Cybersecurity Guideline Digital Financial Asset Trading Pro…

127

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

No Ref

Domain Sub-Domain Technical Checklist

Status

Layered Authentication Protocols

36

Cybersecuri- ty Implemen- tation

Implementing risk-based adaptive authentication: dynamically assess login risk (e.g., factors such as geolocation, IP address reputation, device type, behavior patterns) and applying additional verification when anomalies are detected (e.g., login from a new location/device). Storing at least 70% of consumer crypto assets in cold wallets (offline) in accordance with regulations, and use hot wallets only for operations with multi- layered authorization such as multi-signature. Incorporating layered security on the wallet system: physical security (e.g., separate devices and secret storage locations), Multi-Party Computation (MPC), isolation (air gap) with HSM, disaster resilience, and strict access and control SOPs for wallets. Ensuring that the wallet management system has a policy engine integrated and properly implemented in the wallet management system.

4.1.6 (point 3)

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Wallet Security

37

Cybersecuri- ty Implemen- tation

4.1.7

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Wallet Security

38

Cybersecuri- ty Implemen- tation

4.1.7

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Wallet Security

39

Cybersecuri- ty Implemen- tation

4.1.7

 Fulfilled  Partially Fulfilled  Unfulfilled

Description

Made with FlippingBook Ebook Creator