127
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
No Ref
Domain Sub-Domain Technical Checklist
Status
Layered Authentication Protocols
36
Cybersecuri- ty Implemen- tation
Implementing risk-based adaptive authentication: dynamically assess login risk (e.g., factors such as geolocation, IP address reputation, device type, behavior patterns) and applying additional verification when anomalies are detected (e.g., login from a new location/device). Storing at least 70% of consumer crypto assets in cold wallets (offline) in accordance with regulations, and use hot wallets only for operations with multi- layered authorization such as multi-signature. Incorporating layered security on the wallet system: physical security (e.g., separate devices and secret storage locations), Multi-Party Computation (MPC), isolation (air gap) with HSM, disaster resilience, and strict access and control SOPs for wallets. Ensuring that the wallet management system has a policy engine integrated and properly implemented in the wallet management system.
4.1.6 (point 3)
Fulfilled Partially Fulfilled Unfulfilled
Description
Wallet Security
37
Cybersecuri- ty Implemen- tation
4.1.7
Fulfilled Partially Fulfilled Unfulfilled
Description
Wallet Security
38
Cybersecuri- ty Implemen- tation
4.1.7
Fulfilled Partially Fulfilled Unfulfilled
Description
Wallet Security
39
Cybersecuri- ty Implemen- tation
4.1.7
Fulfilled Partially Fulfilled Unfulfilled
Description
Made with FlippingBook Ebook Creator