Cybersecurity Guideline Digital Financial Asset Trading Pro…

121

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

No Ref

Domain Sub-Domain Technical Checklist

Status

Access Control

13

Cybersecuri- ty Implemen- tation

Enforcing Role-Based Access Control (RBAC) policy and conducting periodic reviews on access rights as well as user roles so that they remain appropriate with the current needs. Enforcing the principle of least-privilege by granting only the minimum access necessary to each user, and conducting regular audits to ensure compliance with this principle. Establishing a formal process for requesting and approving access to sensitive systems and data, including identity verification, business needs evaluation, data owner approval, and recording of approval as an audit trail. Recording and storing logs of all account management activities (creation, modification, access deletion) completely for the purpose of audit and incident investigation.

4.1.2 (point 1)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Access Control

14

Cybersecuri- ty Implemen- tation

4.1.2 (point 2)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Access Control

15

Cybersecuri- ty Implemen- tation

4.1.2 (point 3)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Access Control

16

Cybersecuri- ty Implemen- tation

4.1.2 (point 3)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Made with FlippingBook Ebook Creator