Cybersecurity Guideline Digital Financial Asset Trading Pro…

99

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Risk assessment process includes, but not limited to: 1. Vulnerability Assessment

a. E stablishing vulnerability assessments periodically. Ideally, the assessment should be conducted at least quarterly and when there are any significant changes on the infrastructure, such as system update, new service launch, or new device integration. b. A djusting policies based on the vulnerability assessment results to align them with the specific architecture of the Provider’s network and system, including adjustments to the depth of the assessment, scope, and complexity of testing. c. M aintaining a bug bounty program if necessary to discover and report vulnerabilities before they are exploited by malicious parties. By involving ethical hackers, the platform may identify security gaps which may not be detected by the internal team. In high-value industries, implementing bug bounty may enhance consumers’ trust and platform integrity.

2.

Penetration Testing a. C onducting penetration testing by external cybersecurity experts annually or when there are significant network changes or after any crucial infrastructure implementation. b. In addition to the regular schedule, carrying out ad-hoc penetration testing in response to recent emerging threats or following cybersecurity incidents. c. Utilizing penetration testing results comprehensively to remediate identified vulnerabilities.

Made with FlippingBook Ebook Creator