SPBE (Perpres 95/2018) Compliance Guide
The Electronic-Based Government System requires security built into every stage of how agencies plan, build, and run their systems. Claro helps you deliver and evidence the human-layer controls that support it.
- Regulator
- MENPAN-RB, with BSSN for security
- Applies to
- Central and regional government agencies
Overview
SPBE (Sistem Pemerintahan Berbasis Elektronik) is Indonesia's Electronic-Based Government System, established under Presidential Regulation No. 95 of 2018 (Peraturan Presiden No. 95 Tahun 2018). It governs how central and regional government agencies plan, build, and operate their electronic government systems so that public services are delivered efficiently, transparently, and securely. Oversight is led by MENPAN-RB, while security matters involve BSSN. In short, SPBE is the framework that shapes digital government across Indonesia.
Security is not a bolt-on within SPBE; it is expected to be integrated into every stage of system and application development. The framework calls for controls that protect the confidentiality, integrity, and availability of government data and information, together with sound risk management. This lifecycle view means agencies should consider security from planning through operation, and treat the people who use these systems as a core part of the control environment.
SPBE applies to all government entities, from ministries and central agencies to regional governments delivering public services electronically. Because civil servants are frequent targets of phishing and social engineering, their ability to recognize and report suspicious messages has a direct effect on whether government data stays confidential and available. Human-layer resilience is therefore a practical component of the integrated security SPBE envisions, alongside technical and process controls. Regional agencies in particular often operate with leaner security teams, which makes empowered, alert staff an even more valuable line of defence. Content delivered in Bahasa Indonesia, at a level every civil servant can act on, is essential for this to work in practice.
This page is general information to help agencies plan the human-risk side of SPBE readiness; it is not legal advice and does not cover the full breadth of the framework, its maturity assessments, or its architecture requirements. SPBE is administered by MENPAN-RB with security input from BSSN and evolves over time, so confirm current expectations through official sources and qualified advisers. Claro supports the awareness, simulation, reporting, and evidence controls that SPBE security expects, but a tool alone does not make an agency compliant.
What the rule expects
Integrate security across the whole system lifecycle
SPBE expects security to be built into every stage of system and application development, not added at the end. Awareness and human-risk controls should likewise run continuously rather than as a one-off exercise.
Protect confidentiality, integrity, and availability of government data
The framework requires controls that safeguard the confidentiality, integrity, and availability of government information. Since phishing and credential theft threaten all three, workforce resilience is a direct contributor to these objectives.
Manage information-security risk systematically
SPBE calls for sound risk management across government electronic systems. Agencies should be able to identify where human-driven risk concentrates and prioritize action toward the roles and units that carry the greatest exposure.
Build security awareness among civil servants
Delivering secure public services depends on the people operating the systems. SPBE-aligned programs should raise and sustain security awareness across all levels of an agency, in language staff understand.
Prepare to detect and respond to incidents
Integrated security includes readiness to detect and respond to threats. Fast internal reporting of suspicious messages gives security teams, including any BSSN-aligned response function, the early signal needed to act quickly.
Demonstrate security maturity and improvement
SPBE involves ongoing assessment of how agencies perform. Being able to evidence awareness activity, simulation outcomes, and risk reduction over time supports maturity evaluation and internal governance.
Keep government data within controlled environments
Government agencies place a high value on data residency and control over sensitive information. Any awareness or simulation platform handling civil-servant data should offer deployment options that keep that data in a controlled, sovereign environment.
Understanding your SPBE index score
The SPBE index (Indeks SPBE) is the score a government body receives from its SPBE evaluation, covering domains such as SPBE policy, governance, risk and information security management, and SPBE services. Information security is assessed as part of that score, and awareness of personnel handling government data is part of what sits behind it. Instansi that treat the index as an annual reporting exercise tend to plateau; those that treat the underlying domains as an operating model improve year on year.
How Claro helps you comply
Continuous phishing simulations for agencies
Claro runs bilingual phishing simulations with scheduling, throttling, and per-recipient tracking of opens, clicks, submissions, and reports. This makes human-layer resilience a continuous, measurable control that fits SPBE's expectation of security across the lifecycle.
Protect government data by reducing successful attacks
Because most breaches begin with a person, cutting successful phishing directly protects the confidentiality, integrity, and availability of government information. Claro's simulations and training lower the chance that a deceptive message becomes unauthorized access.
Risk scoring aligned to systematic risk management
Per-user and per-department risk scoring, supported by a behaviour engine, shows exactly where human-driven risk concentrates. Agencies can then focus effort on the roles and units that carry the greatest exposure, supporting SPBE's risk-management goals.
Bilingual awareness and just-in-time training
When a civil servant fails a simulation, Claro shows an instant awareness page and auto-enrols them in relevant micro-modules. Bilingual learning paths and assignment rules keep awareness continuous and appropriate for every level of the agency.
A phish-report loop for faster response
The Claro phish-report button (Outlook add-in and Gmail extension) turns civil servants into human sensors. Their one-click reports feed a central loop that shortens detection time and supports the incident detection and response SPBE expects.
Evidence packages and sovereign deployment
Claro's compliance module maps control coverage and produces evidence packages (ZIP bundles of PDFs and CSVs) plus Claro-style reports for maturity and governance. On-premise deployment with per-tenant isolation and AES-256-GCM encryption keeps government data in a controlled environment. Detailed audit logs record who did what and when, so your evidence trail stands up to internal and external scrutiny.
Frequently asked questions
SPBE (Sistem Pemerintahan Berbasis Elektronik) is Indonesia's Electronic-Based Government System, established under Presidential Regulation No. 95 of 2018. It applies to all central and regional government agencies that plan, build, and operate electronic systems to deliver public services.
This page is provided for general information only and is not legal advice. Regulatory requirements change and apply differently depending on your organization. Confirm your specific obligations with qualified counsel or your regulator.
Related pages
ISO/IEC 27001
The global ISMS standard. Evidence the awareness control its Annex A calls for.
Learn moreNIST Cybersecurity Framework (CSF 2.0)
A voluntary global framework organizing cybersecurity around six Functions, with security awareness sitting inside Protect and Govern.
Learn moreSOC 2
An AICPA attestation on security controls that commonly expects documented security awareness training as evidence.
Learn moreBuild defensible security awareness evidence
Claro gives compliance and security teams the reporting auditors expect, in English and Bahasa Indonesia.
Request a demo