71
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
4.3 Cybersecurity Ancillaries
As exposure to cyber risks increases within the digital asset ecosystem, there is a need for support mechanisms that include training, awareness-building, and collaboration among stakeholders.
4.3.1 Training
Providers must establish a comprehensive and ongoing cybersecurity training program for all personnel, particularly for employees involved in trading systems, digital asset storage, and consumer data management. The training aims to enhance awareness of cyber threats and strengthen capabilities in mitigating risks. In addition, the program is expected to foster a security culture and ensure compliance with applicable regulations such as OJK Regulation, ISO/IEC 27001:2022, and international best practices. Recommended practices in developing training programs include:
1
Development of a comprehensive curriculum a. Create modules covering topics such as identification, best practices in data and digital asset protection, wallet protection, suspicious activity detection, response, and incident recovery. b. P roviders may adopt references from the NIST Cybersecurity Framework, tailored to the characteristics of crypto assets and blockchain technology. c. Special attention should be given to social
engineering to equip Providers’ employees with the understanding to recognize manipulative tactics such as phishing and pretexting. Employees must be able to identify, prevent, and report fraud attempts.
Made with FlippingBook Ebook Creator