Text
Rancang bangun cyber exercise simulasi penanganan insiden siber menggunakan enisa cyber exercise cycle
Abstrak:
Politeknik Siber dan Sandi Negara (Poltek SSN) merupakan lembaga pendidikan yang mempersiapkan calon aparatur sipil negara (ASN) guna memenuhi kebutuhan sumber daya manusia di Badan Siber dan Sandi Negara (BSSN). Fungsi BSSN berdasarkan Peraturan BSSN Nomor 6 tahun 2021 yaitu pengelolaan tanggap insiden siber nasional dan sektor pemerintah, sehingga perlu adanya peningkatan kapabilitas sumber daya manusia menggunakan cyber exercise. Perancangan dan pembangunan cyber exercise dilakukan berdasarkan European Network and Information Security Agency (ENISA) Cyber exercise Cycle sedangkan simulasi penanganan insiden siber akan diberikan berdasarkan NIST 800-61R2. Cyber exercise memanfaatkan laboratorium virtual simulasi penanganan insiden siber Cyberexce dan sistem Monitoring IR-Range, dirancang dan dibangun menggunakan System Development Life Cycle (SDLC) dengan metode waterfall. Skenario cyber exercise dibuat berdasarkan kasus nyata mengimplementasikan problem based-learning dengan penyelesaian berdasarkan proses bisnis BSSN dan NIST 800-61R2 berbentuk simulasi laboratorium dibuat dengan bentuk virtual OVA. Pelaksanaan Cyber exercise dilakukan kepada sampel Taruna Poltek SSN pada tingkat 1 dan 2. Hasil penelitian ini adalah berupa Laboratorium simulasi Cyberexce dan IR-Range yang bekerja sesuai dengan fungsi yang dibutuhkan dalam pemenuhan Cyber exercise dan menganalisa dampak penggunaan laboratorium menggunakan one group pretest-post-test design dan User Acceptance Test untuk menentukan tingkat efektivitas dan tingkat penerimaan terhadap kesuksesan cyber exercise.
Abstract:
Politeknik Siber dan Sandi Negara (Poltek SSN) is an educational institution that prepares prospective civil servant candidates to meet the human resource needs of Badan Siber dan Sandi Negara (BSSN). Based on BSSN Regulation Number 6 of 2021, the role of BSSN encompasses the management of responses to national cyber incidents and the government sector. As a result, enhancing human resource capabilities through cyber exercises is essential. The design and development of these cyber exercises are based on the European Network and Information Security Agency (ENISA) Cyber exercise Cycle, while simulations of cyber incident responses are guided by NIST 800-61R2. Cyber exercises utilize a virtual laboratory setup, including the Cyberexce incident response simulation and the IR-Range Monitoring system. These are designed and constructed using the System Development Life Cycle (SDLC) with a waterfall methodology. The exercise scenarios are drawn from real-world cases, incorporating problem-based learning approaches and solutions aligned with BSSN's operational processes and NIST 800-61R2 standards. These scenarios are presented through a virtual laboratory simulation in the form of an Open Virtual Appliance (OVA). The cyber exercise is conducted with a sample of Poltek SSN cadets at levels 1 and 2. The research outcomes include the Cyberexce simulation laboratory and the IR-Range system, both effectively meeting the requirements of the cyber exercise. Additionally, the study analyzes the impact of laboratory utilization employing a one-group pretest-post-test design and evaluates user acceptance through the User Acceptance Test to determine effectiveness and the level of acceptance of the cyber exercise's success.
No other version available