125
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
No Ref
Domain Sub-Domain Technical Checklist
Status
End-to-End Encryption
28
Cybersecuri- ty Implemen- tation
Data-at-rest encryption: Encrypting all stored data (e.g., databases) with strong algorithm (AES-256) so that they data cannot be accessed without the encryption key. Limiting decryption capability only for authorized personnels through role-based access control (RBAC). Encrypted Backup: Conducting routine backups for important data in encrypted form, and storing those backups in a geographically separate Key Management: Utilizing Hardware Security Module (HSM) or Key Management Service (KMS) system to store, rotate, and revoke encryption keys securely and regularly. Data-in-use: Real-time monitoring of access activities on data in use to detect anomalous behavior or unauthorized access, and applying the principles of least- privilege and RBAC to data access during processing. secure location for disaster recovery purposes.
4.1.4 (point 2)
Fulfilled Partially Fulfilled Unfulfilled
Description
End-to-End Encryption
29
Cybersecuri- ty Implemen- tation
4.1.4 (point 2)
Fulfilled Partially Fulfilled Unfulfilled
Description
End-to-End Encryption
30
Cybersecuri- ty Implemen- tation
4.1.4 (point 2)
Fulfilled Partially Fulfilled Unfulfilled
Description
End-to-End Encryption
31
Cybersecuri- ty Implemen- tation
4.1.4 (point 3)
Fulfilled Partially Fulfilled Unfulfilled
Description
Made with FlippingBook Ebook Creator