Indonesian Financial Services Authority
Measures that can be taken during the risk assessment process are as follows:
1. Vulnerability Assessment a. Establish a recurring schedule for vulnerability assessments. Ideally, assessment should be performed quarterly and after any significant changes to infrastructure, such as system updates, new service rollouts, or integration of new hardware or software. b. Tailor the policy based on the vulnerability assessment results to match the specific architecture of FSTI Provider’s networks and systems, including setting the depth of assessments and the aggressiveness of tests.
2. Risk Modelling Techniques Apply quantitative and qualitative risk assessment models to evaluate the potential impact of threats. The following are feasible techniques: a. Use ISO 27001 as the assessment framework in FSTI Provider’s risk modelling technique. b. Integrate risk modelling into business decision-making processes. c. Use the outcomes from risk modelling to influence policy changes, security enhancements, and strategic planning.
43
Made with FlippingBook. PDF to flipbook with ease