Cybersecurity Guidelines for Financial Sector Te…

Indonesian Financial Services Authority

4.3. Risk Treatment FSTI Provider’s action towards risk assessment and risk mitigation involves a structured approach to addressing identified risks, including selecting appropriate risk treatment options, implementing security measures, and continuously monitoring the effectiveness of the security measures.

1. Risk Treatment Options

a) Risk Avoidance Implement strategies to avoid activities that introduce unacceptable risks. For instance, avoid using outdated software known to have vulnerabilities. b) Risk Reduction Apply security controls and measures to reduce the likelihood and impact of identified risks, including enhancing security controls, conducting regular audits, and training employees. c) Risk Sharing Transfer or share the risk with other parties. Risk sharing could involve outsourcing certain functions to specialised cybersecurity firms or purchasing cyber insurance to cover potential losses from incidents. d) Risk Acceptance Accept the risk when the cost of risk mitigation exceeds the potential impact. Risk acceptance should be based on a clear understanding of the potential impact and losses.

47

Made with FlippingBook. PDF to flipbook with ease