Cybersecurity Guideline Digital Financial Asset Trading Pro…

48

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

1. Security Management a. The data storage environment must be protected with multiple layers of security. This includes the use of servers equipped with firewalls to prevent unauthorized external access and up-to-date antivirus. In addition, data centers must have strict physical security systems to prevent unauthorized physical access. b. Ensure that password hashes are stored separately from other sensitive data to reduce the risk of leakage in the event of a data breach. c. Use dedicated and secure storage mechanisms for sensitive data, while continuing to implement the principle of least privilege. 2. Data Center and Disaster Recovery Center The Data Center and Disaster Recovery Center must be located in Indonesia, with the Disaster Recovery Center situated at least 20 (twenty) kilometers from the location of the Data Center. The use of servers or cloud servers must be with international standard certifications related to information security management systems. If the server or cloud server is provided by a third party, the provider must have an official representative office in Indonesia.

Made with FlippingBook Ebook Creator