Cybersecurity Guideline Digital Financial Asset Trading Pro…

124

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

No Ref

Domain Sub-Domain Technical Checklist

Status

Secure storage media

24

Cybersecuri- ty Implemen- tation

Performing routine testing (simulation) on the backup data to ensure that the data can be perfectly restored.

4.1.3 (point 3)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Secure storage media

25

Cybersecuri- ty Implemen- tation

Implementing secure data destruction procedures: completely deleting data from storage using secure wiping, degaussing, or physical destruction methods in accordance with standards (e.g., NIST guidelines), including employing cryptographic erasure for data in the cloud so that the deleted data cannot be recovered. Data-in-transit encryption: Using TLS 1.3 protocol for all communications (including logins, transactions, APIs) to protect the data during transmission. Server configuration should prevent downgrading to weak encryption protocols. Using SSL/TLS certificate with Extended Validation (EV) and implementing Certificate Authority Authorization (CAA) mechanism as well as Certificate Transparency (CT) to ensure the validity of digital certificates and prevent misuse.

4.1.3 (point 4)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

End-to-End Encryption

26

Cybersecuri- ty Implemen- tation

4.1.4 (point 1)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

End-to-End Encryption

27

Cybersecuri- ty Implemen- tation

4.1.4 (point 1)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Made with FlippingBook Ebook Creator