Indonesian Financial Services Authority
Checklist The checklist below can be used by FSTI Providers to conduct self-assessment.
1.
Data Protection
1.1.
Confidentiality Encryption Data at rest encryption using AES-256 or at least AES-128 Data in transit encryption using TLS 1.2 or higher Encryption for all sensitive data Encryption keys are managed securely Implement end-to-end encryption (E2EE) for all data exchanges
Data Storage Security Server firewall for data storage security
Authentication and Access Control Implement an authentication mechanism using multi-factor authentication (MFA) Strong password policies, including minimum password length, combinations of upper and lower case, numbers, and special character usage Implement a password reset mechanism by using temporary tokens or links sent via email Use Hypertext Transfer Protocol Secure (HTTPS) to encrypt data transmitted between clients and servers
107
Made with FlippingBook. PDF to flipbook with ease