords, no encryption).
- Risk evaluation: Calculate risk level as likelihood x impact. Prioritise risks exceeding the organisation's risk appetite.
- Risk treatment plan: For every unacceptable risk, choose a treatment: mitigate (implement a control), transfer (insurance), avoid (eliminate the activity), or accept (with management approval).
- Statement of Applicability (SoA): A document listing all 93 Annex A controls, stating which are applicable and which are not, with justification for each.
This risk assessment material goes deeper in the CSPM Tools & Framework and Compliance Mapping (PBI/POJK) modules of the Cloud Security Posture Management course.
Clause 7: Support
- Resources: Adequate budget, tools, and personnel
- Competence: Training and certification for the information security team — this is where the ISO 27001 Lead Implementer course becomes a critical investment
- Awareness: A security awareness programme covering all employees
- Communication: An internal and external communication plan for the ISMS
- Documented information: An adequate documentation system — policies, procedures, records, evidence
Clause 8: Operation
Executing what Clause 6 planned. This covers:
- Implementing the risk treatment plan
- Operating the controls set out in the Statement of Applicability
- Operational procedures for each control
- Change management for anything affecting the ISMS
Clause 9: Performance Evaluation
- Monitoring and measurement: ISMS KPIs — the number of security incidents, time to patch, awareness training completion rate, audit findings closed
- Internal audit: An ISMS audit at least annually, by an auditor independent of the area being audited
- Management review: Top management reviews ISMS effectiveness at least annually, against an agenda prescribed by the standard
Clause 10: Improvement
- Nonconformity and corrective action: The process for handling audit findings and security incidents
- Continual improvement: An ISMS is not a project with an end date — it is a continual improvement process (the PDCA cycle)
Annex A Controls: Priorities for Indonesian Industry
Not all 93 controls carry equal weight for an Indonesian organisation. From implementation experience, these are the most critical and the most frequent audit findings:
Controls That Frequently Show Gaps
- A.5.1 Policies for Information Security: Many organisations have policies but never review or update them. Auditors always check the last review date.
- A.5.23 Information Security for Cloud Services: New in 2022. As more Indonesian organisations migrate to cloud, this becomes critical. The Cloud Security Fundamentals module covers the groundwork for it.
- A.5.30 ICT Readiness for Business Continuity: A new control requiring a tested ICT continuity plan — not a DR plan on paper, but one that has been through testing.
- A.6.3 Information Security Awareness, Education, and Training: A documented, measurable awareness programme, delivered periodically.
- A.8.8 Management of Technical Vulnerabilities: A documented patch management process executed on time — an area where many Indonesian organisations remain weak.
- A.8.12 Data Leakage Prevention: New in 2022, requiring mechanisms to prevent data leakage.
- A.8.28 Secure Coding: New, for organisations that develop software. Requires documented secure coding practices.
Aligning with the POJK Cybersecurity Regulation
For Indonesian financial services, ISO 27001 implementation does not stand alone — it must align with OJK regulation. The POJK Cybersecurity for Financial Institutions course covers that alignment in detail.
POJK No. 11/POJK.03/2022 on the provision of information technology by commercial banks imposes several requirements overlapping with ISO 27001:
- IT risk management: Overlaps with ISO 27001 Clause 6 (risk assessment and treatment)
- Cybersecurity: Overlaps with the Annex A controls under the Technological theme
- Business continuity plan: Overlaps with A.5.30 ICT Readiness for Business Continuity
- Incident reporting: The POJK requires incidents to be reported to OJK within a set timeframe — this has to be built into the ISMS incident response procedure
- Self-assessment: Banks must conduct IT security self-assessments and report to OJK periodically
The efficient approach is building one information security framework satisfying both ISO 27001 and the POJK, rather than two separate systems. Mapping Annex A controls to POJK requirements ensures no duplicated effort. The Compliance Mapping (PBI/POJK) module covers that mapping technique practically.
Gap Assessment: The Methodology
Before implementation begins, a gap assessment establishes a clear baseline of where the organisation stands. Here is the methodology we recommend:
Phase 1: Document Review (Weeks 1-2)
Review all existing information security documentation: policies, procedures, standards, guidelines, the risk register, incident reports, and prior audit reports.
Phase 2: Interview and Observation (Weeks 3-4)
Interview key personnel in every in-scope department. Observe operations directly — are the documented procedures actually followed?
Phase 3: Technical Assessment (Weeks 5-6)
Vulnerability assessment, configuration review, access control review, log analysis. The Misconfiguration Detection & Remediation module provides a framework for this, particularly for cloud infrastructure.
Phase 4: Gap Analysis and Roadmap (Weeks 7-8)
Map the findings to ISO 27001 clauses and Annex A controls. Rate each gap by severity and effort to close. The output: a prioritised roadmap with an implementation timeline.
An insight: During a gap assessment at an Indonesian insurer, we found that 70% of the required documentation already existed but was scattered across departments with no central management. The largest effort was not writing new documents but consolidating, updating, and connecting the existing ones into a coherent ISMS framework. This is very common in Indonesian organisations — the documents exist, but the ISMS as a "system" has not yet formed.
The Certification Process and Cost Estimates
Certification Timeline
A realistic timeline from zero to certification for a medium-sized Indonesian organisation:
- Gap assessment: 1-2 months
- ISMS design and documentation: 2-3 months
- Implementation: 3-4 months
- Internal audit: 1 month
- Management review and corrective actions: 1 month
- Stage 1 audit (documentation review): 1-2 weeks
- Closing out Stage 1 findings: 1-2 months
- Stage 2 audit (implementation audit): 1-2 weeks
- Closing out Stage 2 findings: 1-2 months
Total: 12-18 months from kick-off to certification, assuming a dedicated team and management commitment.
Cost Estimates
ISO 27001 certification costs in Indonesia vary with scope, organisation size, and certification body:
- Implementation consultant: IDR 150-500 million (depending on scope and complexity)
- Certification body audit fee: IDR 80-200 million (Stage 1 + Stage 2)
- Surveillance audit (annual): IDR 40-100 million a year
- Recertification (every 3 years): IDR 60-150 million
- Tools and infrastructure: IDR 50-200 million (GRC platform, vulnerability scanner, SIEM, and so on)
- Training: IDR 30-80 million (Lead Implementer, Lead Auditor, awareness programme)
Total first-year investment runs IDR 400 million to 1.2 billion, depending on starting point and scope ambition.
Common Implementation Mistakes in Indonesia
- "Buying" certification without internalising it: Relying on a consultant for all documentation with no knowledge transfer to the internal team. The result: certification achieved, but the ISMS never becomes operational. At surveillance audit, nonconformities pile up.
- A superficial risk assessment: Using a risk register template without genuinely understanding the organisation's threat landscape. An experienced auditor spots a template-based risk assessment against a genuine one immediately.
- An unrealistic scope: Attempting to certify the entire organisation at once. Better to start small, prove the value, then expand.
- Neglecting people controls: Over-focusing on technology controls while ignoring awareness, training, and cultural change.
- Documentation without implementation: Neatly written procedures that nobody follows. This is the most common nonconformity found at Stage 2 audit.
- No continuous monitoring: Controls implemented at the outset with no ongoing monitoring process. The Continuous Monitoring & Reporting module covers building monitoring that is sustainable.
What Our Courses Cover
For a successful ISO 27001 implementation, we recommend two complementary courses:
1. ISO 27001 Lead Implementer — The primary course for leading an ISMS implementation project. Covers interpreting each clause, risk assessment technique, writing the SoA, audit preparation, and ISMS project management.
2. Cloud Security Posture Management for Regulated Industries — For the increasingly critical technical side of cloud security. Its modules:
- Cloud Security Fundamentals: The shared responsibility model, cloud-specific threats, and security architecture for AWS/Azure/GCP.
- CSPM Tools & Framework: Tools and frameworks for continuous posture assessment — making sure cloud configuration complies with ISO 27001 Annex A controls.
- Compliance Mapping (PBI/POJK): Mapping between ISO 27001, the POJK cybersecurity regulation, and cloud security controls. Building one unified compliance framework.
- Misconfiguration Detection & Remediation: Finding and fixing the misconfigurations that are the largest attack vector in cloud environments.
- Continuous Monitoring & Reporting: Dashboards, alerting, and reporting for monitoring the ISMS continuously — not only in the run-up to an audit.
Related Courses
- Cybersecurity for Compliance Officers — For compliance teams needing to understand the technical side of information security
- Cybersecurity per BSSN Standards — Alignment with the national cybersecurity standard from BSSN
- POJK Cybersecurity for Financial Institutions — A deep dive into OJK's regulatory requirements for financial services
FAQ: ISO 27001 Implementation in Indonesia
Is ISO 27001 certification mandated by Indonesian regulation?
ISO 27001 certification is not explicitly mandated by general regulation. However, the POJK on information technology provision by commercial banks requires adequate information security standards to be applied — and ISO 27001 is the most widely accepted evidence of that compliance. Some government and large corporate tenders already require ISO 27001 certification from their vendors. In practice, certification is increasingly "required" even where it is not yet "mandatory".
How long does ISO 27001 certification remain valid?
Certification is valid for 3 years, subject to an annual surveillance audit. Surveillance audits confirm the ISMS is still operating and improving. After 3 years, a recertification audit follows — more comprehensive than surveillance but not as extensive as the initial certification. Many organisations lose certification by neglecting surveillance audits or failing to pursue continual improvement.
Can we implement it ourselves without a consultant?
In theory yes, but it depends heavily on internal capability. An organisation with ISO 27001 Lead Implementer certified staff and implementation experience can run it alone. For most Indonesian organisations implementing for the first time, the most effective approach combines an external consultant (for guidance and gap assessment) with a trained internal team (for execution and sustainability). Investing in training your own team pays back far more over the long run than depending entirely on a consultant.
Which certification body do you recommend in Indonesia?
Choose a certification body accredited by a recognised accreditation authority — in Indonesia the National Accreditation Committee (KAN), or international bodies such as UKAS (UK), ANAB (US), or JAS-ANZ (Australia/NZ). Well-known certification bodies operating in Indonesia include BSI, SGS, Bureau Veritas, TUV, and DNV. What matters most is valid accreditation — a certificate from an unaccredited body carries no international recognition.
How do you align ISO 27001 with the PDP Law?
ISO 27001 provides a solid framework covering most PDP Law requirements on data security. Annex A controls such as data classification, access control, cryptography, and data leakage prevention support personal data protection directly. The PDP Law does add requirements ISO 27001 does not cover, however: consent management, data subject rights (access, correction, deletion), and the Data Protection Officer role. The best approach is building the ISMS on ISO 27001 and layering the PDP-specific requirements on top.