Cybersecurity Guideline Digital Financial Asset Trading Pro…

4

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

Several key strategic substances highlighted in this guideline include: 1. Implementation of the Zero Trust Principle, which eliminates implicit trust within networks and promotes multi-layered authentication systems, device management, and dynamic access policies. 2. Cyber Risk Management based on both national and international frameworks such as ISO, NIST, CSMA BSSN, and CREST, aimed at measuring the cybersecurity maturity level of each Provider. 3. Data and Wallet Protection, through the implementation of cold wallets for the majority of consumer assets and end-to- end encryption using cryptographic algorithms that meet industry standards. 4. Incident Response Plan, developed with principles of effective coordination, swift recovery, and integrated reporting to OJK and all relevant stakeholders. 5. Enhancement of Technical Competence, conducted continuously through intensive training, professional certifications (such as CISA, CISSP, and CISM), and incident simulations to strengthen operational readiness. In addition to these technical substances, the guideline holistically integrates principles of sound information security governance, referencing international best practices while also considering the unique characteristics of Indonesian society within the context of an inclusive digital asset trading ecosystem. It is important to note that in this context, cybersecurity is not merely a technical matter, but an integral part of a comprehensive governance system. Therefore, this guideline emphasizes the importance of security governance, regular maturity assessments, independent audits, human resource capacity-building, and a culture of cybersecurity awareness throughout all levels of the organization. Furthermore, collaboration among regulators, industry actors, associations, academics, and the public serves as a fundamental principle for building strong national cyber resilience. As a regulator, OJK believes that the implementation of this guideline

Made with FlippingBook Ebook Creator