Cybersecurity Guideline Digital Financial Asset Trading Pro…

84

Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia

c. Temporary Revocation of Access Rights Disabling user accounts, service accounts, or administrative credentials suspected of being misused or showing abnormal activity. This action is necessary to stop attackers’ access to critical systems. d. Shutting Down Specific Services or Processes For incidents affecting production services, impacted processes or services may be shut down in a controlled manner. Examples include suspending payment systems, public APIs, or cloud-based applications that may be vulnerable to exploitation. e. Internal and External Coordination Clearly communicating information to the internal incident response team, and notifying relevant external stakeholders (including partners, service users, and regulatory authorities if necessary) to ensure that mitigation efforts are coordinated and accountable. f. Logging and Documentation All isolation activities must be thoroughly documented in the incident log, including the time of execution, systems isolated, reason for the action, and responsible personnel. This documentation is essential for audits, post-incident evaluations, and accountability to regulators. By implementing these steps in a disciplined and systematic manner, the spread of the incident can be effectively contained, providing the technical team with the space to conduct further investigation and plan for comprehensive eradication measures.

Made with FlippingBook Ebook Creator