64
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
b. Information Classification and Protection To prevent misuse by unauthorized parties, Providers must classify public information and confidential information. Information that may increase security risks, such as technical architecture, authentication systems, or details of asset storage infrastructure, must not be publicly published without careful security consideration. c. Incident Response Procedures Providers must have a structured and documented incident response procedure in place, including for scenarios such as: 1. Loss or theft of digital assets , due to cyberattacks or operational errors. 2. Technical disruptions that result in loss of access or harm to consumers. 3. Account misuse by third parties due to negligence or data breaches These procedures must include mitigation steps, reporting to consumers, claim verification, and compensation processes in cases where the Providers are proven to be negligent. Providers must also offer a responsive complaint channel that is integrated with internal audit functions and the legal compliance unit.
Made with FlippingBook Ebook Creator