Cybersecurity Guidelines for FSTI Providers
3.2. Information Security Principles
The fundamental framework to safeguard information security covers Confidentiality, Integrity, and Availability (CIA).
3.2.1. Confidentiality
All sensitive data should be encrypted using advanced cryptographic standards to ensure that data remains secure even if accessed by unauthorised entities. FSTI Providers implement strong encryption standard AES-256 1 or at least AES-128 as recommended by the National Cyber and Crypto Agency (BSSN).
1.
Encryption
a) Encryption Standards - Encryption data at rest using industry-standard algorithms such as AES (Advanced Encryption Standard) AES-128 as per the minimum recommendation by BSSN. Employ TLS 1.2 or higher for encrypting data in transit to ensure secure data exchange between clients and servers. 2 b) Encryption Implementation - Apply encryption to all sensitive data, including personal identification information, transaction details, and financial records. - Ensure that encryption keys are securely managed, with key generation, distribution, storage, rotation, and destruction procedures in place to prevent unauthorised access.
1 Advanced Encryption Standard (AES), https://www.techtarget.com/searchsecurity/definition/ Advanced-Encryption-Standard 2 Advanced Encryption Standard (AES) - National Institute of Standards and Technology (NIST), https:// www.nist.gov/publications/advanced-encryption-standard-aes
24
Made with FlippingBook. PDF to flipbook with ease