121
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
No Ref
Domain Sub-Domain Technical Checklist
Status
Access Control
13
Cybersecuri- ty Implemen- tation
Enforcing Role-Based Access Control (RBAC) policy and conducting periodic reviews on access rights as well as user roles so that they remain appropriate with the current needs. Enforcing the principle of least-privilege by granting only the minimum access necessary to each user, and conducting regular audits to ensure compliance with this principle. Establishing a formal process for requesting and approving access to sensitive systems and data, including identity verification, business needs evaluation, data owner approval, and recording of approval as an audit trail. Recording and storing logs of all account management activities (creation, modification, access deletion) completely for the purpose of audit and incident investigation.
4.1.2 (point 1)
Fulfilled Partially Fulfilled Unfulfilled
Description
Access Control
14
Cybersecuri- ty Implemen- tation
4.1.2 (point 2)
Fulfilled Partially Fulfilled Unfulfilled
Description
Access Control
15
Cybersecuri- ty Implemen- tation
4.1.2 (point 3)
Fulfilled Partially Fulfilled Unfulfilled
Description
Access Control
16
Cybersecuri- ty Implemen- tation
4.1.2 (point 3)
Fulfilled Partially Fulfilled Unfulfilled
Description
Made with FlippingBook Ebook Creator