86
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
c. Strengthening Configuration and Security Controls Review and reinforce system settings, such as firewall configurations, role-based access control (RBAC), and authentication management. Adjustments should also include improved password policies, activation of multi- factor authentication (MFA), and removal of inactive Before reintegrating systems into the production network, conduct comprehensive validation to ensure no malicious components remain. Testing should include: 1. Full-system scan using Antivirus and Endpoint Detection and Response, 2. File system integrity, 3. Configuration security, 4. Review of logs and SIEM to detect any residual activity. e. Documentation and Audit Trail All eradication activities must be systematically documented as part of the incident log. This includes the time, affected systems, actions taken, responsible personnel, and results of the post-cleanup evaluation. This documentation serves as a crucial reference for post- incident analysis and compliance reporting to authorities. By applying these measures, Providers can ensure that systems are clean, secure, and ready for the next recovery and operational normalization process. accounts and excessive access rights. d. System Health Validation and Testing
Made with FlippingBook Ebook Creator