Cybersecurity Guideline Digital Financial Asset Trading Pro…

47

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

c. Re-Authentication and Step-Up Authentication For access to data or privileged functions, the system must enforce re-authentication or step-up authentication. This mechanism requires users to re-authenticate (e.g., re-enter a password, OTP, or use biometric factors) before accessing sensitive resources such as:

• Management of other user accounts. • High-value or critical transactions. • System configuration changes. • Access to logs or encrypted data.

T he purpose of this step is to reverify the user’s identity, especially in long-running sessions, and strengthen access control so that it does not rely solely on initial authentication.

4.1.3 Secure Storage Media

In modern information systems, secure data storage is a vital component in maintaining the confidentiality, integrity, and availability of information. The implementation of secure storage does not rely solely on encryption technology but also includes access management, operational oversight, and robust policies and procedures. Data storage security strategies must be designed comprehensively by considering the following key aspects:

Made with FlippingBook Ebook Creator