Cybersecurity Guideline Digital Financial Asset Trading Pro…

102

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

c. Risk Sharing Transferring half of the risks to other parties. Risk sharing may involve assigning certaing functions to a cybersecurity- specialized company or purchasing cyber insurance to protect the system from potential of loss due to cyber incidents such as hacking or digital asset thefts. d. Risk Acceptance Accepting risks when the risk mitigation cost is higher than the possible impact potential. Risk acceptance shall be supported by a clear understanding based on an analysis on the potential impacts and possible loss. Security follow-up actions a. Implementing advanced security measures, such as multi- factor authentication (MFA), reliable data encryption, and coding practices that are safe for data and transactions. b. Utilizing sustainable monitoring system such as Security Information and Event Management (SIEM), User and Entity Behaviour Analytics (UEBA), as well as monitoring digital asset transactions in real time to track and analyze network traffic and system activities to identify potential threats. c. Preparing and implementing adequate incident response plan, which includes specific actions to detect, isolate, mitigate impacts, restore the system, and report incidents to regulators. d. Ensuring that the third-parties/vendors comply with the Provider’s security policies, including security control integration in the cooperation agreement and willingness to be inspected by OJK if required. e. Using smart contact audit tools if the Provider offers services on the basis of blockchain technology.

2.

Made with FlippingBook Ebook Creator