Cybersecurity Guideline Digital Financial Asset Trading Pro…

62

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

a. Storage Security and Crypto Asset Protection, including system resilience against private key theft, physical and digital attacks, and control over the software used in wallet management. b. Access Control, both physical and logical, including authentication mechanisms, access segregation, and control over privileged accounts. c. Effectiveness of Backup and Data Recovery Protocols, to ensure service availability and reliability under both normal and incident conditions. The audit must refer to relevant and internationally recognized standards, including: a. ISO/IEC 27001: A global standard for information security management systems (ISMS), covering policies, procedures, and technical controls. b. SOC 2 Type II: An audit standard that evaluates internal controls related to security, availability, processing integrity, confidentiality, and privacy in technology-based service providers. c. Cryptocurrency Security Standard (CCSS): A specialized framework for systems handling crypto assets, focusing on private key security, wallet management, and operational control of digital assets. This audit must be thoroughly documented, and its results submitted to the OJK , either separately or as part of the Annual Report , in accordance with the provisions of OJK Regulation Number 27 of 2024 concerning the Implementation of the Trading of Digital Financial Assets including Crypto Assets. Compliance with this audit process is not only a regulatory obligation but also reflects the providers’ commitment to transparency, security, and consumer protection in the digital financial asset sector.

Made with FlippingBook Ebook Creator