32
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
OJK Regulation Number 27 of 2024 further elaborates on the implementation of personal data protection that must be carried out by Providers. Article 3 paragraph 2 letter (g) states that Providers must implement personal data protection when conducting trade. Article 119 of Chapter 12 on Personal Data Protection further stipulates that Providers are obligated to maintain the integrity and availability of personal data, transaction data, and financial data under their management from the point of collection until the data is destroyed. Providers also have the obligation to keep consumer data and/or information confidential. Furthermore, crypto assets traded in the Digital Financial Asset Market, as mentioned in Article 8 paragraph 2 letter (k), must consider consumer protection methods and personal data protection. These provisions strengthen the cause for Providers to give greater attention to the implementation of data protection policies within their business operations.
3.2 Principles of Data and Information Security
The systems built and/or used by Providers must adopt the Zero Trust Architecture (ZTA) principle. Under the zero-trust approach, every application user, device, and system must go through a verification process each time they request access. In other words, access is not granted automatically, even if the user or device is already within the internal network 5 . The Zero Trust principle emphasizes Secure by Design , ensuring that security considerations are integrated from the earliest stages of system design rather than being added as a complement, including default system configurations that are inherently set to the most secure state to minimize the risk of negligence or configuration errors.
5 National Institute of Standards and Technology, NIST Special Publication 800‑207 - Zero Trust Architecture
Made with FlippingBook Ebook Creator