Cybersecurity Guidelines for Financial Sector Te…

Indonesian Financial Services Authority

Checklist The checklist below can be used by FSTI Providers to conduct self-assessment.

1.

Data Protection

1.1.

Confidentiality Encryption Data at rest encryption using AES-256 or at least AES-128 Data in transit encryption using TLS 1.2 or higher Encryption for all sensitive data Encryption keys are managed securely Implement end-to-end encryption (E2EE) for all data exchanges

Data Storage Security Server firewall for data storage security

Authentication and Access Control Implement an authentication mechanism using multi-factor authentication (MFA) Strong password policies, including minimum password length, combinations of upper and lower case, numbers, and special character usage Implement a password reset mechanism by using temporary tokens or links sent via email Use Hypertext Transfer Protocol Secure (HTTPS) to encrypt data transmitted between clients and servers

107

Made with FlippingBook. PDF to flipbook with ease