Designing a Security Profile Using the NIST Cybersecurity Framework for General Elections in Indonesia
DOI: https://doi.org/10.70184/813bar95
Election cybersecurity;, NIST CSF 2.0 e-voting VVPAT;, election information systems; , cyber threats; , electoral governance
Abstract
This study aims to design a comprehensive cybersecurity profile for Indonesia’s electoral digital ecosystem using the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF) 2.0. The research focuses on identifying vulnerabilities in election information systems, formulating mitigation controls, and strengthening the supervisory role of the Election Supervisory Agency (Bawaslu) toward the General Election Commission (KPU). This study employed a qualitative descriptive-diagnostic approach. Data were collected through qualitative observations, historical cyber incident reports, regulations, cybersecurity documents, and academic literature related to election governance and digital security in Indonesia. Data analysis followed five implementation phases of NIST CSF 2.0: prioritize and scope, orient, create current profile, conduct risk assessment, and create target profile. The findings indicate that Indonesia’s election information systems remain vulnerable to data breaches, access control weaknesses, insider threats, infrastructure failures, and disinformation attacks. The study proposes a dual-recording e-voting architecture integrated with Voter Verifiable Paper Audit Trail (VVPAT) to improve transparency, auditability, and election integrity. The findings imply that election cybersecurity governance requires integrated institutional oversight, technical mitigation, and forensic audit mechanisms to maintain democratic legitimacy and public trust
References
Afiansyah, H. G., & Amiruddin, A. (2019). Perancangan Rencana Tata Kelola dan Manajemen Teknologi Informasi Menggunakan COBIT 2019 dan NIST SP 800-53 Rev 5 (Studi Kasus: Instansi Pemerintah ABC). Jurnal Info Kripto, 6(1), 33–39.
Annisa, A. N., Kadaruddin, Yunus, A., Anas, A. M. A., Juniar, M. W., Wahyuni, A. S., Kurniawati, A., & Librayanto, R. (2020). Improving Accessibility of The Right to Persons with Mental Disabilities in General Election. Journal of Critical Reviews, 7(19), 905–909.
Arinze, S. N., & Nwajana, A. O. (2025). RFID-Enabled Electronic Voting Framework for Secure Democratic Processes. Telecom, 6(78), 1–19.
Berenjestanaki, M. H., Barzegar, H. R., Ioini, N. El, & Pahl, C. (2024). Blockchain-Based E-Voting Systems: A Technology Review. Electronics, 13(17), 1–38.
Brady, M., Franklin, J. M., Sames, C., Brady, M., Franklin, J. M., Sames, C., & Snyder, J. (2024). Cybersecurity Framework Election Infrastructure Profile.
Dewan Kehormatan Penyelenggaraan Pemilihan Umum. Putusan Nomor 4-PKE-DKPP/I/2024, (2024).
Dewan Kehormatan Penyelenggaraan Pemilihan Umum. Putusan Nomor 53-PKE-DKPP/III/2024, (2024).
Fitzpatrick, J., & Jöst, P. (2022). “The High Mass of Democracy” — Why Germany Remains Aloof to the Idea of Electronic Voting. Frontiers in Political Science, 4(July), 1–14. https://doi.org/10.3389/fpos.2022.876476
Hastuti, D., Rochman, S., & Aini, R. S. Z. (2024). Cybersecurity Measures For Election Information Systems : Sistem Rekapitulasi Suara Pemilu 2024 (siRekap). Journal of Applied Electrical & Science Technology, 06(01), 20–24.
Kementerian Petahanan Republik Indonesia. Pedoman Pertahanan Siber, (2014).
Kersting, N., & Baldersheim, H. (2004). Electronic Voting and Democracy: A Comparative Analysis.
Khatami, M. I., & Rahayu, R. (2024). Cybersecurity Leadership in Safeguarding Election Voter Data (Case Study: Implementation of the SIDALIH Information System by the Indonesian General Election Commission). Jurnal Komunikasi Indonesia, 13(1), 81–97. https://doi.org/10.7454/jkmi.v13i1.1215
Krivonosova, I., & Iova, R. A. S. (2021). From the Parliament to a Polling Station: How to Make Electoral Laws More Comprehensible to Election Administrators. Election Law Journal, 20(4), 364–381. https://doi.org/10.1089/elj.2020.0670
Mahkamah Konstitusi Republik Indonesia. Putusan Nomor 147/PUU-VII/2009, (2009).
National Institute of Standards and Technology. (2014). Framework for Improving Critical Infrastructure Cybersecurity (Version 1.0). Department of Commerce.
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0.
Norris, P. (2014). Why Mass Perceptions of Electoral Integrity Matter for Legitimacy.
Presiden Republik Indonesia. Undang-Undang Republik Indonesia Nomor 7 Tahun 2017 tentang Pemilihan Umum, (2017).
Republik Indonesia. Undang-Undang Dasar Negara Republik Indonesia Tahun 1945, (1945).
Shackelford, S. J., Raymond, A., Stemler, A., & Loyle, C. (2020). Defending Democracy : Taking Stock of the Global Fight Against Digital Repression, Disinformation, and Election Insecurity. Washington and Lee Law Review, 77(4).
Sumardi. (2024). Penguatan Sistem Pengawasan dalam Penyelenggaran Tahapan Pemilu 2024. Journal of Government Insight, 2, 210–220. https://doi.org/10.47030/jgi.v1i1.53
Tampubolon, F. D. G., Amin, M., & Harahap, H. (2021). Pengaruh Informasi Sistem Penghitungan Nasional Online pada Hasil Pemilu 2019 terhadap Kepercayaan Publik Kota Medan. PERSPEKTIF, 10(2), 399–415. https://doi.org/10.31289/perspektif.v10i2.4601
Vincent, A., Alihodzic, S., & Gale, S. (2021). Risk Management in Elections. Australian Electoral Commision and International for Democracy and Electoral Assistance.
Walker, C. P., Schiff, D. S., & Schiff, K. J. (2024). Merging AI Incidents Research with Political Misinformation Research: Introducing the Political Deepfakes Incidents Database. ArXiv, 38(21).
Wamala, F. (2011). ITU National Cybersecurity Strategy Guide. International Telecommunication Union.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Muhammad Hibban Mikhail, Sinung Suakanto, Basuki Rahmad (Author)

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors retain the full copyright of their published articles. By submitting and publishing their work, authors grant Vifada Management and Social Sciences the right of first publication. All published articles are simultaneously licensed under the Creative Commons Attribution License (CC BY 4.0), which permits unrestricted use, distribution, and reproduction in any medium, provided that the original author(s) and the initial publication in this journal are properly acknowledged.








