Cybersecurity Guideline Digital Financial Asset Trading Pro…

108

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

5.5 Audits

Audits should be conducted independently, periodically, and comprehensively on all operational aspects, both on the Provider’s legal entity and the digital asset trading system used. The key purpose of audit is to ensure that the Provider’s operational acitivities are in line with the good governance principle, comply with the applicable provisions and regulations, and are capable in maintaining security as well as public trust toward the digital asset ecosystem. The audits referred to in this guideline at least includes, but not limited to: 1. Information System Audit conducted based on the international standards such as ISO/ IEC 27001, NIST, or the testing standards of the security system and other networks to ensure integrity, confidentiality, and data availability, as well as information technology system. 2. Wallet Technology Audit encompassing security architecture evaluation, private key management, multisignature mechanism, as well as fund segregation between the Provider’s and the Consumers’ funds. 3. Proof of Reserve (PoR) Audit on the Consumers’ fund managed by the Provider, in order to ensure that the Consumers’ fund is completely stored, separated from the company assets, and can be proven of its existence through transparent and auditable verification methods. In accordance with the provision on the OJK Regulation Number 27 of 2024, the audit results shall be reported to OJK , both separately and as an integral part of the Annual Report. Compliance toward this obligation indicates the Provider’s commitment in maintaining transparency, accountability, as well as protection for the Consumers and the financial system as a whole.

Made with FlippingBook Ebook Creator