106
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
5.4 Third-Party Risk Management
As Digital Financial Asset Providers become increasingly dependent on third parties to provide technology, infrastructure, and operational support services, the complexity of risk management also increases, particularly in the context of cyber risk. Several incidents in the digital asset ecosystem have demonstrated that vulnerabilities on the part of third parties can be a major entry point for cyber attacks that have a systemic impact on major providers. Therefore, the third party should play an active role and be responsible in managing cyber risks under their scope of service, as well as support the Provider in ensuring operational sustainability and security.
To address such challenges, the third party’s risk management should refer to the risk-based approach by focusing on the following:
1.
Formal Policy and Oversight Structure There should be a formal policy regarding third-party risk management, which ecompasses the process of identification, evaluation, monitoring, and termination of cooperation. Additionally, there needs to be a special function
Made with FlippingBook Ebook Creator