Indonesian Financial Services Authority
Security Assessment 4 - Conduct annual security assessments to assess and evaluate the effectiveness of the encryption measures implemented. - Update encryption methods as needed to address new vulnerabilities and to align with updated security standards and best practices. 4.
3.2.2. Integrity
1.
Documentation and Audit
- Maintain logs of all data disposal activities, detailing the method of destruction, the person responsible, and the date of destruction. - Regularly review and audit data retention and disposal practices effectively while complying with the applicable policies and regulations.
2.
Privacy by Design
- Ensure that the personal data protection principle is incorporated into system architecture design and business processes as an integral part of the data lifecycle, from collection to disposal.
4 See the Risk Assessment section in Chapter 4.
29
Made with FlippingBook. PDF to flipbook with ease