Cybersecurity Guideline Digital Financial Asset Trading Pro…

49

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

3. Access Audit and Logging Activities related to storage media must be auditable and comprehensively monitored, including: a. Implementing a logging system that records user or system identity, access time, type of operation (read, write, delete, modify), as well as IP address or location of each activity. b. Storing logs in a tamper-evident system and integrating them with SIEM for correlation, anomaly detection, and real-time incident reportin.. c. Conducting regular log reviews by an independent team or internal security team to detect potential breaches or suspicious activities. 4. Redundancy and Backup a. The implementation of regular and reliable data backups needs to utilize automated backup systems for critical data. b. Ensuring that the infrastructure of data centers and backup data centers has equivalent configurations, capacity, and security levels (1:1 ratio) to guarantee operational continuity and seamless service recovery in the event of disruptions. c. Conducting regular testing of backup data to ensure that data can be fully recovered. d. Backup data needs to be encrypted to protect against unauthorized access. e. Developing and maintaining data, including procedures to restore data after loss or damage. f. Performing regular recovery simulations to ensure that the staff understand and can efficiently execute recovery procedures.

Made with FlippingBook Ebook Creator