Cybersecurity Guideline Digital Financial Asset Trading Pro…

57

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

2. Biometric Authentication

a. Mobile Integration and Device Security: • Application systems must support the integration of biometric authentication, such as facial recognition or fingerprint scanning, as a secondary method or as a substitute for token- based MFA. • Biometric data must be securely stored and processed on-device, utilizing the Trusted Execution Environment (TEE) on Android or the Secure Enclave on iOS devices to prevent exploitation by third-party apps or remote attacks. b. Protection Against Spoofing: B iometric systems must implement liveness detection features to differentiate between genuine biometric inputs and spoofed inputs (such as photos or molds), in order to prevent spoofing and replay attacks.

Made with FlippingBook Ebook Creator