SPBE Security Assessment Evidence: Reviewable Record
Source requirement and assessment practice
Presidential Regulation No. 95 of 2018 concerns SPBE. This article uses its official government publication as a narrow source for the instrument’s identity and status; it does not map BSSN instruments or represent BSSN assessment criteria. Current text, dates, and application to a government agency or system require authorized operator and legal review.
A source requirement is what an authoritative instrument says. An assessment practice is a practical record used to make testing reviewable. NIST SP 800-115, published September 2008, describes planning, conducting, analysing, and mitigating technical security tests; it is useful methodology, not an Indonesian legal instrument. Operator and legal review are required before any SPBE mapping. Where formal assessment or assurance is involved, the relevant competent or accreditation reviewer must set acceptance rules.
Evidence chain
Build a chain from authority to action. Keep originals read-only and record hashes for supplied evidence.
| Record | Pass criterion | Owner | Failure treatment |
|---|---|---|---|
| Applicability decision | agency, system, instrument, provision, reviewer, date recorded | SPBE/legal owner | unconfirmed; do not claim mapping |
| Asset scope | production assets, integrations, data class, exclusions named | system owner | scope gap blocks conclusion |
| Written authorization | dates, targets, methods, stop contact, prohibited actions signed | accountable official | no testing begins |
| Test log | method, tester, UTC time, target version, result, hash linked | assessment lead | result is insufficient evidence |
| Finding record | reproduction boundary, impact rationale, severity, owner, due date | remediation owner | remains open |
| Retest record | changed version, method, result, residual risk decision linked | assessment lead | closure denied |
Completed example: an agency portal release 3.7.2 has scope approval naming public web, API, and SSO integration; production denial-of-service and social engineering are excluded. Assessor stores signed ROE, sanitized request evidence, report hash, and ticket SPBE-42. A broken authorization finding passes retest only when test account cannot access another tenant after release 3.7.3, evidence states date and method, and system owner accepts remaining limitations. “Report delivered” is not a pass criterion.
Review questions and remediation
Ask whether evidence proves the stated scope, rather than whether a policy exists. Can reviewer identify who authorized access? Can they reproduce a result against stated version? Was evidence protected from alteration? Does each exception name an approver and expiry? Does remediation show effectiveness, not only a ticket status?
Mark failure when authorization is absent, evidence cannot be attributed to a target/version, raw evidence includes unapproved personal data, severity has no rationale, or a closed item has no retest or formally recorded risk acceptance. Remediation record should state action, owner, target date, dependency, validation method, and decision if delayed. Preserve minimum necessary evidence under agency retention and classification rules; do not upload credentials, production secrets, or unnecessary personal data to an assessor workspace.
Change control for evidence
When a target changes during assessment, record changed component, release identifier, approving owner, and whether prior result remains valid. Do not silently reuse evidence from a staging build for production. If material scope changes, pause conclusion, update authorization, and decide whether focused retest is needed. This preserves a defensible timeline without expanding test authority.
Reviewer decision rule
Reviewer should record each objective as supported, partly supported, or not supported, with citation to exact artifact. Supported requires authorized scope, attributable result, and complete disposition; it does not mean control is permanently effective. Partly supported identifies missing sampling, limitations, or pending retest. Not supported opens remediation or formal risk decision. This language makes assessment uncertainty visible without producing an unsupported assurance conclusion.
Evidence handover
Give review team an indexed package: applicability decision; signed authorization; approved asset list; evidence manifest and hashes; finding register; exception register; remediation status; retest output; and retention decision. Each item names custodian, classification, and permitted readers. Reviewers can request a protected original when summary evidence is insufficient.
Use internal states deliberately: ready means required records are present and attributable; blocked means authorization, scope, or integrity is unresolved; conditional means a named owner accepted a bounded exception. These are workflow states, never SPBE status labels.
Publication and assurance boundary
Recheck current authority text and status in official government publication before publication or procurement use. This record helps an agency prepare a reviewable assessment package. It does not demonstrate SPBE compliance, BSSN approval, certification, accreditation, or a guaranteed security outcome.
Assessment closure identifies evidence period, system boundary, reviewer, unresolved gap, and responsible follow-up. Expected result: each conclusion can be traced to dated observation without extending beyond stated assessment scope. Edge case: configuration changes during evidence collection; separate pre-change and post-change results. Close package only after accountable agency owner accepts limitations and next review date.
Sources
Worked closure check
For citizen-service evidence, close package around agency-approved scope, portal release, signed ROE, assessment interval, accountable official, and hashed result set. It supports review of stated technical observations only; it does not establish SPBE status, BSSN approval, certification, or legal interpretation. Separate evidence when a portal release changes during collection and request revised authority before extending tests. Reviewer samples one conclusion from authorization through original artifact, remediation status, and limitation register; any missing chain remains blocked.