79
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
4.4.1 Incident Response Phases
1.
Preparation The preparation phase is a critical foundation in the incident response strategy, aimed at building an organization’s initial capability to recognize, respond to, and recover from cyber incidents effectively. In this phase, Providers need to establish an organizational structure, guidance documents, and a reliable coordination framework to be ready for incident dynamics in a swift and structured manner. Key steps in the preparation phase include: a. Developing an Incident Response Plan (IRP) or a comprehensive playbook, which outlines roles, responsibilities, communication protocols, including with authorities and stakeholders, and procedures for handling incidents as a foundation of a reliable cybersecurity strategy. Exchanges may use frameworks such as NIST SP 800-61 or MITRE ATT&CK 11 that offer comprehensive knowledge of hacker tactics and techniques to help detect and mitigate cyber threats. b. C onducting an asset inventory and determining priorities for systems, data, and services that hold strategic value for operational continuity. This is important for determining the urgency level and appropriate response types for various incidents. c. M aintaining accurate, real-time Proof-of-Reserves verified by an independent auditor to ensure consumer confidence during market volatility, validate the solvency of the Provider, and reduce fiat withdrawals driven by panic. d. Providing an emergency buffer fund and implementing withdrawal throttling mechanisms.
11 https://attack.mitre.org/resources/
Made with FlippingBook Ebook Creator