126
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
No Ref
Domain Sub-Domain Technical Checklist
Status
Network Segmentation
32
Cybersecuri- ty Implemen- tation
Implementing network segmentation by dividing the internal network into isolated zones (Internet Zone, Intranet Zone, Extranet Zone) to limit lateral movement of attackers in the event of security breach. Use firewall, IDS/IPS, and DMZ to control traffic between zones and prevent direct access from the internet to the internal network. Clearly separate the development and production environments within the Intranet, and restrict Extranet access to trusted external parties via VPN
4.1.5
Fulfilled Partially Fulfilled Unfulfilled
Description
Network Segmentation
33
Cybersecuri- ty Implemen- tation
4.1.5
Fulfilled Partially Fulfilled Unfulfilled
Description
and identity control (RBAC) with strong authentication and encryption.
Layered Authentication Protocols
34
Cybersecuri- ty Implemen- tation
Requiring Multi-Factor Authentication (MFA) for all user accounts; the MFA feature is activated by default and cannot be disabled by users.
4.1.6 (point 1)
Fulfilled Partially Fulfilled Unfulfilled
Description
Layered Authentication Protocols
35
Cybersecuri- ty Implemen- tation
Providing various MFA methods (e.g., Time-Based One-Time Password (TOTP) via authenticator app, hardware token, or on- device biometrics) to enhance authentication security.
4.1.6
Fulfilled Partially Fulfilled Unfulfilled
Description
Made with FlippingBook Ebook Creator