Cybersecurity Guideline Digital Financial Asset Trading Pro…

31

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

The encryption policy must be designed to protect all sensitive data, including consumer identification numbers, personal data, financial information, and data processing results that could lead to the identification of individuals, done using standardized and cryptographic algorithms whose security has been proven. Encryption should apply not only when data is at rest but also when data is in transit. Furthermore, servers storing data must be protected by advanced firewall systems, network segmentation, and intrusion detection mechanisms to prevent both external and internal attacks. Data protection cannot be effective without strict access control management, where only authorized parties with appropriate risk profiles are granted access to specific data. This must be reinforced by the implementation of the least privilege principle, the use of multi-factor authentication (MFA), and the documentation of access logs for audit and investigation purposes. Finally, data storage system security testing and audits must be conducted regularly by both internal teams and independent third parties to ensure that the systems in use comply with AKD/AK industry standards and applicable regulations, including personal data protection policies.

3.1 Data Protection Policy

In today’s digital era, personal data protection is becoming increasingly crucial, considering that the collection and storage of data are generally conducted online. Therefore, compliance with the provisions on personal data protection and privacy, as stipulated in Law Number 27 of 2022 on Personal Data Protection, is imperative. This compliance includes, but is not limited to, determination of the location of personal data storage and the mechanisms for data transfer, both domestically and across borders.

Made with FlippingBook Ebook Creator