Cybersecurity Guideline Digital Financial Asset Trading Pro…

45

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

c. Create periodic access rights review mechanism to identify and revoke no longer relevant or excessive privileges. d. Employ proactive alerting systems that automatically monitor and notify any changes to high-privilege access or roles. e. Centralized and integrated implementation of Identity and Access Management (IAM) enables organizations to manage user identities and access rights consistently across information technology environments, including local systems, cloud, and third-party applications. f. Implementation of Privileged Access Management (PAM) to manage, monitor, and control access to privileged accounts, such as system administrator accounts, database root accounts, or service accounts with access to critical infrastructure and data. g. PAM ensures that access is only granted to authorized parties, for a limited duration, and with full monitoring and logging of every activity performed.

4. Session Management Session Management is a crucial aspect of controlling the security of user access to information systems, particularly in the context of web-based applications, cloud, or digital financial service platforms. Improper session management can create gaps for various types of misuse, such as session hijacking, session fixation, and unauthorized access due to improperly terminated sessions. To mitigate these risks, the comprehensive implementation of user session policies and

Made with FlippingBook Ebook Creator