Cybersecurity Guideline Digital Financial Asset Trading Pro…

56

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

4.1.6 Multi-Layered Authentication Protocol

To strengthen the security posture of systems and protect user accounts, especially those with administrative or sensitive access, a multi-layered authentication protocol must be implemented. Authentication based solely on passwords is no longer sufficient to counter increasingly sophisticated cyber threats. Therefore, organizations must adopt an approach that combines multiple authentication layers to enhance resilience against identity theft, account breaches, and access misuse. MFA must be enforced as a minimum requirement for all user accounts, particularly those with privileged access, system administrator accounts, and service accounts. • MFA must be enabled by default and cannot be deactivated by users, whether during account registration or while logging into the system. TOTP (Time-Based One-Time Password): A time-based one-time code generated by an authenticator app (e.g., Google Authenticator, Microsoft Authenticator, or Authy), with a limited validity period and time synchronization-based validation. • Hardware Token: b. Recommended MFA Methods: • Physical authentication devices such as smartcards that support public cryptography- based authentication. This method is highly effective against software-based attacks such as keyloggers and phishing. 1. M ulti-Factor Authentication (MFA) a. Mandatory Implementation: •

Made with FlippingBook Ebook Creator