94
Cybersecurity Guidelines for Digital Financial Asset Trading Providers in Indonesia
Agar strategi keamanan siber dapat dijalankan secara efektif dan berkelanjutan, Penyelenggara harus memastikan alokasi sumber daya yang memadai, baik dalam bentuk teknologi pendukung, personel, maupun pengembangan kapabilitas tim keamanan siber. Ketersediaan dan pemanfaatan sumber daya ini harus dirancang untuk mendukung respons cepat terhadap ancaman, peningkatan efisiensi operasional, serta adaptasi terhadap dinamika ancaman yang terus berkembang. 3. Classification or type of cyber incident (e.g., malware, DDoS, unauthorized access, system failure); 4. Attack vector, such as the affected system, application, or infrastructure component; 5. Initial response carried out by the technical or incident response team; 6. Initial assessment of the impact, risk escalation, and potential losses to operations and user data. This initial notification report is part of the Providers’ incidental reporting responsibility, aimed at enabling fast monitoring and coordination to protect the stability and integrity of the digital financial services sector.
2.
Cyber Incident Report a. T he Cyber Incident Report is another report as referred to in letter h of Article 110 of OJK Regulation Number 27 of 2024; b. Providers must submit the Cyber Incident report no later than 5 (five) working days from the occurrence of the incident.
Made with FlippingBook Ebook Creator