πŸ›‘οΈ Cybersecurity Defense Architecture β€” Hierarki Pertahanan Sistem Digital

Cybersecurity bukan satu produk β€” ia adalah 9 lapis pertahanan yang harus diterapkan simultan. Catatan ini memetakan seluruh attack surface ke dalam Defense-in-Depth hierarchy, dari ancaman fisik sampai reputasi, dengan NIST CSF 2.0 alignment, OSI layer mapping, timeline evolusi (1960-2026), dan trade-off matrix per layer. Setiap layer punya kontrol, tool, framework, dan failure mode sendiri.


Daftar Isi

  1. 1. Premise β€” Mengapa β€œSatu Layer = Aman” Itu Mitos
  2. 2. Nine-Layer Defense-in-Depth Model
  3. 3. Layer L9 β€” Brand & Reputation
  4. 4. Layer L8 β€” Compliance & Legal
  5. 5. Layer L7 β€” Identity & Access (IAM)
  6. 6. Layer L6 β€” Application Security
  7. 7. Layer L5 β€” Endpoint Security (EDR/XDR)
  8. 8. Layer L4 β€” Network Security
  9. 9. Layer L3 β€” Data Security & Cryptography
  10. 10. Layer L2 β€” Cloud & Infrastructure
  11. 11. Layer L1 β€” Physical & Hardware
  12. 12. Layer L0 β€” Threat Intelligence & Governance
  13. 13. OSI Layer Mapping
  14. 14. NIST CSF 2.0 Alignment
  15. 15. Timeline 1960-2026 β€” Evolusi Ancaman
  16. 16. Cross-Reference ke Vault
  17. References

1. Premise β€” Mengapa β€œSatu Layer = Aman” Itu Mitos

Kesalahan paling fatal dalam cybersecurity adalah mempercayai satu kontrol memberikan keamanan total:

  • β€œPakai antivirus saja cukup” β†’ ransomware tetep masuk (1990-an)
  • β€œPakai firewall saja cukup” β†’ insider threat bocor (2000-an)
  • β€œPakai enkripsi saja cukup” β†’ side-channel attack bocor (2010-an)
  • β€œPakai cloud security group saja cukup” β†’ misconfiguration bocor (2020-an)

Defense-in-Depth menyadari: setiap kontrol bisa gagal. Karena itu, kita stack 9 layer pertahanan β€” jika satu jebol, layer di belakangnya menahan.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ L9: Brand & Reputation                                   β”‚
β”‚ L8: Compliance & Legal                                   β”‚
β”‚ L7: Identity & Access                                    β”‚
β”‚ L6: Application Security                                 β”‚
β”‚ L5: Endpoint / EDR / XDR                                 β”‚
β”‚ L4: Network / NDR                                        β”‚
β”‚ L3: Data Security & Cryptography                         β”‚
β”‚ L2: Cloud & Infrastructure                               β”‚
β”‚ L1: Physical & Hardware                                  β”‚
β”‚ L0: Threat Intelligence & Governance                     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
     ↑   INCREASING ATTACKER REWARD      ↓
         DECREASING ATTACKER SKILL      (zero-day exploits)

Prinsip Castle-and-Moat yang usang: perimeter saja tidak cukup β€” attacker masuk lewat berbagai vektor (phishing, supply chain, insider).

Prinsip Zero Trust modern: verifikasi setiap akses, dari setiap arah, dari setiap entitas β€” trust nothing.


2. Nine-Layer Defense-in-Depth Model

2.1 Definisi Setiap Layer

LayerFungsiFailure Mode TipikalOwner
L9Brand reputasi, crisis commsKey product tak relevan setelah breachPR, marketing
L8Compliance frameworkDenda GDPR 4% revenue, PCI bannedLegal, GRC
L7Authentication, authorizationAkun compromised, privilege escalationIAM team
L6App-level vulnerabilitiesSQLi, XSS, RCE, supply chainDevSecOps
L5Host-level detection & responseRansomware lolos, lateral movementSOC + EDR team
L4Network segmentation, IDS/IPSEast-west traffic tidak terlihat, DDoSNetSec team
L3Encryption, key management, DLPData exfiltration, breach disclosureDataSec
L2Cloud misconfig, IAM, secretsS3 public bucket, IAM privilege excessCloudSec
L1Data center access, hardware tamperingBoot-level implant, hardware backdoorIT ops
L0Threat intel, governance, riskUnknown unknown exploitCISO, GRC

2.2 Layer Dependency & Failover

[L0: intel feeds]──── feeds to ────→ [L4, L5, L6]
    ↓
Detect threat signature
    ↓
[L4: NDR]──── blocks ────→ if bypassed β†’ [L5: EDR]──── blocks ────→ if bypassed β†’ [L6: AppSec]
                                                                              ↓
                                                                         [L7: MFA catches]
                                                                                    ↓
                                                                         [L3: encryption at rest]
                                                                                    ↓
                                                                         [L1: physical security]

Jika L0-L6 gagal total, L7-L9 adalah last line of defense:

  • L7: zero-trust dengan MFA tahan phising
  • L3: data encrypted β†’ theft tidak langsung berguna
  • L9: brand reputation dijaga lewat respon krisis

3. Layer L9 β€” Brand & Reputation

Pertahanan tertinggi: memastikan bahwa bahkan setelah breach, brand tetap relevan.

3.1 Komponen

KomponenFungsi
Incident response planKoordinasi respon saat breach terjadi
Crisis communicationsPernyataan publik, customer notification
Cyber insuranceFinansial cover untuk breach
Reputation monitoringDark web mentions, social sentiment
Customer trust restorationCompensation, transparency

3.2 Failure Mode

FailureDampakContoh
Delay disclosure 6 bulanGDPR fine €50M, brand drop 30% Yahoo (2017)
Berbohong tentang cakupan breachMulti-class lawsuit, executive ousterUber 2017
Slow customer notification50% churn dalam 30 hariEquifax (2017)
Tidak punya crisis comm teamRunaway story = market cap -20%Target (2013)

Memastikan organisasi mengikuti regulasi yang berlaku di industri + yurisdiksi.

4.1 Framework Compliance per Industri

IndustriWajibOpsional
Healthcare (US)HIPAA, HITECHHITRUST, SOC 2
Finance (US)SOX, PCI DSS, GLBAISO 27001
Finance (EU)PSD2, Basel III, MiFID IIDORA
EU generalGDPR, NIS2, DSAISO 27001, 27017
Cloud (US Fed)FedRAMP, FISMACMMC
Energy/UtilitiesNERC CIPIEC 62443
Privacy (US State)CCPA, NYDFSSOC 2
DefenseCMMC, ITARFedRAMP High

4.2 Dampak Compliance Failure

RegulasiDenda Tipikal
GDPR4% annual revenue OR €20M (mana yang lebih tinggi)
HIPAA50,000 per record + criminal
PCI DSS100K/month + kehilangan merchant
SOXCriminal prosecution untuk officer
CCPA$750 per record + class action
NIS2€10M atau 2% revenue

5. Layer L7 β€” Identity & Access (IAM)

Siapa yang boleh melakukan apa, dan dari mana.

5.1 Komponen

KomponenFungsiContoh
SSOSingle sign-on multi-appOkta, Azure AD, Auth0
MFASecond factor from passwordTOTP, FIDO2, push
PIM/PAMJust-in-time adminCyberArk, BeyondTrust
RBACRole-based accessAWS IAM, K8s RBAC
ABACAttribute-based accessOpen Policy Agent
ZTAZero Trust ArchitectureBeyondCorp, Zscaler
User behavior analyticsAnomaly detection on accessSplunk UBA, Exabeam

5.2 Frameworks

  • NIST SP 800-63 β€” Digital identity levels (IAL1-3, AAL1-3, FAL1-3)
  • NIST SP 800-207 β€” Zero Trust Architecture
  • OAuth 2.1 + OIDC β€” Modern delegated auth
  • SAML 2.0 β€” Enterprise SSO
  • SPIFFE/SPIRE β€” Workload identity

5.3 Failure Mode

AttackMitigation
PhisingFIDO2 (WebAuthn) β€” tahan phising
Credential stuffingMFA + breach detection
Session hijackShort-lived JWT + refresh
Privilege escalationLeast privilege + JIT admin
Insider threatUEBA + audit logs

Koneksi ke Vault:


6. Layer L6 β€” Application Security

Aplikasi itu sendiri β€” yang menerima input dari user dan memproses data.

6.1 OWASP Top 10 (2021) β€” Surface of Attack

RankVulnerabilityFrequency
1Broken Access Control3.81%
2Cryptographic Failures4.49%
3Injection4.74%
4Insecure Design3.0%
5Security Misconfiguration4.4%
6Vulnerable & Outdated Components8.78%
7Identification & Auth Failures<1%
8Software & Data Integrity Failures2.06%
9Security Logging & Monitoring Failures6.51%
10Server-Side Request Forgery1.43%

6.2 SDLC Security Integration

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Requirements (Abuse cases)                         β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Design (Threat modeling STRIDE, attack trees)      β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Coding (Secure code review, SAST)                  β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Testing (DAST, IAST, fuzzing, pentest)             β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Build (SCA, SBOM, signed artifacts)                β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Deploy (IaC scanning, secrets detection)           β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Operate (RASP, WAF, observability)                 β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

6.3 Supply Chain Security (SBOM Era)

  • SLSA (Supply-chain Levels for Software Artifacts) β€” Google framework
  • Sigstore β€” Cosign signing
  • in-toto β€” Attestation generation
  • CycloneDX/SPDX β€” SBOM standards
  • Sigstore Fulcio + Rekor β€” certificate transparency

Koneksi ke Vault:


7. Layer L5 β€” Endpoint Security (EDR/XDR)

Setiap device β€” laptop, server, IoT, container β€” adalah target.

7.1 Evolusi Endpoint Security

EraTeknologiDeteksiResponse
1990-2005Antivirus signatureDatabase signatureQuarantine file
2005-2015Anti-malware heuristikRule-basedBlock process
2015-2020EDR (Endpoint Detection & Response)Behavioral analyticsIsolate host, kill process
2020-2024XDR (Extended Detection & Response)Cross-domain correlationOrchestrated response
2024-2026AI-Native EDRML pattern + LLM analystAutonomous response

7.2 EDR vs XDR vs NDR

AspekEDRXDRNDR
ScopeEndpoint onlyEndpoint + email + cloud + networkNetwork traffic only
Data sourceSyscalls, file, registryMulti-source unifiedNetFlow, packet, pcap
ResponseKill process, isolate hostCross-tier orchestratedBlock traffic, sinkhole

7.3 MITRE ATT&CK Framework

ATT&CK = Adversarial Tactics, Techniques, and Common Knowledge β€” database taktik+teknik attacker:

  • 14 Tactics β€” Recon, Initial Access, Execution, Persistence, Privilege Esc, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Exfiltration, Impact
  • 200+ Techniques β€” spesifik behavior attacker
  • 600+ Sub-techniques

Setiap kontrol EDR/XDR dipetakan ke ATT&CK technique yang bisa ia detect.

Koneksi ke Vault:


8. Layer L4 β€” Network Security

Arus lalu lintas di dalam dan antar jaringan.

8.1 Komponen Jaringan

KomponenFungsi
Firewall (stateful)Filter paket berdasarkan state
WAF (Web Application Firewall)Filter HTTP/HTTPS sesuai rule
IDS/IPSIntrusion Detection/Prevention
NDRNetwork Detection & Response
NACNetwork Access Control
MicrosegmentationEast-west isolation
VPN / ZTNAEncrypted remote access
BGP RPKIRoute hijacking prevention
DDoS protectionMitigation volumetric attacks

8.2 OSI Layer Mapping

OSI LayerAncamanKontrol
1 (Physical)Wiretap, EMPFaraday cage, fiber tap detection
2 (Data Link)ARP spoof, MAC floodPort security, 802.1X
3 (Network)IP spoof, route hijackRPKI, BCP38
4 (Transport)SYN flood, port scanTCP RST, rate limit
5 (Session)Session hijackEncrypted sessions, short JWT
6 (Presentation)SSL strippingHSTS, certificate pinning
7 (Application)SQLi, XSS, mitmWAF, input validation

8.3 East-West vs North-South Traffic

                North-South (in/out)
             β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
             ↓                      ↑
β”Œβ”€β”€β”€β”€β”€β”     β”Œβ”€β”€β”€β”€β”€β”    East-west    β”Œβ”€β”€β”€β”€β”€β”
β”‚ App │←───→│ App β”‚ ←───────────→  β”‚ App β”‚
β”‚  1  β”‚     β”‚  2  β”‚    intra-DC     β”‚  3  β”‚
β””β”€β”€β”€β”€β”€β”˜     β””β”€β”€β”€β”€β”€β”˜                 β””β”€β”€β”€β”€β”€β”˜
              β”‚      β”Œβ”€β”€β”€β”€β”€β”        β”‚
              └─────→│ DB  β”‚β†β”€β”€β”€β”€β”€β”€β”€β”˜
                     β””β”€β”€β”€β”€β”€β”˜
  • North-south traffic = traffic masuk/keluar DC (perimeter defense handles)
  • East-west traffic = traffic antar-service dalam DC (microsegmentation handles)
  • 80%+ modern traffic = east-west, tapi tool tradisional fokus north-south

Koneksi ke Vault:


9. Layer L3 β€” Data Security & Cryptography

Data at rest, in transit, in use β€” diproteksi dengan kriptografi.

9.1 The Three States of Data

Data at Rest      β†’ Encryption at storage layer (LUKS, KMS, dm-crypt)
                  β†’ Backup encryption
                  β†’ Tokenization / anonymization

Data in Transit   β†’ TLS 1.3, WireGuard, IPsec, mTLS
                  β†’ Certificate management (cert-manager)
                  β†’ PFS (Perfect Forward Secrecy)

Data in Use       β†’ Confidential Compute (SEV-SNP, TDX, SGX)
                  β†’ Memory encryption (AMD SME)
                  β†’ Homomorphic encryption (research)

9.2 Key Management Lifecycle

Generate β†’ Store β†’ Distribute β†’ Use β†’ Rotate β†’ Destroy
   β”‚         β”‚        β”‚         β”‚       β”‚         β”‚
   β”‚         β”‚        β”‚         β”‚       β”‚         └─ Crypto-shred / zeroize
   β”‚         β”‚        β”‚         β”‚       └─ Per Q3 / annual rotation
   β”‚         β”‚        β”‚         └─ Access control (KMS+IAM)
   β”‚         β”‚        └─ HSM, KMS, sealed secret
   β”‚         └─ HSM (FIPS 140-3 L3)
   └─ entropy source

9.3 Algoritma yang Direkomendasikan (2026)

Use CaseAlgoritmaKey Size
Symmetric encryptionAES-256-GCM256 bit
AsymmetricEd25519, X25519, ML-KEM-768-
Hashing (general)SHA-3-256, BLAKE3256-512 bit
Password hashingArgon2id64-128 MB mem
TLS 1.3AES-256-GCM + Ed25519-
BackupAES-256-GCM + Argon2id passphrase-

Koneksi ke Vault:


10. Layer L2 β€” Cloud & Infrastructure

Konfigurasi cloud yang aman, IAM, secrets management, runtime security.

10.1 Cloud Security Failure Modes

FailureContoh
Public S3 bucket100M+ records bocor (2017-2024 trends)
Excessive IAM permissionsService account dengan admin
Secrets in source codeAPI keys di public repo
Unpatched container imagesCVE ratusan di registry
Insecure API gatewayNo auth, no rate limit
Misconfigured K8sPrivileged pod, hostPath mount

10.2 CSPM, CIEM, CNAPP

Tool KategoriFungsiVendor
CSPM (Cloud Security Posture Mgmt)Multi-cloud config auditWiz, Prisma Cloud, Lacework
CIEM (Cloud Infrastructure Entitlement Mgmt)IAM rightsizingSonrai, Ermetic
CNAPP (Cloud-Native App Protection Platform)K8s runtime + observabilityWiz, Aqua, Snyk
Secrets MgmtVault, KMSHashiCorp Vault, AWS KMS, SOPS
IaC ScanTerraform/Kubernetes auditCheckov, tfsec, Trivy

10.3 K8s-Specific Stack

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Cluster (managed: EKS/GKE/AKS)                   β”‚
β”‚   β”œβ”€ Control Plane encryption at rest            β”‚
β”‚   β”œβ”€ etcd encryption                             β”‚
β”‚   └─ Network Policy (Calico/Cilium)              β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Workload                                          β”‚
β”‚   β”œβ”€ Pod Security Standards                      β”‚
β”‚   β”œβ”€ Runtime (Falco, Tetragon)                   β”‚
β”‚   β”œβ”€ Image scanning (Trivy, Grype)               β”‚
β”‚   β”œβ”€ Supply chain (Sigstore, Kyverno)            β”‚
β”‚   └─ mTLS service mesh (Istio, Linkerd)          β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ Pipeline                                          β”‚
β”‚   β”œβ”€ Static analysis (kubescape, kube-bench)     β”‚
β”‚   β”œβ”€ Admission control (OPA, Kyverno)            β”‚
β”‚   └─ Secret rotation (External Secrets, SOPS)    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Koneksi ke Vault:


11. Layer L1 β€” Physical & Hardware

Akses fisik ke hardware, secure boot, hardware backdoors.

11.1 Komponen

KontrolFungsi
Data center access controlsBiometric, mantrap, visitor log
SurveillanceCCTV, motion sensor, IR curtain
Hardware tamper-evidentSeal, intrusion sensor
Secure bootBIOS/UEFI signature chain
TPMHardware root of trust, measured boot
HSMCryptographic key storage FIPS 140-3
Faraday cageEMP / TEMPEST shielding
Hardware attestationTEE attestation remote

11.2 Trusted Execution Environments (TEE)

TEEVendorUse Case
Intel SGXIntelEnclave computation (deprecated dari desktop)
Intel TDXIntelVM-level confidential computing
AMD SEV-SNPAMDVM-level + memory encryption
ARM TrustZoneARMMobile, IoT normal mode
Apple SEAppleSecure enclave di iOS/Mac
AWS NitroAWSCustom cloud hardware
Nvidia H100 CCNvidiaGPU confidential computing

Koneksi ke Vault:


12. Layer L0 β€” Threat Intelligence & Governance

Paling bawah β€” fondasi intelijen + keputusan yang menggerakkan semua layer di atas.

12.1 Komponen Governance

KomponenFungsi
CISOExecutive accountability untuk security
SOC24/7 monitoring, triage, response
GRCGovernance Risk Compliance
CTICyber Threat Intelligence team
Red TeamAuthorized adversary simulation
Bug BountyExternal researcher engagement
Penetration testScheduled adversarial testing

12.2 Frameworks Inti

FrameworkOwnerFungsi
NIST CSF 2.0NISTGeneric security framework (6 functions: Govern, Identify, Protect, Detect, Respond, Recover)
NIST SP 800-53NISTControl catalog (1000+ controls)
ISO 27001/27002ISOISMS implementation
MITRE ATT&CKMITREAdversary behavior catalog
CIS ControlsCIS18 prioritized actions
OWASP ASVSOWASPApplication security verification

12.3 Threat Intelligence Sources

TierSumber
StrategicVendor reports (Mandiant, CrowdStrike, Microsoft)
OperationalISACs, threat sharing communities (MISP, STIX/TAXII)
TacticalIoC feeds (abuse.ch, AlienVault OTX, VirusTotal)
TechnicalYARA rules, Snort/Suricata signatures
OSINTTwitter, Reddit, dark web forums, paste sites

13. OSI Layer Mapping

Singkat β€” setiap cybersecurity layerε―ΉεΊ” OSI:

Cybersecurity LayerOSI LayerTools Khas
L1 PhysicalOSI 1Faraday, biometrics, security cameras
L4 Network (firewall/IDS)OSI 2-4Cisco ASA, Palo Alto, Suricata
L4 Network (NDR)OSI 3-4ExtraHop, Corelight
L3 Data (TLS encrypt)OSI 6OpenSSL, cert-manager
L3 Data (storage encryption)OSI 1LUKS, dm-crypt
L2 CloudOSI 7Wiz, Prisma Cloud
L6 Application (WAF)OSI 7ModSecurity, Cloudflare WAF, Coraza
L6 Application (RASP)OSI 7Datadog ASM, Sqreen
L5 Endpoint (EDR)Host layerCrowdStrike, SentinelOne, Wazuh
L7 IdentityOSI 7Okta, Auth0, Azure AD

14. NIST CSF 2.0 Alignment

NIST CSF 2.0 punya 6 Functions. Setiap cybersecurity layer punya representative controls:

FunctionDeskripsiCybersecurity Layer yang Dominan
GOVERNKebijakan, risk, supplierL8 + L0
IDENTIFYAsset, riskL0 + L9
PROTECTKontrol preventifL1, L2, L3, L6, L7
DETECTDeteksi anomalyL4, L5, L6
RESPONDContainment, eradicationL0, L5
RECOVERRestorationL9 + L1

15. Timeline 1960-2026 β€” Evolusi Ancaman

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Era    β”‚ Decade β”‚ Major Shift                                  β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ ARPANETβ”‚ 1960s  β”‚ Physical access = total access              β”‚
β”‚ Unix   β”‚ 1970s  β”‚ Password files, user permission             β”‚
β”‚        β”‚ 1980s  β”‚ Worms (Morris 1988), first antivirus        β”‚
β”‚ Web    β”‚ 1990s  β”‚ Network worms, firewall tsunami, Nessus      β”‚
β”‚ E-com  β”‚ 2000s  β”‚ SQL injection, XSS, APT, Storm Worm         β”‚
β”‚ Cloud  β”‚ 2010s  β”‚ Supply chain, ransomware, IoT botnets       β”‚
β”‚        β”‚ 2015s  β”‚ Cryptoware, BEC, deepfake voice              β”‚
β”‚ AI-era β”‚ 2020s  β”‚ LLM prompt injection, deepfake vishing       β”‚
β”‚        β”‚ 2025   β”‚ Autonomous agents attacking each other       β”‚
β”‚        β”‚ 2026+  β”‚ Self-evolving malware, AI-powered APT        β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Trend besar tiap dekade:

  • Surface: makin meluas (device, cloud, container, AI agent)
  • Speed: makin cepat (zero-day dalam hitungan jam)
  • Sophistication: makin advanced (AI-generated phishing)
  • Target: bergeser dari random β†’ high-value (ransomware, BEC)

16. Cross-Reference ke Vault


References

  1. NIST. β€œCybersecurity Framework 2.0.” (2024).
  2. NIST SP 800-207. β€œZero Trust Architecture.” (2020).
  3. OWASP. β€œOWASP Top 10 2021.” https://owasp.org/Top10/
  4. MITRE. β€œATT&CK Matrix.” https://attack.mitre.org/
  5. CIS. β€œCIS Critical Security Controls v8.” (2021).
  6. ISO/IEC 27001:2022. β€œInformation security management systems.”
  7. SANS Institute. β€œDefense in Depth.” (2018).
  8. Verizon. β€œ2024 Data Breach Investigations Report.”
  9. Mandiant. β€œM-Trends 2024 Annual Report.”
  10. NSA. β€œNSA Cybersecurity Advisories.” 2020-2024.
  11. Cloud Security Alliance. β€œTop Threats to Cloud Computing.” (2024).
  12. PCI Security Standards Council. β€œPCI DSS v4.0.” (2022).
  13. ENISA. β€œThreat Landscape Report 2024.”
  14. Google. β€œBeyondProd, BeyondCorp.” (2019-2024).
  15. R. Ross. β€œRisk Frameworks: NIST and ISO.” NIST Publication, 2023.