68
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
2. Benchmarking with AKD/AK industry standards can be done by: a. Comparing the Providers’ cybersecurity practices with those of the AKD/AK industry and other common practices to identify areas for improvement. b. Participating in AKD/AK industry forums such as FS-ISAC, Indonesia Cyber Security Forum (ICSF), or Computer Security Incident Response Team (CSIRT) to enhance knowledge of effective strategies for addressing cyber threats and to increase collaboration opportunities. 3. Development of improvement plan should be carried out in a structured manner and include both corrective and preventive actions based on risk evaluations, audits, or past security incidents. The plan must contain the details of actions to be taken, a realistic implementation schedule, specific person in charge for each phase, and appropriate budget allocations, including investments in security technology and human resource training. 4. The Continuous Improvement Cycle is an integral part of information security management, aimed at maintaining the relevance and effectiveness of controls in line with dynamic threats and technological evolution. Organizations must formally establish this cycle by ensuring that the evaluation, monitoring, and updating of policies, procedures, and assessment criteria are conducted regularly. These updates should take into account audit findings, security incidents, current cyber threat trends, and technological innovations that could improve efficiency or strengthen system protection. Thus, the continuous improvement cycle serves not only as a response to weaknesses but also as a proactive mechanism to build an adaptive and resilient security posture.
Made with FlippingBook Ebook Creator