Home News CBQA Global Asia Pacific Director Shares ISO/IEC 27001 Insights at Research Security and Cyberbiosecurity Workshop for Indonesian Biotechnology Companies

CBQA Global Asia Pacific Director Shares ISO/IEC 27001 Insights at Research Security and Cyberbiosecurity Workshop for Indonesian Biotechnology Companies

ISO/IEC 27001

Written By

CBQA Global

Follow us:

Jakarta, 22 September 2026 – Anwar Siregar, Director Asia Pacific at CBQA Global, was invited as a speaker at the Raising Awareness on Research Security and Cyberbiosecurity Best Practices for Indonesian Biotechnology Companies workshop.

The workshop was held in Jakarta on 22-23 September 2026.

The two-day workshop was initiated by Health Security Partners (HSP). It was held in collaboration with the Konsorsium Bioteknologi Indonesia (KBI) and BEP.

The program focused on research security and cyberbiosecurity. It aimed to strengthen awareness among Indonesian biotechnology companies.

The workshop also addressed the protection of sensitive data and intellectual property. In addition, it covered other critical research assets that may face security threats.

The workshop brought together stakeholders from the biotechnology sector. These included researchers, managers, compliance officers, and IT personnel.

The agenda covered several important topics. These included research security, dual-use technologies, and Know-Your-Collaborator (KYC).

It also covered due diligence practices and cybersecurity threats. Furthermore, participants discussed the NIST Cybersecurity Framework and risk mitigation.

Institutional policies for protecting data and intellectual property were also discussed.

Connecting Information Security with Biotechnology Research

During the first-day research security session, Anwar Siregar delivered a presentation on ISO/IEC 27001:2022 – Information Security Management Systems – Requirements.

The presentation focused on the role of an Information Security Management System (ISMS). In particular, it explored how an ISMS can protect biotechnology research, data, and intellectual property.

The security of biotechnology research goes beyond conventional IT systems. Therefore, organizations need to consider a wider range of critical assets.

These assets include research knowledge, biological and genomic data, intellectual property, and research outputs.

They can also include physical and biological assets. Examples include samples, strains, cell lines, reagents, prototypes, and equipment.

A single compromised research project can affect multiple areas of an organization. For example, compromised researcher credentials may create unauthorized access to raw sequence data.

They may also allow changes to analysis parameters. As a result, the reliability of research results may become uncertain.

This example shows how information security connects with research integrity. It also connects with intellectual property protection, privacy, and business continuity.

In this context, ISO/IEC 27001 provides a structured framework for managing information security risks. It can support organizations in protecting critical research activities and assets.

From Security Controls to Risk-Based Governance

Many organizations already have security controls in place. These controls can include firewalls, endpoint protection, backups, and confidentiality agreements.

They may also use physical access controls and research collaboration platforms.

However, security controls alone may not answer important governance questions.

For example, organizations need to know which research assets are most critical. They also need to determine who owns and accepts residual risk.

In addition, organizations need to know whether data manipulation can be detected. They should also determine whether collaborator access rights expire when required.

Another important question concerns data recovery. Organizations need to establish whether trusted data can be restored when necessary.

An effective governance framework connects security controls with risk, ownership, evidence, and continual improvement.

In this context, ISO/IEC 27001 provides a systematic approach to information security risk management.

The ISMS brings several areas together. These include organizational context, leadership, accountability, risk assessment, and risk treatment.

It also includes operational controls, monitoring, and continual improvement.

Therefore, information security should not be viewed only as a technical function. Instead, it should become part of a broader management system.

This approach connects business objectives with risk management. It also connects responsibilities, controls, and evidence.

Protecting Research Throughout Its Lifecycle

Another key message from the presentation was the importance of defining the ISMS scope around the research lifecycle.

The scope should not be limited to specific IT systems. Instead, it should consider how research assets move through the organization.

For biotechnology organizations, the research lifecycle can involve several stages.

These stages may include research initiation and funding. They can also include experimental design and sample acquisition.

Next, the process may involve laboratory processing and data generation. It can then continue through data analysis, collaboration, and transfer.

The lifecycle may also include publication or commercialization. Finally, it may involve secure archiving or destruction.

At each stage, organizations need to identify relevant owners and users. They should also identify systems, collaborators, threats, and required evidence.

Applying ISO/IEC 27001 across this lifecycle can create a more structured approach. As a result, organizations can better identify and manage information security risks.

The presentation also highlighted the importance of critical dependencies.

These dependencies can include laboratories and instruments, bioinformatics applications, researchers and support teams, cloud and data repositories, collaborators, and service providers.

Therefore, an effective information security scope should consider both internal and external dependencies.

An Integrated Approach to Cyberbiosecurity

The session also explored the role of ISO/IEC 27001 controls in cyberbiosecurity.

These controls can be considered across four interconnected dimensions. They include organizational, people, physical, and technological controls.

For example, organizational controls can establish research security policies. They can also define asset ownership and classification requirements.

In addition, they can support third-party requirements and incident escalation. Backup, continuity, and assurance can also form part of the governance approach.

People controls address the human element of information security.

These controls can include role-based access and confidentiality obligations. They can also include training, access reviews, and defined responsibilities.

These responsibilities become especially important when personnel change roles. They also matter when employees or collaborators leave an organization.

Meanwhile, physical controls help protect research environments.

They can help protect laboratories, samples, records, instruments, and other physical research assets.

Technological controls address the digital environment. These controls can include identity and access management, encryption, and data sharing.

They may also cover infrastructure security and application security. Furthermore, they can address code security, laboratory technology, monitoring, and incident response.

However, no single control can adequately protect a high-value research asset.

Instead, organizations need multiple layers of protection. These layers should reinforce one another across organizational, people, physical, and technological dimensions.

This integrated approach is particularly relevant to biotechnology organizations.

Research assets can exist across digital systems and physical facilities. They can also include biological materials, human knowledge, and external collaboration networks.

Therefore, cyberbiosecurity requires a broader view of information security and risk management.

Building a Stronger Cyberbiosecurity Foundation

The broader objective of the workshop was to strengthen cyberbiosecurity capabilities among Indonesian biotechnology organizations.

The program focused on identifying and mitigating risks associated with research collaboration.

It also aimed to help institutions strengthen policies and procedures. These measures can help protect sensitive data, intellectual property, and research outputs.

At the same time, organizations can improve alignment with international standards and best practices.

Concluding his presentation, Anwar highlighted five starting points for organizations beginning their cyberbiosecurity journey.

1. Identify the Crown Jewels

Determine which research, data, and intellectual property assets are most critical.

Organizations should understand the potential impact if these assets are compromised.

2. Map the Research Lifecycle

Understand where research assets are created and processed.

Also identify where they are transferred, shared, and stored.

3. Assign Ownership

Establish clear accountability for critical assets.

In addition, define who is responsible for important security decisions.

4. Assess Integrated Risk

Evaluate risks across people, processes, and technology.

The assessment should also consider physical environments and external collaborations.

5. Prioritize Treatment

Determine which risks require immediate attention.

Then, prioritize controls based on their potential business and operational impact.

Through its participation in the workshop, CBQA Global continues to contribute to discussions around information security, cybersecurity, and risk-based governance.

The company supports organizations in understanding internationally recognized management system frameworks.

These frameworks can help organizations address evolving security challenges.

For biotechnology organizations, information security is not only about protecting IT systems.

It is also about protecting the knowledge, data, intellectual property, people, facilities, and research outcomes that create value.

Ready to Strengthen Your Organization’s Information Security Management?

ISO/IEC 27001:2022 can help organizations establish a structured and risk-based approach to information security management.

The standard provides a management system approach to identifying, assessing, treating, and monitoring information security risks.

For biotechnology organizations, this approach can support stronger governance across research activities and critical information assets.

Learn more about ISO/IEC 27001 certification with CBQA Global.

Contact us for more information:

CBQA Global
Certification | Audit | Training | Sustainability

Email: marketing@cbqaglobal.com
WhatsApp: 08118468777
Phone: +62 21 2781 4200

More CBQA Global News

Ready to Strengthen Compliance, Trust, and Business Resilience?

Get expert support for your ISO certification and compliance needs through structured services in Certification, Audit, Training, Verification, Validation, Sustainability, and Professional Training to strengthen governance, reduce risk, and improve performance.

Apply for This Opportunity

Name
Drag & Drop Files, Choose Files to Upload