43
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
a. Security Information and Event Management (SIEM): for centralized log consolidation, correlation, and analysis. b. Intrusion Detection System (IDS): for passively detecting malicious activities or intrusions. c. Intrusion Prevention System (IPS): for actively preventing and automatically blocking identified attacks.
With this approach, Providers do not rely solely on initial authentication, but continuously monitor, verify, and evaluate all activities within the system, in accordance with the basic principle of Zero Trust: “Never trust, always verify.”
4.1.2 Access Control
In the effort to strengthen information security systems, the implementation of strict and structured access control policies is crucial. One effective approach that can be applied is adopting various principles and best practices in user access management. Several key components to consider in access control implementation include user role management, the principle of least privilege, session settings and access request mechanisms, and session management. Below are important points that need to be applied to ensure the system remains secure, controlled, and aligned with information security governance standards:
Made with FlippingBook Ebook Creator