Cybersecurity Guidelines for Financial Sector Te…

Indonesian Financial Services Authority

1. Development of a comprehensive curriculum Develop modules based on frameworks like the US NIST Cybersecurity Framework, which covers areas such as identification, protection, detection, response, and recovery. a.

b.

Include real-world case studies to highlight the consequences of non-compliance and the importance of personal data protection.

2. Training session

a.

Conduct annual training sessions to cover foundational and advanced cybersecurity practices.

b.

Offer in-depth technical training, focusing on risk assessment and mitigation techniques in the FSTI industry for IT employees.

3. Cybersecurity simulations

Use simulation tools like those used in the UK’s CBEST program 10 to provide scenario-based learning experiences that mimic real cyber- attacks. 4. Assessment and certification Utilize assessment tools, including scenario-based questions and practical test. a.

b.

Encouraging employees to pursue certifications such as Certified Information System Auditor (CISA), Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM).

10 Bank of England CBEST Implementation Guide, https://www.bankofengland.co.uk/-/media/boe/files/ financial-stability/financial-sector-continuity/cbest-implementation-guide.

73

Made with FlippingBook. PDF to flipbook with ease