53
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
c. Encrypted Backups Perform data backups using encryption, and store these backups in geographically distributed locations to support disaster recovery and service continuity. d. Key Management Systems (KMS) Use Hardware Security Modules (HSMs) or cloud- based KMS to securely store, rotate, and revoke encryption keys. This process must be conducted in a scheduled and documented way to prevent key leaks or unauthorized usage.
3. Data in Use Data in use refers to data that is actively being processed by applications, users, or systems. This is the most vulnerable stage, as data temporarily appears in plaintext form in memory. a. Real-Time Monitoring and Audit Implement real-time activity monitoring systems to data in use. These systems must be capable of recording, analyzing, and detecting suspicious behaviors such as data manipulation, unauthorized access, or usage outside of policy. b. Strict Access Control Consistently apply the principle of least privilege and RBAC to limit access only to processes and entities with legitimate operational needs during data processing.
Made with FlippingBook Ebook Creator