Cybersecurity Guidelines for FSTI Providers
1.
Commitment to Cyber Security 1.1.
All employees must be committed to maintaining cybersecurity standards as determined by OJK Regulations and general practices carried out internationally. FSTI providers must ensure continuous improvement and adaptation of cybersecurity measures to address current threats and technologies.
1.2.
2.
Data Protection
2.1.
Implement adequate data encryption protocols to protect sensitive financial information both in transit and at rest. Implement strict access controls and data storage security to protect data from unauthorized access. Develop and enforce comprehensive data retention and destruction policies in accordance with applicable legal and regulatory requirements.
2.2.
2.3.
3.
Risk Management
3.1.
Conduct regular and comprehensive risk assessments to identify and address potential cybersecurity threats. Develop a risk mitigation strategy that includes the implementation of appropriate security controls and regular security audits. Integrate risk management into all aspects of business operations and decision-making processes
3.2.
3.3.
104
Made with FlippingBook. PDF to flipbook with ease