Indonesian Financial Services Authority
·
Cloud Security Alliance (CSA) https://cloudsecurityalliance.org/research/guidance/.
·
SANS Institute Resources: https://www.sans.org/reading-room/) https://www.sans.org/cyber-security-courses/
9.3. Essential Cybersecurity Steps
This appendix outlines the essential or ‘Must Have’ cybersecurity measures required by FSTI Providers.
Encryption Standard
1.
Implement encryption standards such as AES-256 11 or at least AES- 128, as recommended by BSSN.
Access Control
2.
2.1.
· Multi-Factor Authentication (MFA) Implement MFA for all critical systems and applications to ensure that users must provide at least two forms of verification to gain access
Leverage methods such as SMS-based codes, authentication apps (e.g. Google Authenticator), and tokens
·
11 Advanced Encryption Standard (AES), https://www.techtarget.com/searchsecurity/definition/ Advanced-Encryption-Standard
89
Made with FlippingBook. PDF to flipbook with ease