Cybersecurity Guidelines for Financial Sector Te…

Cybersecurity Guidelines for FSTI Providers

Implement HTTP Strict Transport Security (HSTS) to ensure a secure connection

1.2. Integrity

The principle of personal data protection has been incorporated into the design of system architecture and business processes as an integral part of the data life cycle Implement an adequate access control mechanism Conduct training covering proper handling, retention, and disposal of sensitive information Use server firewall for storage security

1.3. Availability

Data Retention Policy

Set retention period policy Update the retention policy regularly

Data Disposal Security Establish disposal security procedures for data that is no longer needed Delete data using methods such as data deletion, degaussing (removal of magnetic storage media, e.g. disposal of hard disks or flash disks), or physical disposal

108

Made with FlippingBook. PDF to flipbook with ease