Javascript must be enabled to continue!
Evaluating ISO Standards for Indonesian PDP Law Compliance: A Regulatory Mapping and Literature Review
View through CrossRef
Purpose: This paper aims to demonstrate how ISO standards such as ISO/IEC 27001:2022, ISO/IEC 27002:2022, and ISO/IEC 27701:2019 can assist Indonesian organizations in facilitating compliance with the Personal Data Protection (PDP) Law. It highlights the challenge organizations face due to the lack of clear guidance in the law, then shows how these ISO standards can guide them to achieve the compliance. The study also maps the regulation’s requirements and how that requirements can be fulfilled by certain approaches provided by the standards and offers a clearer path toward full compliance.
Methods: This research employs a qualitative approach, combining a literature review, document analysis, and comparative assessment. It provides systematic Indonesian PDP Law-ISO/IEC 27001, ISO/IEC 27002, and ISO/IEC 27701 mapping, an analysis of their alignment, a gap analysis, and how these standards able to demonstrate compliance to Indonesian PDP Law.
Result: This study shows that from 14 mandatory requirement topics of Indonesian PDP Law that have been mapped, The ISO/IEC 27001:2022 only able to cover 1 topic, while ISO/IEC 27002:2022 able to provide controls to accommodating 8 topics and ISO/IEC 27701:2019 able to provide controls to accommodating 13 topics. But by combining these standards, then all of mandatory requirements of Indonesian PDP Law can be satisfied.
Novelty: This study shows how international standards like ISO/IEC 27001, ISO/IEC 27002, and ISO/IEC 27701 would help organize compliance to the Indonesian PDP Law while also strengthening data protection practices in Indonesia.
Universitas Negeri Semarang
Title: Evaluating ISO Standards for Indonesian PDP Law Compliance: A Regulatory Mapping and Literature Review
Description:
Purpose: This paper aims to demonstrate how ISO standards such as ISO/IEC 27001:2022, ISO/IEC 27002:2022, and ISO/IEC 27701:2019 can assist Indonesian organizations in facilitating compliance with the Personal Data Protection (PDP) Law.
It highlights the challenge organizations face due to the lack of clear guidance in the law, then shows how these ISO standards can guide them to achieve the compliance.
The study also maps the regulation’s requirements and how that requirements can be fulfilled by certain approaches provided by the standards and offers a clearer path toward full compliance.
Methods: This research employs a qualitative approach, combining a literature review, document analysis, and comparative assessment.
It provides systematic Indonesian PDP Law-ISO/IEC 27001, ISO/IEC 27002, and ISO/IEC 27701 mapping, an analysis of their alignment, a gap analysis, and how these standards able to demonstrate compliance to Indonesian PDP Law.
Result: This study shows that from 14 mandatory requirement topics of Indonesian PDP Law that have been mapped, The ISO/IEC 27001:2022 only able to cover 1 topic, while ISO/IEC 27002:2022 able to provide controls to accommodating 8 topics and ISO/IEC 27701:2019 able to provide controls to accommodating 13 topics.
But by combining these standards, then all of mandatory requirements of Indonesian PDP Law can be satisfied.
Novelty: This study shows how international standards like ISO/IEC 27001, ISO/IEC 27002, and ISO/IEC 27701 would help organize compliance to the Indonesian PDP Law while also strengthening data protection practices in Indonesia.
Related Results
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Evaluating the Science to Inform the Physical Activity Guidelines for Americans Midcourse Report
Abstract
The Physical Activity Guidelines for Americans (Guidelines) advises older adults to be as active as possible. Yet, despite the well documented benefits of physical activi...
Proposta de estruturação do processo de desenvolvimento de produtos para empresas prestadoras de serviço de telecomunicações
Proposta de estruturação do processo de desenvolvimento de produtos para empresas prestadoras de serviço de telecomunicações
O setor de telecomunicações apresenta um cenário altamente competitivo e de constante inovação tecnológica, exigindo que seu Processo de Desenvolvimento de Produtos (PDP) tenha ade...
The impact of ISO security standards on enhancing cybersecurity posture in organizations
The impact of ISO security standards on enhancing cybersecurity posture in organizations
The increasing frequency and sophistication of cyber threats have made organizations need to adopt robust cybersecurity frameworks. ISO security standards, particularly the ISO/IEC...
Pros and Cons Comparison of Reporting on the Personal Data Protection Law in Tribunnews.com and Antaranews.com
Pros and Cons Comparison of Reporting on the Personal Data Protection Law in Tribunnews.com and Antaranews.com
This article observes the framing contained in reports of Tribunnews.com and antarnews.com regarding the ratification of Law No. 27 of 2022 concerning Perlindungan Data Pribadi or ...
Situated Personal Development Planning
Situated Personal Development Planning
In the UK, institutional strategies regarding Personal Development Planning (PDP) are based on two main approaches: 1) legitimising local practices, with an emphasis on PDP process...
Standardization in Health and Medical Informatics
Standardization in Health and Medical Informatics
When things go well then often it is because they conform to standards (ISO, 2005). According to the Oxford Dictionary of Modern English, there is a lot of explanation of what stan...
Global Problem of Physician Dual Practices: A Literature Review
Global Problem of Physician Dual Practices: A Literature Review
Background: Physician dual practices (PDP) is a term used to describe physicians who combine work in public and private health-care sector. This study aimed to find evidence of PDP...
API Offshore Structures Standards: Changing Times
API Offshore Structures Standards: Changing Times
Abstract
Two instrumental series of events in the past several years have provided the impetus for API Subcommittee 2 (SC 2) to action a new strategy for the API ...

