Indonesian Financial Services Authority
Formulate Incident Response Plan Establish a clear incident response plan, including eradicating cyber threats, establishing internal and external communication strategies (including with OJK and/or other relevant authorities), and preparing a recovery plan
2.3. Risk Treatment
Security Measures/Devices Implement advanced security measures, such as multi-factor authentication, data encryption, and secure coding practices Implement an adequate incident response plan, including specific actions to detect, identify, contain, eradicate, and recover security incidents Ensure third parties/vendors comply with FSTI Provider’s security policy and are willing to be audited by OJK if necessary Periodic Monitoring and Review Conduct periodic risk assessments to identify new risks and re- evaluate existing risks Carry out periodic reviews of the effectiveness of risk-handling measures Update the risk management process based on the lesson learned from incidents Monitor compliance with industry standards and applicable regulations
111
Made with FlippingBook. PDF to flipbook with ease