CYBERSECURITY GUIDELINES FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION (FSTI) PROVIDERS
Supported by:
CYBERSECURITY GUIDELINES FOR FINANCIAL SECTOR TECHNOLOGY INNOVATION (FSTI) PROVIDERS
Supported by:
Cybersecurity Guidelines for FSTI Providers
FOREWORD
Assalamualaikum warahmatullahi wabarakatuh.
We offer our praise and gratitude to God Almighty, for it is by His blessings and grace that the Financial Services Authority has been able to complete the preparation of the Cybersecurity Guidelines for the Financial Sector Technology Innovation (FSTI) Sector in Indonesia. These guidelines are intended to provide an explanation to all FSTI providers regarding the framework and mechanisms for implementing cyber risk management, which includes application of cyber risk management and response to cyber incidents. By applying an effective and responsive cybersecurity framework, it is hoped that a safe, resilient, and trustworthy digital financial ecosystem in the financial services sector can be established. In this highly connected era, data and information stored and interconnected within digital networks and other cyberspace elements have become crucial components in supporting transactions in the financial sector. This connectivity in cyberspace not only offers opportunities for the development of the financial sector but also introduces new risks, namely cyber risks, for the financial sector including the FSTI sector. According to global data, the financial sector was the industry most frequently targeted by cyberattacks in 2023, accounting for 16 percent of all cyber incidents. In addition, the average cost of data breach in the financial sector reached USD 4.35 million, significantly higher than the average
2
Indonesian Financial Services Authority
cost of data breach across all industries (USD 3.92 million). Domestically, the National Cyber and Crypto Agency (BSSN) recorded that Indonesia experienced 361 million cyberattacks in 2023, with the financial sector being the most targeted compared to other sectors. In this regard, the Financial Services Authority recognizes that the financial sector, including the FSTI sector, will continue to be a primary target for cyberattacks and will be highly vulnerable if it does not implement an effective and responsive cybersecurity framework. Therefore, the implementation of a cybersecurity framework in the FSTI sector is crucial, which is hoped to serve as a protective mechanism that can be used to minimize disruptions to the availability, integrity, and confidentiality of data and information managed by FSTI providers in cyberspace. In the context of implementing a cybersecurity framework, this guide provides a mapping of a cybersecurity framework through a multi-aspect approach and layered security strategies, where FSTI provider’s understanding of cyber risks from innovations being carried out is the first and most crucial step in developing and implementing appropriate risk mitigation measures to prevent cyber incidents. The Financial Services Authority also emphasizes the importance of implementing cybersecurity that can be integrated into the innovation life-cycle. This means that the development of innovation using new technology and the implementation of cybersecurity are not mutually exclusive. Through this mechanism, it can
3
Cybersecurity Guidelines for FSTI Providers
be ensured that innovations in the financial sector are secure from the start of their development, considering that FSTI providers have made cybersecurity an integral part of the innovation development process, where risks associated with new and cyber technology can be identified and mitigated before they can give way to cyberattacks. Naturally, all FSTI providers must continuously update their knowledge of the development of cyber threats in cyberspace to develop a cybersecurity framework that meets their needs. All initiatives and efforts by Indonesian Financial Services Authority to enhance cybersecurity in the FSTI sector are aligned with the mandate of Law Number 4 of 2023 concerning the Development and Strengthening of the Financial Sector, which stipulates that one of the principles of the FSTI industry is the implementation of security and reliability of information systems, including cybersecurity. In developing the FSTI sector, the Financial Services Authority cannot go alone without the support and roles of all stakeholders. Therefore, the Financial Services Authority expects support from all parties so that the implementation of the cybersecurity framework in the FSTI sector can be carried out effectively and in harmony with all policies, programs, and expectations of all stakeholders in Indonesia’s financial sector. The Cybersecurity Guidelines for the Financial Sector Technology Innovation Sector in Indonesia is a living document that can be continuously adjusted to developments in the FSTI sector, to produce relevant and credible regulatory responses, provisions, or policies.
4
Indonesian Financial Services Authority
In conclusion, we hope that this guideline will continue to empower the digital ecosystem and strengthen cybersecurity resilience in supporting national economic resilience so that the FSTI sector can continue to grow and contribute optimally to inclusive, sustainable, and equitable national economic growth.
Wassalamu’alaikum warahmatullahi wabarakatuh.
Hasan Fawzi Chief Executive of The Financial Sector of Technology Innovation, Digital Financial Assets, and Crypto Assets Supervision and Member of The Board of Commissioners of Indonesian Financial Services Authority
5
Cybersecurity Guidelines for FSTI Providers
Table of Content
Chapter 1 - INTRODUCTION 1.1. Background 1.2. Purpose 1.3. Scope
8 10 11 13 14 17 17
Chapter 2 - URGENCY OF CYBERSECURITY 2.1. Threat Aspects 2.2. Types of Cyber Threats
20 22 24 24 29 31 40 42 45 47 50 52 56 57 58 59 60
Chapter 3 - DATA PROTECTION 3.1. Data Protection Policy 3.2. Information Security Principles 3.2.1 Confidentiality 3.2.2 Integrity 3.2.3 Availability Chapter 4 - RISK MANAGEMENT 4.1. Risk Assessment 4.2. Risk Mitigation 4.3. Risk Treatment Chapter 5 - INCIDENT RESPONSE 5.1. Preparation 5.2. Detection and Analysis 5.3. Containment 5.4. Eradication 5.5. Recovery 5.6. Post-Incident Activities
6
Indonesian Financial Services Authority
Chapter 6 - ASSESSMENT OF
62
CYBERSECURITY MATURITY
70 72 74 76
Chapter 7 - CYBERSECURITY SUPPORTS 7.1. Training 7.2. Increasing Awareness 7.3. Collaboration
Bab 8 - CONCLUSION
78
Bab 9 - APPENDIX 9.1
82
Glosarium: Definition of Key Terms and Acronyms in Cybersecurity Sources: List of Sources, Tools, and Cybersecurity Services
84
9.2
88 89 96
9.3 9.4
Essential Cybersecurity Measures Advanced Cybersecurity Measures
CYBERSECURITY CODE OF CONDUCT
102
CONTACT PERSON
116
Disclaimer
1.
These guidelines provide general guidance and are not intended to replace the provisions of applicable laws and regulations. They should be read in conjunction with the relevant laws, regulations, and other guidelines issued by OJK or other regulatory bodies. The products or services mentioned in this document are not endorsements of those products or services. Rather, they are used as examples of commonly used practices.
2.
Matters relating to crypto assets will be regulated in separate guidelines.
3.
7
Cybersecurity Guidelines for FSTI Providers
01 Introduction
8
Indonesian Financial Services Authority
9
Cybersecurity Guidelines for FSTI Providers
Introduction 01
1.1. Background
Cybersecurity has become a major concern among Financial Services Industry actors. Article 215 of Law Number 4 of 2023 on the Development and Strengthening of the Financial Sector (UUP2SK) stipulates that one of the principles of the Financial Sector Technology Innovation (FSTI) industry is implementing the security and reliability of information systems, including cybersecurity resilience. The Financial Services Authority Regulation (POJK) Number 3 of 2024 on the Implementation of Financial Sector Technology Innovation also emphasizes the importance of cybersecurity and cyber resilience. Therefore, Cybersecurity Guidelines The cybersecurity landscape in Indonesia is rapidly evolving, driven by the increasing use of technology in the financial services sector. The Financial Sector Technology Innovation (FSTI) industry also continues to develop significantly, creating new innovations and technology. However, this development also brings cybersecurity challenges, including the risk of cyberattacks, data breaches, and other illegal activities.
10
Indonesian Financial Services Authority
for FSTI Providers are needed to enhance understanding and awareness among stakeholders. FSTI is defined as technology-based innovations that impact products, activities, services, and business models within the digital financial ecosystem of FSTI providers. In this context, FSTI does not include digital assets and crypto assets. These guidelines provide a risk management framework to encourage a balanced ecosystem
between innovation development and consumer protection. To achieve this, several key steps must be taken. First, FSTI Providers need to implement cybersecurity guidelines. Second, ensuring that cybersecurity practices are integrated and not overlooked in the development of innovations. Lastly, it is important to keep up with technological advancements and update these guidelines to benefit consumers and the FSTI industry.
1.2. Purpose
The cybersecurity guidelines establish a framework to ensure the security and integrity of technology-based innovations in the FSTI industry, encompassing prevention strategies, cybersecurity management, risk assessment, and incident response.
11
Cybersecurity Guidelines for FSTI Providers
The general purposes of these guidelines are:
Provide guidance for FSTI Providers: To protect personal information/data, maintain the integrity of financial transactions, and build consumer trust.
Address vulnerabilities: To encourage FSTI Providers to understand and address any identified threats, as well as provide a comprehensive framework for addressing such threats.
Increase management awareness: To ensure that management understands the importance of cybersecurity and receives adequate information to take proactive measures and make strategic decisions in strengthening FSTI Provider’s cyber resilience.
Increase audit and risk management awareness: To provide the necessary information for developing, assessing, and enhancing cybersecurity protocols.
12
Indonesian Financial Services Authority
1.3. Scope
These guidelines provide a framework for FSTI Providers, encompassing data protection, risk management, incident response, maturity assessment, and employee training, while taking into account gender equality and social inclusion in their implementation.
The scope of the industry or business models of FSTI Providers includes, among others:
Aggregators
are Websites or Applications that assist customers in obtaining information about financial products and services by collecting information, filtering, and comparing products and services from various Financial Services Institutions (LJK) digitally.
Innovative Credit Scoring (ICS)
Institutions or entities that process data, other than credit data and its derivatives, using specific algorithms through information technology (IT) to generate a score or rating that indicates assessment of the eligibility of a person to receive services in the Financial Services sector.
13
Cybersecurity Guidelines for FSTI Providers
02 Urgency of Cybersecurity
14
Indonesian Financial Services Authority
15
Cybersecurity Guidelines for FSTI Providers
Urgency of Cybersecurity 02
The urgency of cybersecurity is needed to anticipate threats and cyberattacks, requiring readiness and agility in facing attacks and the ability to recover from the cyberattacks.
Cybersecurity is the condition of maintaining the confidentiality, integrity, and availability of information and/or information systems interconnected through cyber media from cyberattacks. Cybersecurity can also encompass other aspects such as authenticity, accountability, non- repudiation, and reliability.
continuity by taking anticipatory, adaptive, and proactive measures against cyber threats. FSTI Providers are required not only to protect their electronic systems from cyberattacks but also to possess the ability to detect and recover from cyber incidents. FSTI Providers also need to monitor cyber incidents as a form of communication to stakeholders about their cybersecurity resilience and security.
Cyber resilience refers to the ability of FSTI Providers to maintain their business
16
Indonesian Financial Services Authority
2.1 Threat Aspects
Threat aspects are everything underlying cyber threats and attacks, including Ideological, Political, Economic, Social, Cultural, National, Military, Scientific, Financial, Technological, and other
aspects related to life as a nation, state, and society, including personal interests.
2.2. Types of Cyber Threats Cyber threats can take various forms, including:
1. Malware
2. Ransomware
Malware is software with features or capabilities that has the potential to disrupt an information system. The disruption may cause direct or indirect harm to the information system owner.
Ransomware is a type of malware that encrypts the victim’s files and demands a ransom for decrypting the file. Ransomware can cause significant financial loss to individuals and organizations.
17
Cybersecurity Guidelines for FSTI Providers
4. Denial of Services (DoS) dan Distributed Denial of Services (DDos)
3. Web Defacement
Web defacement is an attack on a website carried out by altering or modifying its content so that the website’s content conforms to the attacker’s desire.
DoS and DDoS attacks aim to disrupt the availability of an electronic system in processing transactions or authorized access by making it so that the network or system capacity seems full due to a large volume of access requests.
5. Phishing
Phishing is a deceptive technique aimed at obtaining personal or sensitive information, such as login credentials, financial data, or other personal information. This is usually done through emails, text messages, or fake websites that mimic legitimate ones.
6. Social Engineering
Social Engineering constitutes psychological manipulation to trick victims into taking actions that endanger themselves or others. Examples include clicking malicious links, providing sensitive information, or transferring money.
18
Indonesian Financial Services Authority
7. Man-in-the-Middle (MitM)
8. Zero-Day Attack
Man-in-the-Middle (MitM) is an attack that intercepts communication between two parties and impersonates one of them. MitM can be used to steal data, alter messages, or disrupt communication.
Zero-Day Attack exploits software vulnerabilities that are unknown to the developers. This attack is harder to detect and prevent as there are no available patches to address them.
9. Cyber Espionage
10. Supply Chain Attack
Cyber Espionage is the theft of confidential or sensitive information, such as business data, government data, or trade secrets. It is often carried out by state- sponsored hackers or criminal organizations.
Supply Chain Attack targets third- party suppliers to gain access to larger organizational systems or data. This attack can be very dangerous as it can affect multiple organizations simultaneously.
11. Credential Stuffing
Credential Stuffing is an attack that uses illegally obtained credentials, such as usernames and passwords, to access online accounts. These credentials can be obtained through phishing, data breaches, or malware.
Cyberattacks are not limited to the examples above. FSTI Providers must continuously update their security measures of the ever-evolving cyber threats.
19
Cybersecurity Guidelines for FSTI Providers
03 Data Protection
20
Indonesian Financial Services Authority
21
Cybersecurity Guidelines for FSTI Providers
Data Protection 03
Data protection policy includes data encryption, secure data storage, and access controls. Data encryption security is intended for all sensitive information/data, such as credit card numbers, banking details, personal identification data, using strong cryptographic algorithms. Along with encryption, secure data storage must be supported by installing firewalled servers to ensure the data is protected from cyberattacks and other potential security threats. Data protection procedures must also be equipped with strict access controls in place to prevent unauthorised data access. It is also crucial to regularly test and audit the secure data storage to ensure that FSTI Providers meet the highest security standards. 3.1. Data Protection Policy Having a comprehensive data protection policy is crucial for the cybersecurity efforts of FSTI Providers for several reasons: 1. Safeguarding sensitive data FSTI Providers handle a significant amount of sensitive data. Data protection policy ensures that data is encrypted and stored securely, and accessible only to authorised personnel. FSTI Providers can implement strong encryption standards like AES-256 or at least AES-128 as recommended by the National Cyber and Crypto Agency (BSSN).
22
Indonesian Financial Services Authority
2. Compliance with regulations Indonesia has various laws and regulations related to data protection and cybersecurity, such as the Personal Data Protection Act (PDP Act), OJK Regulations, and other regulations. FSTI Providers must comply with related regulations in implementing these guidelines to avoid potential penalties and reputational damage. 3. Building trust with customers Implementing data protection policy and communicating it clearly to customers to build trust in the services provided. 4. Mitigating cyber risks A data protection policy that includes regular security assessment, updates to encryption methods, and secure access controls helps FSTI Providers mitigate these risks and protect data against potential cyber-attacks. 5. Enabling secure collaboration In the event that FSTI Providers collaborate with other entities, such as banks in processing payments or third-party service providers, a robust data protection policy is required to ensure that data shared with these partners is encrypted. 6. Fostering innovation and growth FSTI Providers must promote innovation and growth by prioritizing data protection and cybersecurity to maintain their customers’ and stakeholders’ trust.
23
Cybersecurity Guidelines for FSTI Providers
3.2. Information Security Principles
The fundamental framework to safeguard information security covers Confidentiality, Integrity, and Availability (CIA).
3.2.1. Confidentiality
All sensitive data should be encrypted using advanced cryptographic standards to ensure that data remains secure even if accessed by unauthorised entities. FSTI Providers implement strong encryption standard AES-256 1 or at least AES-128 as recommended by the National Cyber and Crypto Agency (BSSN).
1.
Encryption
a) Encryption Standards - Encryption data at rest using industry-standard algorithms such as AES (Advanced Encryption Standard) AES-128 as per the minimum recommendation by BSSN. Employ TLS 1.2 or higher for encrypting data in transit to ensure secure data exchange between clients and servers. 2 b) Encryption Implementation - Apply encryption to all sensitive data, including personal identification information, transaction details, and financial records. - Ensure that encryption keys are securely managed, with key generation, distribution, storage, rotation, and destruction procedures in place to prevent unauthorised access.
1 Advanced Encryption Standard (AES), https://www.techtarget.com/searchsecurity/definition/ Advanced-Encryption-Standard 2 Advanced Encryption Standard (AES) - National Institute of Standards and Technology (NIST), https:// www.nist.gov/publications/advanced-encryption-standard-aes
24
Indonesian Financial Services Authority
c) End-to-End Encryption - Implement end-to-end encryption (E2EE) 3 for all data exchanges within the network and with external entities to ensure that data is encrypted from the point of origin to the point of destination, limiting access even in transit.
2.
Secure Storage Solutions
Data storage environments must be secured with multiple layers of protection that includes the deployment of firewall servers and strict physical security measures.
3.
Authentication and Access Controls
Implementing robust authentication mechanisms is essential to verifying the identity of users accessing data. Multi-factor Authentication (MFA) should be employed to add an extra layer of security. Additionally, password policies should enforce strong, unique passwords that are regularly updated during both database storage and login processes.
3 Encryption end-to-end encryption (E2EE), https://www.techtarget.com/searchsecurity/definition/ end-to-end-encryption-E2EE
25
Cybersecurity Guidelines for FSTI Providers
a) Authentication or hashing password
•
Hashing Password: - Use strong cryptographic hashing algorithms (e.g., bcrypt, Argon2, PBKDF2) to hash passwords before storing them in the database, ensuring that the actual passwords cannot be easily recovered even if the database is compromised. - Implement a salt mechanism to add random data to each password before hashing. This prevents hackers from using precomputed tables (rainbow tables) to crack the hashes. Masking Passwords in User Interfaces: - Always display passwords as asterisks (*) or dots (•) during login and registration. - Provide an option to show or hide the password to balance usability and security, but ensure the default state is hidden. Secure Transmission of Passwords: - Use Hypertext Transfer Protocol Secure (HTTPS) to encrypt data transmitted between client and server, ensuring that passwords are protected during transit. - Implement additional measures like HTTP Strict Transport Security (HSTS) to force secure connections.
•
•
26
Indonesian Financial Services Authority
•
Password Policy Enforcement - Enforce strong password requirements, including a minimum length, a mix of uppercase and lowercase letters, numbers, and special characters. - Implement rate limiting and account lockout mechanisms to protect against brute force attacks Regularly Update Hashing Algorithms - Periodically review and update the hashing algorithms used to ensure they remain secure against evolving threats. - Implement a system to rehash existing passwords with stronger algorithms when users log in or change their passwords. Store Passwords Separately from Other Data - Ensure that password hashes are stored separately from other sensitive data to reduce the risk of exposure in case of a data breach. - Use dedicated and secure storage mechanisms for password data Secure Password Reset Processes - Implement secure password reset mechanisms that do not expose or transmit the current password. Instead, use temporary tokens or links sent via email. - Ensure that reset tokens are time-limited and can only be used once. -
•
•
•
27
Cybersecurity Guidelines for FSTI Providers
b) Access Control Mechanisms
•
Role-Based Access Control (RBAC): - Implement RBAC to assign rights based on the user’s role within the organisation. - Regularly review and update role definitions and access permissions to reflect changes in job functions. Least Privilege Principle: - Grant users the minimum level of access according to roles and responsibilities in carrying out their job duties. - Regularly audit access levels to ensure compliance with the least privilege principle. Access Requests and Approvals - Establish a formal process for requesting, reviewing, and approving access to sensitive systems and data. - Maintain detailed logs of access requests and approvals for audit purposes. Session Management - Implement automatic session timeouts after a period of user’s inactivity to prevent unauthorised access. - Use secure methods to manage session tokens and ensure they are invalidated upon logout .
•
•
•
28
Indonesian Financial Services Authority
Security Assessment 4 - Conduct annual security assessments to assess and evaluate the effectiveness of the encryption measures implemented. - Update encryption methods as needed to address new vulnerabilities and to align with updated security standards and best practices. 4.
3.2.2. Integrity
1.
Documentation and Audit
- Maintain logs of all data disposal activities, detailing the method of destruction, the person responsible, and the date of destruction. - Regularly review and audit data retention and disposal practices effectively while complying with the applicable policies and regulations.
2.
Privacy by Design
- Ensure that the personal data protection principle is incorporated into system architecture design and business processes as an integral part of the data lifecycle, from collection to disposal.
4 See the Risk Assessment section in Chapter 4.
29
Cybersecurity Guidelines for FSTI Providers
3.
Secure Storage Solutions and Access Controls - Data storage environments must be secured with multiple layers of protection that includes the deployment of firewalled servers and strict physical security measures to prevent unauthorised access. - Implement robust access control mechanisms to ensure that only authorised personnel can access sensitive data. Access control mechanisms based on international standards include: multi-factor authentication (MFA), role-based access control (RBAC), and the principle of least privilege (PoLP). 5
4.
Training and Awareness
- Training comprises an explanation of the significance of data protection, focusing on proper handling, retention, and disposal of sensitive information. - Update training materials regularly to cover new regulatory changes, technological advancements, and emerging threats that impact data protection.
5 A Balanced Approach to Permission Control. https://www.doc-elite.co.uk/post/a-balanced-approach- to-permission-control-1
30
Indonesian Financial Services Authority
3.2.3. Availability
1.
Data Retention Mechanisms
In terms of data retention, FSTI Providers are required to adhere to the following:
a) Data Retention Policy
- Establish a retention period policy according to the data category and type, such as transaction records, customer identification documents, and communication logs, each adhering to specific legal requirements. - Regularly update the retention policy according to the new regulatory changes applicable in Indonesia. - Data storage, data retention, and data destruction may refer to Law Number 43 of 2009 on Archives and/or Law No. 27 of 2022 on Personal Data Protection. - Below are specific guidelines for different types of data referring to the European Union GDPR 6 :
6 GDPR - General Data Protection Regulation: Regulations concerning data protection and privacy in the European Union and the European Economic Area.
31
Cybersecurity Guidelines for FSTI Providers
a. Personal Identity Information Retention Period:
Employment Records: Duration of employment + 7 years
Customer Records: Duration of the customer relationship + 5 years.
Conditions: - Ensure retention period compliance with the applicable laws. - Implement secure deletion of personal identity information after the retention period unless required for ongoing legal proceedings.
b. Financial Records Retention Period:
Tax Records:
Audit Records:
General Accounting Records:
Retain for 7 years from the date of filing.
Retain for 7 years from the completion of the audit.
Retain for 7 years
Conditions: - Ensure retention periods comply with the applicable tax regulations and other relevant regulations. - Store and protect financial records with strong access controls.
32
Indonesian Financial Services Authority
c. Customer Transaction Data Retention Period:
Transaction Records: Retain for 5 years from the date of the transaction.
Credit Card Information: Retain only as long as necessary for the transaction processing and dispute resolution, typically no more than 90 days.
Conditions: - Comply with Payment Card Industry Data Security Standard (PCI DSS) for handling and storage of credit card information. - Implement secure deletion processes for personal identity information after the retention period.
d. Business Communications Retention Period:
Emails: Retain for 3 years.
Instant Messaging & Chat Log: Retain for 1 year.
Conditions: - Ensure compliance with applicable regulations related to the retention of business communications. - Ensure secure retention of business communication data to protect against unauthorised access and ensure data integrity.
33
Cybersecurity Guidelines for FSTI Providers
e. Operational Data Retention Period:
Log System:
Project Documentation: Retain for the duration of the project + 3 years.
Retain for 1 year.
Conditions: - Ensure operational data is retained long enough to support business continuity and disaster recovery efforts. - Regularly review and update retention policies according to the changes in the applicable regulations in Indonesia.
In addition to the data retention reference above, the following are recommended best practices for FSTI Providers:
- Conduct periodic risk assessments to evaluate if retention periods need to be extended based on emerging risks. - Implement data minimisation techniques to only collect and retain necessary data. - For Innovative Credit Scoring (ICS) providers, anonymise non-financial data used in credit models after the retention period. - For InsurTech providers, consult industry-specific data retention regulations.
34
Indonesian Financial Services Authority
2.
Secure Data Disposal
- Establish and ensure secure destruction procedures for data that is no longer needed or has passed the retention period. - Delete data securely from the retention devices using methods such as data wiping, degaussing (removal of magnetic storage media, such as: hard disk or flash disk destruction), or physical destruction.
3. Backup and Recovery Data
Back-up Integrity: - Regularly test backup integrity to ensure that data can be successfully restored. - Use encryption to protect backup data from unauthorised access. Recovery Planning: - Develop and establish detailed data recovery plans that outline the procedures for restoring data. - Conduct regular data recovery drills to ensure personnel are familiar with data recovery procedures and can execute them efficiently. Regular Back-up: - Implement a robust data backup strategy, including periodic and automated backups for all critical data. - Store backups in multiple locations, including both on-site and off- site facilities, to mitigate the risk of data loss due to local disasters.
35
Cybersecurity Guidelines for FSTI Providers
4. Data Centre
Failover Systems: - Deploy failover systems to automatically switch to a backup system in the event of a primary system failure. - Ensure that failover systems are tested regularly to verify their effectiveness. Redundancy: - Implement redundancy measures in data centres, including alternative power supplies. - Utilise Redundant Array of Independent Disks (RAID) configurations to protect against data loss due to disk failures. Security and Maintenance: - Conduct regular security audits to identify and address vulnerabilities in data centre infrastructure. - Implement automated updates for all software, including virus definitions and firewall configurations, to protect against emerging threats.
Location: - Data Centre (DC) are required to be located in Indonesia.
36
Indonesian Financial Services Authority
5.
Data Recovery Centre
- Data recovery centres are established in different locations with a minimum distance of 35 km from the data centre and must consider different geographical areas (for example: not located within the area with the same potential disaster impacts) to ensure that data can be restored even if a regional disaster occurs. - Ensure that data recovery centres are equipped with the necessary infrastructure to support proper data restoration. - Data recovery centres are required to be located in Indonesia.
The following must be put into consideration in establishing data recovery centres:
a. Synchronisation: - Regularly synchronise data between primary data centres and recovery centres to ensure that the most current data is available for recovery. - Use real-time replication technologies where possible to minimise data loss in the event of a failure. b. Disaster Recovery Testing: - Conduct regular disaster recovery tests (e.g. every semester or year) to validate the effectiveness of recovery processes and infrastructure. - Document and review test results to identify areas for improvement and ensure compliance with recovery objectives.
37
Cybersecurity Guidelines for FSTI Providers
6.
Cloud Use
If FSTI Providers use cloud provider services, data centres and data recovery centres also refer to points 4 and 5 above.
7. Business Continuity Plans
a. Comprehensive Policy: - Possess comprehensive policies related to Business Continuity Plans (BCPs) that cover business impact analysis, business continuity management, and recovery strategy including all critical aspects of operations, such as IT systems, management roles, personnel, and communication strategies. - Ensure that BCPs are regularly updated to reflect changes in business processes, technologies, and internal/external threats. b. Training and Awareness - Provide annual training to employees on their roles and responsibilities in executing the business continuity plan. - Conduct awareness programs to ensure that all staff understand the importance of business continuity and their part in maintaining it. - Undertake annual review and improve business continuity plans based on lessons learned from drills, real incidents, and changes in the business environment. - Engage with stakeholders to ensure BCPs align with organisational goals and regulatory requirements. c. Continuous Improvement:
38
Indonesian Financial Services Authority
39
Cybersecurity Guidelines for FSTI Providers
Risk Management 04
40
Indonesian Financial Services Authority
41
Cybersecurity Guidelines for FSTI Providers
Risk Management 04
Risk management is a multifaceted process that involves identifying, assessing, and mitigating cybersecurity risks to protect sensitive information/data and maintain the integrity of financial transactions. This process is crucial in ensuring the security and stability of FSTI Providers.
4.1. Risk Assessment
This assessment is necessary to identify potential cybersecurity threats and vulnerabilities that are specific to FSTI Providers’ operations.
The first step in managing cybersecurity risks is to conduct a risk assessment. This process involves identifying potential vulnerabilities that could compromise the confidentiality, integrity, and availability of financial data. FSTI Providers can use various techniques, such as vulnerability assessment, penetration testing, and risk modelling, to identify and prioritise risks based on their likelihood and potential impact.
42
Indonesian Financial Services Authority
Measures that can be taken during the risk assessment process are as follows:
1. Vulnerability Assessment a. Establish a recurring schedule for vulnerability assessments. Ideally, assessment should be performed quarterly and after any significant changes to infrastructure, such as system updates, new service rollouts, or integration of new hardware or software. b. Tailor the policy based on the vulnerability assessment results to match the specific architecture of FSTI Provider’s networks and systems, including setting the depth of assessments and the aggressiveness of tests.
2. Risk Modelling Techniques Apply quantitative and qualitative risk assessment models to evaluate the potential impact of threats. The following are feasible techniques: a. Use ISO 27001 as the assessment framework in FSTI Provider’s risk modelling technique. b. Integrate risk modelling into business decision-making processes. c. Use the outcomes from risk modelling to influence policy changes, security enhancements, and strategic planning.
43
Cybersecurity Guidelines for FSTI Providers
3. Regular Compliance Checks a. Continuously monitor regulatory updates to ensure compliance with applicable laws and regulations. b. FSTI Providers can utilise any means/tools to assist them in tracking real-time compliance status with applicable laws and standards, such as Microsoft Compliance Manager 7 . c. Conduct regular meetings with key stakeholders, including compliance officers, IT security teams, and business unit leaders, to evaluate compliance status and discuss needed improvements. d. Incorporate compliance checks into software development lifecycle (SDLC). Ensure that every new release complies with relevant regulations.
4. Penetration Test a. Arrange for penetration testing by external cybersecurity experts annually or after significant network changes or critical infrastructure deployment. b. In addition to regular schedules, conduct ad-hoc penetration tests in response to new threats or after deploying new infrastructure or applications. c. Use the results from penetration testing to address vulnerabilities promptly.
7 Microsoft Purview Compliance Manager, https://learn.microsoft.com/en-us/purview/compliance- manager
44
Indonesian Financial Services Authority
4.2. Risk Mitigation Strategies for mitigating cybersecurity risks, including the use of security controls, regular security audits, and employee training programs. To ensure the safety of sensitive data and prevent unauthorised access, security controls such as firewalls, encryption, and access controls should be set up. Regular security audits and penetration testing can help identify and address vulnerabilities.
1. Enhance Security Controls
a. Deploy advanced security solutions like next-generation firewalls, intrusion prevention systems (IPS), intrusion detection systems (IDS), and endpoint detection and response (EDR). b. Deploy encryption for data at rest and data in transit.
2. Regular Security Audits
a. Schedule regular audits internally and/or external auditors to ensure all systems and controls are up to standard. b. Conduct internal audits at least annually to review security policies, access controls, and compliance with relevant regulations. c. Engage with third-party auditors annually to perform comprehensive external audits. These auditors may provide an objective review of security practices and compare them against applicable standards and regulations.
45
Cybersecurity Guidelines for FSTI Providers
3. Employee Training Program
a. Hire employees with cybersecurity expertise. b. Develop cybersecurity training for all employees which focuses on topics such as phishing, secure password practices, and secure handling of sensitive information. c. Regularly update training content to address new cybersecurity threats.
4. Implement an Incident Response Plan
Establish a clear incident response plan that includes immediate steps for containment and eradication of cyber threats, build internal and external communication strategies (including OJK and/or other relevant authorities), and prepare recovery plans to resume business operations.
46
Indonesian Financial Services Authority
4.3. Risk Treatment FSTI Provider’s action towards risk assessment and risk mitigation involves a structured approach to addressing identified risks, including selecting appropriate risk treatment options, implementing security measures, and continuously monitoring the effectiveness of the security measures.
1. Risk Treatment Options
a) Risk Avoidance Implement strategies to avoid activities that introduce unacceptable risks. For instance, avoid using outdated software known to have vulnerabilities. b) Risk Reduction Apply security controls and measures to reduce the likelihood and impact of identified risks, including enhancing security controls, conducting regular audits, and training employees. c) Risk Sharing Transfer or share the risk with other parties. Risk sharing could involve outsourcing certain functions to specialised cybersecurity firms or purchasing cyber insurance to cover potential losses from incidents. d) Risk Acceptance Accept the risk when the cost of risk mitigation exceeds the potential impact. Risk acceptance should be based on a clear understanding of the potential impact and losses.
47
Cybersecurity Guidelines for FSTI Providers
2. Security Measures/Tools
a) Deploy advanced security measures, such as multi-factor authentication, data encryption, and secure coding practices to mitigate identified risks. b) Utilise automated monitoring tools to track and analyse network traffic and system activities for signs of potential threats. c) Develop and implement a robust incident response plan that includes specific actions for detecting, containing, eradicating, and recovering from security incidents. d) Ensure third-party vendors comply with FSTI Provider’s security policies and are willing to undergo inspection by OJK if necessary. Regularly, FSTI Providers assess their security posture to mitigate supply chain risks.
3. Regular Monitoring and Review
a) Conduct regular risk assessments to identify new risks and re-evaluate existing risks. b) Conduct annual reviews of the effectiveness of risk treatment measures through audits, penetration tests, and vulnerability assessments.
c) Provide feedback based on lessons learned from past incidents and update the risk management processes. d) Regularly monitor compliance with industry standards and applicable regulations.
48
Indonesian Financial Services Authority
4.
Action Plan Implementation
a) Prioritise risks based on their potential impact and likelihood, and focus on deploying resources to the most critical areas. b) Allocate necessary resources, including budget, personnel, and technology, to implement risk treatment measures effectively. c) Timeline: develop a clear timeline, with milestones and deadlines in risk treatment measures. d) Develop and assign clear responsibilities to specific teams to monitor risk treatment measures.
5.
Reporting and Communication
a) Establish regular reporting mechanisms to inform management and stakeholders about the status of risk treatment efforts. b) Communicate with relevant authorities, customers, and other external stakeholders about FSTI Provider’s risk treatment strategies. c) Ensure transparency in risk management practices to build stakeholders’ trust.
By following this structured approach to risk treatment, FSTI Providers can effectively address identified risks, enhance their cybersecurity posture, and ensure the safety and integrity of their operations.
49
05 Incident Response
Cybersecurity Guidelines for FSTI Providers
Incident Response 05
Having a robust incident response strategy is key to organizing the Technological Innovation in the Financial Sector (FSTI) to deal with cybersecurity challenges. The plan should include effective steps for promptly detecting, evaluating, and handling cyber incidents quickly and effectively. Detecting incidents early allows companies to act fast, mitigate the damage and prevent further problem escalation. Moreover, immediate reporting to the Authority and the stakeholders shows a commitment to transparency and regulation compliance. A quick and effective response does not not only help in minimizing the operational downtime but also minimizing the financial loss resulting from security incidents. Below are general phases in structuring an incident response plan:
5.1. Preparation
The preparation phase in the incident response is one of the foundations to deal with incidents effectively. At this stage, FSTI Providers need to establish a platform to manage the incidents. Key steps include:
52
Indonesian Financial Services Authority
1. Assembling the Incident Response Plan (IRP), including description of roles, responsibilities, and communication protocols with the authority and stakeholders, as well as the procedures for handling incidents as a robust cornerstone of cybersecurity strategy.
2. Identifying critical assets and prioritizing system and data is crucial for the operation of the organization.
3. Creating an effective and responsible incident response team. The incident response team must consist of members from various departments to ensure a well-rounded approach to incident management.
4. Routine training for the incident response team related to incident response plan, security tools and incident handling procedures.
5. Executing escalation and reporting on cyber incidents to OJK or related authorities in accordance with the defined communication channel.
53
Cybersecurity Guidelines for FSTI Providers
Clear definition of roles and responsibilities of each personnel is key to ensure the effective and efficient functioning of the incident response team. Each member should have a precise understanding of the tasks during the different phases of incident management. The functions and responsibilities of the incident response team are described in the table below:
IT Security Personnel:
1.
Responsible for the technical management of the incident by employing their expertise.
2.
Monitor systems for signs of compromise.
3.
Perform initial detection upon incident occurrence.
4.
Perform containment and eradication of the threat.
5.
Perform the recovery process.
Legal Team:
1.
Ensure that the incident response activities comply with applicable laws.
2.
Handle any legal fallout.
3.
Provide advice on reporting obligations.
4.
Interact with law enforcement if necessary.
54
Indonesian Financial Services Authority
Communication Specialists:
1.
Handle internal and external communication.
2.
Crafting messages that inform stakeholders without causing undue alarm.
3.
Establish communication protocols for timely dissemination of information to employees, customers, partners, and the media.
4.
Manage crisis communications to maintain public trust.
Human Resources Department:
1.
Manage any employee-related issues that arise during the incident, such as potential insider threat or the dissemination of information about the incident within the company.
2.
Maintain confidentiality as required during investigations.
Senior Management:
1.
Provide oversight and make critical decisions such as financial decisions.
2.
Maintain involvement with the clients and stakeholders during the occurrence of incidents.
3.
Ensure that the incident response efforts align with the FSTI Provider’s strategic objectives.
55
Cybersecurity Guidelines for FSTI Providers
5.2. Detection and Analysis
The detection and analysis in incident response is a key step to identify and understand thoroughly cybersecurity event potentials, among others:
1.
Use a detection tool like Security Information and Event Management (SIEM) system to monitor activities to detect suspicious behavior or incident potentials. Things to pay attention to:
·
Integrate SIEM system with existing security tools and IT infrastructure (firewall, router, antivirus, etc.) to connect data to recognize anomalous patterns related to malicious activities. Ensure the SIEM system provides real-time analysis and visualization of security data, enabling rapid incident detection and alarm the security team through email, SMS, and other communication channels.
·
2.
Analyze system log and security alarm to detect indications of intrusion or unauthorized activities. Define scope and impact of the detected incident, including evaluating affected systems and estimating damage potentials resulting from it. Implement automatic response protocol for low-level threats, such as temporary blocking of suspicious Internet Protocol.
3.
4.
5.
Perform check and update regularly. Things to note:
·
Regular check to ensure that all security tools function correctly with the latest threat definition and patch.
·
Regular SIEM update.
56
Page 1 Page 2 Page 3 Page 4 Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 13 Page 14 Page 15 Page 16 Page 17 Page 18 Page 19 Page 20 Page 21 Page 22 Page 23 Page 24 Page 25 Page 26 Page 27 Page 28 Page 29 Page 30 Page 31 Page 32 Page 33 Page 34 Page 35 Page 36 Page 37 Page 38 Page 39 Page 40 Page 41 Page 42 Page 43 Page 44 Page 45 Page 46 Page 47 Page 48 Page 49 Page 50 Page 51 Page 52 Page 53 Page 54 Page 55 Page 56 Page 57 Page 58 Page 59 Page 60 Page 61 Page 62 Page 63 Page 64 Page 65 Page 66 Page 67 Page 68 Page 69 Page 70 Page 71 Page 72 Page 73 Page 74 Page 75 Page 76 Page 77 Page 78 Page 79 Page 80 Page 81 Page 82 Page 83 Page 84 Page 85 Page 86 Page 87 Page 88 Page 89 Page 90 Page 91 Page 92 Page 93 Page 94 Page 95 Page 96 Page 97 Page 98 Page 99 Page 100 Page 101 Page 102 Page 103 Page 104 Page 105 Page 106 Page 107 Page 108 Page 109 Page 110 Page 111 Page 112 Page 113 Page 114 Page 115 Page 116 Page 117 Page 118Made with FlippingBook. PDF to flipbook with ease