Cybersecurity Guideline Digital Financial Asset Trading Pro…

101

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

c. Facilitating regular cross-functional meeting, involving compliance team, IT security team, and business unit leaders, to evaluate compliance status and discuss follow- up actions for improvement. d. Integrating compliance review into the Software Development Life Cycle (SDLC). Ensuring that each new development complies with the applicable regulations.

5.2 Risk Treatment

The Provider’s action plan for risk assessment and risk mitigation consists of a structured approach to addressing identified risks, including selecting appropriate risk treatments, implementing security measures, and reviewing the effectiveness of security measures. Risk treatment process includes, but not limited to:

1.

Risk Treatment Options a. Risk Avoidance

Implementing strategies to avoid activities or technologies which cause unacceptable risks. For instance, not integrating third-party APIs that do not meet the minimal security standard, or avoiding the use of outdated software that is known to contain vulnerabilities. b. Risk Mitigation Applying controls and safeguards to reduce the possibilities and/or impacts of the identified risks, by enacting technical, procedural, and administrative security controls. For example, through MFA implementation for wallet access, conducting regular audit, network segmentation, and security awareness training for employees.

Made with FlippingBook Ebook Creator