122
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
No Ref
Domain Sub-Domain Technical Checklist
Status
Access Control
17
Cybersecuri- ty Implemen- tation
Activating early alert for any changes in access rights or high-privilege roles, in order to ensure immediate response to potential misuse.
4.1.2 (point 3)
Fulfilled Partially Fulfilled Unfulfilled
Description
Access Control
18
Cybersecuri- ty Implemen- tation
Implementing a centralized identity and access management (IAM) system integrated with user directories (e.g., LDAP/AD) and standard authentication protocols (SAML, OIDC, OAuth) for consistent access management. Utilizing Privileged Access Management (PAM) solutions to control and monitor access to privileged accounts (admin, root, service accounts) to prevent misuse that may cause a major impact. Applying secure session management: auto- logout after inactivity, session token protection (logout/invalidate token upon logout or credential change), and re- authentication (step-up auth) for access to high- privilege resources.
4.1.2 (point 3)
Fulfilled Partially Fulfilled Unfulfilled
Description
Access Control
19
Cybersecuri- ty Implemen- tation
4.1.2 (point 3)
Fulfilled Partially Fulfilled Unfulfilled
Description
Access Control
20
Cybersecuri- ty Implemen- tation
4.1.2 (point 4)
Fulfilled Partially Fulfilled Unfulfilled
Description
Made with FlippingBook Ebook Creator