Cybersecurity Guideline Digital Financial Asset Trading Pro…

107

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

or organizational structure which is directly responsible in managing and overseeing risks from vendors or external partners. 2. Third-Party Integration in Security Strategy In designing a comprehensive cybersecurity strategy, the Provider should consider the position and role of the third party in the entire operational value chain, including the potential risk exposure arising from the outsourced services, systems, or business processes. 3. Third-Party Life Cycle Management Complete documentation should be done for the entire collaboration life cycle, starting from vendor selection, service agreement, to the cooperation termination. Such document includes: a. Types of the offered services or products.

b. Access to the system and data provided by the Provider. c.  Cybersecurity requirements that need to be fulfilled by the third party, including compliance toward standards such as ISO 27001, SOC 2, or CSA STAR. Cloud Security Posture Management (CSPM) If the Provider uses a Cloud Service Provider (CSP) , they should verify that the service provider has and activates Cloud Security Posture Management (CSPM) to automatically monitor, detect, and fix misconfigurations, public access vulnerabilities, and other weaknesses in the cloud environment.

4.

By applying these practices consistently, the Provider may mitigate risks resulting from third-party association, increasing the cybersecurity end-to-end.

Made with FlippingBook Ebook Creator