44
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
2. Least Privilege Principle: a. Grant users only the minimum level of access required to perform their duties. b. Conduct periodic audits of access levels to ensure compliance with the least privilege principle. 1. Role-Based Access Control (RBAC): a. Apply RBAC to grant access rights based on the user’s role within the organization. b. Regularly review access rights, roles, and permissions to ensure they align with policy function changes.
3. Access Requests and Approvals: a. Establish policies that cover the steps of access request, review, and approval based on the principle of least privilege and valid operational needs. b. Formulation of policies should include verification of the identity of the requester, assessment of the request’s relevance based on job function, validation by the data or system owner, and thorough logging of all approval histories as part of accountability and audit trails.
Made with FlippingBook Ebook Creator