Cybersecurity Guidelines for Financial Sector Te…

Indonesian Financial Services Authority

Password Policy Enforcement - Enforce strong password requirements, including a minimum length, a mix of uppercase and lowercase letters, numbers, and special characters. - Implement rate limiting and account lockout mechanisms to protect against brute force attacks Regularly Update Hashing Algorithms - Periodically review and update the hashing algorithms used to ensure they remain secure against evolving threats. - Implement a system to rehash existing passwords with stronger algorithms when users log in or change their passwords. Store Passwords Separately from Other Data - Ensure that password hashes are stored separately from other sensitive data to reduce the risk of exposure in case of a data breach. - Use dedicated and secure storage mechanisms for password data Secure Password Reset Processes - Implement secure password reset mechanisms that do not expose or transmit the current password. Instead, use temporary tokens or links sent via email. - Ensure that reset tokens are time-limited and can only be used once. -

27

Made with FlippingBook. PDF to flipbook with ease