Indonesian Financial Services Authority
4.2. Risk Mitigation Strategies for mitigating cybersecurity risks, including the use of security controls, regular security audits, and employee training programs. To ensure the safety of sensitive data and prevent unauthorised access, security controls such as firewalls, encryption, and access controls should be set up. Regular security audits and penetration testing can help identify and address vulnerabilities.
1. Enhance Security Controls
a. Deploy advanced security solutions like next-generation firewalls, intrusion prevention systems (IPS), intrusion detection systems (IDS), and endpoint detection and response (EDR). b. Deploy encryption for data at rest and data in transit.
2. Regular Security Audits
a. Schedule regular audits internally and/or external auditors to ensure all systems and controls are up to standard. b. Conduct internal audits at least annually to review security policies, access controls, and compliance with relevant regulations. c. Engage with third-party auditors annually to perform comprehensive external audits. These auditors may provide an objective review of security practices and compare them against applicable standards and regulations.
45
Made with FlippingBook. PDF to flipbook with ease