Cybersecurity Guidelines for Financial Sector Te…

Cybersecurity Guidelines for FSTI Providers

Data Protection 03

Data protection policy includes data encryption, secure data storage, and access controls. Data encryption security is intended for all sensitive information/data, such as credit card numbers, banking details, personal identification data, using strong cryptographic algorithms. Along with encryption, secure data storage must be supported by installing firewalled servers to ensure the data is protected from cyberattacks and other potential security threats. Data protection procedures must also be equipped with strict access controls in place to prevent unauthorised data access. It is also crucial to regularly test and audit the secure data storage to ensure that FSTI Providers meet the highest security standards. 3.1. Data Protection Policy Having a comprehensive data protection policy is crucial for the cybersecurity efforts of FSTI Providers for several reasons: 1. Safeguarding sensitive data FSTI Providers handle a significant amount of sensitive data. Data protection policy ensures that data is encrypted and stored securely, and accessible only to authorised personnel. FSTI Providers can implement strong encryption standards like AES-256 or at least AES-128 as recommended by the National Cyber and Crypto Agency (BSSN).

22

Made with FlippingBook. PDF to flipbook with ease