Evaluasi Kematangan Penanganan Insiden Insider Threat Nirteknis Berdasarkan NIST SP 800-61: Studi Kasus Pekerja Non-AD di Industri Manufaktur Energi
DOI:
https://doi.org/10.59188/jurnalsostech.v6i8.32966Keywords:
Insider Threat Nirteknis, NIST SP 800-61, Penegakan Kebijakan Keamanan, Kematangan Penanganan Insiden, Pekerja Non-ADAbstract
Ancaman dari dalam (insider threat) selama ini dikaji hampir secara eksklusif pada pekerja pengetahuan yang memiliki akses terhadap sistem digital, sehingga strategi mitigasi didominasi oleh kontrol teknis berbasis identitas dan akses. Celah konseptual muncul pada organisasi dengan populasi pekerja non-digital, di mana kontrol konvensional menjadi tidak berlaku. Penelitian ini mengevaluasi penanganan insiden insider threat nirteknis di PT X, perusahaan manufaktur energi, yang melibatkan mantan pekerja non-Active Directory (non-AD) yang merekam dan memublikasikan area produksi. Dengan pendekatan kualitatif studi kasus deskriptif, penanganan insiden dipetakan ke dalam empat fase kerangka NIST SP 800-61, dinilai kematangannya pada skala 1–5, dan diukur efektivitasnya melalui empat parameter. Hasil penelitian menunjukkan seluruh fase memperoleh skor identik pada tingkat 2 (Initial/Ad Hoc), yang berarti aktivitas penanganan berlangsung tanpa prosedur terdokumentasi dan bergantung pada inisiatif individual. Respons cepat (0 hari) dan keberhasilan penindakan (H+1) tidak diimbangi dengan kepatuhan prosedur dan pelembagaan pembelajaran pasca-insiden. Penelitian ini menyimpulkan bahwa pada populasi non-AD, kematangan penanganan insiden tidak ditentukan oleh kecanggihan kontrol teknis, melainkan oleh kekuatan penegakan kontrol administratif dan fisik. Temuan ini memberikan implikasi bagi organisasi dengan tenaga kerja non-digital untuk mengalihkan fokus penguatan keamanan dari dimensi teknis ke dimensi prosedural dan struktural.
References
Cappelli, D. M., Moore, A. P., & Trzeciak, R. F. (2012). The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes. Addison-Wesley.
Cichonski, P., Millar, T., Grance, T., & Scarfone, K. (2012). Computer security incident handling guide. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r2
Delso-Vicente, A. T., Diaz-Marcos, L., Aguado-Tevar, O., & de Blanes-Sebastián, M. G. (2025). Factors influencing employee compliance with information security policies: A systematic literature review of behavioral and technological aspects in cybersecurity. Future Business Journal, 11(1 AR-28). https://doi.org/10.1186/s43093-025-00452-7
Denzin, N. K. (1978). The research act: A theoretical introduction to sociological methods (2nd ed.). McGraw-Hill.
Farquhar, J., Michels, N., & Robson, J. (2020). Triangulation in industrial qualitative case study research: Widening the scope. Industrial Marketing Management, 87, 160–170. https://doi.org/10.1016/j.indmarman.2020.02.001
Force, J. T. (2020). Security and privacy controls for information systems and organizations. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-53r5
Guba, Y. S. L. dan E. G. (1985). Naturalistic Inquiry. Beverly Hills, CA: Sage Publications.
Handoyo, E., & Nigrum, I. E. (2023). Penilaian risiko keamanan siber kampus menggunakan framework cybersecurity NIST 1.1. Jurnal CoSciTech (Computer Science and Information Technology), 4(3), 677–685. https://doi.org/10.37859/coscitech.v4i3.5628
Herrera Montano, I., Garcia Aranda, J. J., Ramos Diaz, J., Molina Cardin, S., de la Torre Diez, I., & Rodrigues, J. J. P. C. (2022). Survey of techniques on data leakage protection and methods to address the insider threat. Cluster Computing, 25(6), 4289–4302. https://doi.org/10.1007/s10586-022-03668-2
Inayat, U., Farzan, M., Mahmood, S., Zia, M. F., Hussain, S., & Pallonetto, F. (2024). Insider threat mitigation: Systematic literature review. Ain Shams Engineering Journal, 15(9 AR-103068). https://doi.org/10.1016/j.asej.2024.103068
Information Technology, Information Security Incident Management, Part 1: Principles and Process, ISO/IEC 27035-1:2023. (2023). International Organization for Standardization.
ISACA. (2018). COBIT 2019 Framework: Introduction and Methodology. ISACA.
Madiyaningsih, I., & Ramli, K. (2023). IT maturity level analysis using framework COBIT 5 work for management cyber incident: Case study of company Z in ICT field. Gema Wiralodra, 14(2), 952–960. https://doi.org/10.31943/gw.v14i2.476
Pathirana, N., Roberts, R., Kalutarage, H., & McDermott, C. D. (2026). Integrating human factors into insider threat detection: A systematic review. ACM Computing Surveys, 58(10 AR-260).
Rahman, R., Lestari, D., & Lestari, C. I. (2026). Analisis keamanan sistem informasi terhadap serangan insider threat. INOMATEC: Jurnal Inovasi Dan Kajian Multidisipliner Kontemporer, 1(3).
Ramadhanty, N. (2024). Implementasi kerangka keamanan NIST dan ISO/IEC 27001 dalam menghadapi ancaman risiko siber. Journal of Indonesian Management, 4(4). https://doi.org/10.53697/jim.v4i4.1973
Security, Cybersecurity and Privacy Protection, Information Security Management Systems, Requirements, ISO/IEC 27001:2022. (2022). International Organization for Standardization.
Technology, N. I. of S. and. (2024). The NIST Cybersecurity Framework (CSF) 2.0. https://doi.org/10.6028/NIST.CSWP.29
Technology, N. I. of S. and. (2025). Incident response recommendations and considerations for cybersecurity risk management: A CSF 2.0 community profile. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-61r3
Yin, R. K. (2018). Case Study Research and Applications: Design and Methods (6th ed.). Sage Publications.
Zangana, H. M., Sallow, Z. B., & Omar, M. (2025). The human factor in cybersecurity: Addressing the risks of insider threats. Jurnal Ilmiah Computer Science, 3(2), 76–85.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Muhammad Syahdan Junus, Muhammad Najamuddin Dwi Miharja, Hendra Arya

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA). that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.



