2022-12-27 | 29/SEOJK.03/2022Added
This circular mandates conventional and Sharia universal banks to implement comprehensive cyber resilience and cybersecurity frameworks, including inherent risk assessments, maturity evaluations, and regular security testing. Banks must report their inherent risk levels, maturity scores, and overall risk ratings to the Financial Services Authority (OJK) annually, with initial submissions due by June 2023 for the December 2022 position. The regulations require specific governance, risk management processes, and incident response procedures, while OJK retains the authority to adjust reported results if they do not reflect the bank's actual condition.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 29/SEOJK.03/2022
CONCERNING
CYBER RESILIENCE AND CYBERSECURITY FOR UNIVERSAL BANKS
In light of the implementation of Financial Services Authority Regulation Number 11/POJK.03/2022 concerning the Implementation of Information Technology by Universal Banks (State Gazette of the Republic of Indonesia Year 2022 Number 5/OJK, Supplement to the State Gazette of the Republic of Indonesia Number 5/OJK), hereinafter referred to as the IT Regulation (POJK PTI), it is necessary to regulate implementation provisions regarding cyber resilience and cybersecurity for universal banks in this Financial Services Authority Circular as follows:
I. GENERAL PROVISIONS
Banks apply good governance and risk management to continue operating by utilizing IT as appropriate while maintaining cyber resilience and cybersecurity. Furthermore, banks must establish strategies and targeted, sustainable steps to address problems caused by cyber threats and incidents. This must be done considering that the banking business is primarily related to public funds, requiring mature and safe operations.
Cyber resilience is the bank's ability to maintain its business continuity by taking anticipatory, adaptive, and proactive actions against cyber threats.
Cybersecurity is the condition of maintaining the confidentiality, integrity, and availability of information and/or interconnected information systems via cyber media from cyber attacks. Cybersecurity may also cover other aspects, such as authenticity, accountability, non-repudiation, and reliability.
IT incident reports, specifically cyber incidents, hereinafter referred to as cyber incident reports, are reports of critical events, misuse, and/or crimes in the implementation of IT, related to cybersecurity.
Initial IT incident notifications, specifically cyber incidents, hereinafter referred to as initial cyber incident notifications, are immediate notifications regarding critical events, misuse, and/or crimes in the implementation of IT, related to cybersecurity.
II. INHERENT RISK ASSESSMENT RELATED TO CYBERSECURITY
Banks conduct inherent risk assessments related to cybersecurity. These assessments are conducted annually for the position at the end of December. Banks may conduct these assessments at any time if necessary.
Inherent risk assessments related to cybersecurity are conducted by considering at least 4 (four) assessment factors, namely technology, bank products, organizational characteristics, and cyber incident track records. Inherent risk assessments begin with the assessment of risk parameters for each assessment factor related to cybersecurity. There are several minimum parameters or indicators that can serve as references for banks in assessing inherent risks related to cybersecurity as stated in Appendix I.a, which is an integral part of this Financial Services Authority Circular. Banks may add other relevant parameters or indicators based on the characteristics and complexity of the bank's business, considering the principle of proportionality.
In conducting inherent risk assessments related to cybersecurity, banks use the format as stated in Appendix II.a, which is an integral part of this Financial Services Authority Circular.
The determination of inherent risk levels related to cybersecurity is categorized into Rating 1 (low), Rating 2 (low to moderate), Rating 3 (moderate), Rating 4 (moderate to high), and Rating 5 (high), as stated in Appendix III.a, which is an integral part of this Financial Services Authority Circular.
The results of inherent risk assessments related to cybersecurity as referred to in item 3 and the inherent risk levels related to cybersecurity as referred to in item 4 are submitted to the Financial Services Authority as part of the current status report of the bank's IT implementation, namely no later than 15 (fifteen) working days after the end of the reporting year, using the format as stated in Appendix V, which is an integral part of this Financial Services Authority Circular.
Inherent risk assessments related to cybersecurity are first conducted by banks for the position at the end of December 2022, and the results of these assessments are submitted to the Financial Services Authority no later than the end of June 2023. For subsequent years, assessments are submitted according to the deadline as referred to in item 5.
The Financial Services Authority reviews the results of inherent risk assessments related to cybersecurity as referred to in item 5. In the event that the Financial Services Authority's review shows that the results of inherent risk assessments related to cybersecurity do not reflect the bank's actual condition, the Financial Services Authority may adjust the results of the inherent risk assessments related to cybersecurity.
The inherent risk levels related to cybersecurity are considered as additional parameters or indicators of the inherent risk level for the IT aspect of operational risk in the bank's health rating assessment.
III. IMPLEMENTATION OF CYBERSECURITY RISK MANAGEMENT
To implement Article 15 of the IT Regulation (POJK PTI), banks apply effective risk management in the implementation of IT, including regarding cybersecurity.
The implementation of cybersecurity risk management covers 4 (four) aspects, namely:
a. cybersecurity risk governance, which includes the adequacy of active supervision by the Board of Directors and Board of Commissioners, the formulation of cybersecurity risk levels to be taken (risk appetite) and cybersecurity risk tolerance (risk tolerance), as well as cybersecurity risk culture and awareness; b. cybersecurity risk management framework, which includes risk management strategies, the adequacy of organizational devices, and the adequacy of policies, procedures, and risk limit determinations, regarding cybersecurity;
c. risk management processes, the adequacy of human resources (HR), and the adequacy of risk management information systems, regarding cybersecurity; and
d. cybersecurity risk control systems, which include the adequacy of internal control systems and the adequacy of reviews.
The implementation of cybersecurity risk management is adjusted to the characteristics and complexity of the bank's business and the bank's overall implementation of IT.
IV. IMPLEMENTATION OF CYBER RESILIENCE PROCESSES FOR UNIVERSAL BANKS
To implement Article 21 of the IT Regulation (POJK PTI), banks maintain cyber resilience by conducting processes:
a. identification of assets, threats, and vulnerabilities; b. asset protection;
c. cyber incident detection; and
d. cyber incident response and recovery.
Asset, Threat, and Vulnerability Identification Process
In the process of identifying assets, threats, and vulnerabilities, banks must at least:
a. apply asset management through effective inventory and assessment of IT assets (including hardware, software, networks, and infrastructure) and configuration recording; b. conduct vulnerability identification and monitoring of current cyber developments to identify cyber threats; and
c. conduct periodic cybersecurity testing.
Asset Protection Process
In the asset protection process, banks must at least:
a. apply comprehensive security controls based on the results of asset, threat, and vulnerability identification as referred to in item 2; b. maintain and repair security controls over IT assets in accordance with applicable policies and procedures;
c. apply security systems managed well in accordance with applicable policies and procedures;
d. conduct periodic reviews of bank security controls to ensure the adequacy of security controls used aligns with the latest results from the identification process; e. apply data and information security management and ensure that data and/or information are managed in accordance with the organization's risk management strategy to protect the confidentiality, integrity, and availability of data and information; f. apply protection management for networks, hardware, and software; g. apply access and user protection management to prevent unauthorized actions on devices, network infrastructure, and system components managed by the bank; h. apply adequate protection in the implementation of cooperation between the bank and IT service providers, including the use of cloud services;
i. ensure the application of secure coding in system and application development to minimize vulnerabilities in systems and applications; and
j. ensure that patching is carried out well and ensure the reliability and currency of all components of the bank's software, communication networks, databases, and operating systems.
Cyber Incident Detection Process
In the cyber incident detection process, banks must at least:
a. ensure the availability of baseline performance documentation for critical bank functions and supporting systems, so that any deviations can be detected in a timely manner and anomalous activities and events can be flagged for follow-up; b. monitor suspicious activities and manage and test detection processes and procedures to ensure anomalous activities can be detected in a timely manner;
c. conduct continuous monitoring or detection of vulnerabilities to ensure the effectiveness of applied protection efforts;
d. ensure the availability of processes to adequately detect cyber incidents; and e. analyze threats and vulnerabilities from a cyber incident to ensure effective incident handling, thereby preventing disruptions to bank services and/or operations.
Cyber Incident Response and Recovery Process
In the cyber incident response and recovery process, banks must at least:
a. establish cyber incident response and recovery plans to ensure timely response and service restoration in accordance with the risks involved, with minimal impact; b. establish the roles, duties, and responsibilities of the cyber incident response team to ensure that cyber incident response and recovery are implemented with minimal impact on bank services and operations;
c. apply recovery procedures and efforts to prevent the spread of impact from a cyber incident by mitigating the impact and handling the cyber incident;
d. conduct analysis to ensure that cyber incident response and recovery steps are executed correctly; e. escalate and report cyber incidents according to established communication channels; and f. conduct post-incident analysis as valuable lessons (lesson learned) in cyber incident response and recovery for continuous improvement.
V. CYBERSECURITY MATURITY LEVEL ASSESSMENT
Cybersecurity maturity level assessments aim to measure the level of maturity achieved by the bank. The cybersecurity maturity level reflects the state of cybersecurity at the bank. In cases where areas with weaknesses requiring improvement are identified, these can serve as input for enhancing the bank's cyber resilience and cybersecurity.
Cybersecurity Maturity Level Assessment Procedures
a. Banks conduct cybersecurity maturity level assessments. These assessments are conducted annually for the position at the end of December. Banks may conduct these assessments at any time if necessary. b. The cybersecurity maturity level assessment includes assessments of:
The results of cybersecurity maturity level assessments as referred to in item 2 letter d and the cybersecurity maturity levels as referred to in item 2 letter f are submitted to the Financial Services Authority as part of the current status report of the bank's IT implementation, namely no later than 15 (fifteen) working days after the end of the reporting year, using the format as stated in Appendix V, which is an integral part of this Financial Services Authority Circular.
Cybersecurity maturity level assessments are first conducted by banks for the position at the end of December 2022, and the results of these assessments are submitted to the Financial Services Authority no later than the end of June 2023. For subsequent years, assessments are submitted according to the deadline as referred to in item 3.
The Financial Services Authority reviews the results of cybersecurity maturity level assessments as referred to in item 3. In the event that the Financial Services Authority's review shows that the results of cybersecurity maturity level assessments do not reflect the bank's actual condition, the Financial Services Authority may adjust the results of the cybersecurity maturity level assessments.
The cybersecurity maturity levels are considered as additional parameters or indicators of the quality of implementing risk management for the IT aspect of operational risk in the bank's health rating assessment.
VI. CYBERSECURITY RISK LEVELS
Cybersecurity risk levels are determined based on inherent risk assessments related to cybersecurity and cybersecurity maturity levels.
The determination of cybersecurity risk levels is categorized into Rating 1 (low), Rating 2 (low to moderate), Rating 3 (moderate), Rating 4 (moderate to high), and Rating 5 (high). The order of cybersecurity risk levels with smaller ratings reflects lower cybersecurity risks faced by the bank.
The cybersecurity risk levels as referred to in item 1 are submitted to the Financial Services Authority as part of the current status report of the bank's IT implementation, namely no later than 15 (fifteen) working days after the end of the reporting year, using the format as stated in Appendix V, which is an integral part of this Financial Services Authority Circular.
The determination of cybersecurity risk levels is first conducted by banks for the position at the end of December 2022, and submitted to the Financial Services Authority no later than the end of June 2023. For subsequent years, cybersecurity risk levels are submitted according to the deadline as referred to in item 3.
The Financial Services Authority reviews the cybersecurity risk levels as referred to in item 2. In the event that the Financial Services Authority's review shows that the cybersecurity risk levels do not reflect the bank's actual condition, the Financial Services Authority may adjust the determination of cybersecurity risk levels.
VII. CYBERSECURITY TESTING
Banks conduct periodic cybersecurity testing on network, system, and data security as a step to maximize efforts to maintain bank cybersecurity. Cybersecurity testing is divided into 2 (two) types, namely cybersecurity testing based on:
a. vulnerability analysis; and b. scenarios.
Cybersecurity Testing Based on Vulnerability Analysis
Banks conduct cybersecurity testing based on vulnerability analysis to view the weak points of the bank's systems. This testing is conducted periodically based on the bank's internal evaluation. Examples of factors that can determine the frequency of this testing include the criticality level of systems from the bank's IT asset identification results and changes in Electronic Systems or IT architecture at the bank that result in increased exposure to cybersecurity risks. This testing begins with the implementation of vulnerability identification, followed by penetration testing.
Penetration testing is testing that uses a series of techniques and methodologies utilizing available resources, including source code, system design, and bank system manuals. Penetration testing aims to breach existing security systems, within previously determined boundaries. Furthermore, penetration testing must be conducted periodically on the software and hardware used by the bank, both for operations and services to customers and/or third parties. Specifically, this testing must be conducted by banks providing digital banking services or other services operating online.
a. Table-top Exercise
Table-top exercises are discussion-based activities where personnel with specific roles and responsibilities at the bank meet in a forum to discuss each role during emergencies and the response actions taken for specific emergency situations. In implementation, there is a facilitator guiding participants through discussions designed to meet predetermined objectives.
b. Cyber Range Exercise
Cyber range exercises are tests using interactive simulated representations of the bank's networks, systems, devices, and applications. These simulations allow testing in a controlled environment without disrupting the bank's operational continuity.
c. Social Engineering Exercise
Social engineering exercises are tests using scenarios where attackers manipulate less vigilant employees to leak sensitive information such as passwords, using techniques such as phishing and spam. This testing can be conducted to determine the level of cybersecurity awareness among employees.
d. Adversarial Attack Simulation Exercise (AASE) Adversarial Attack Simulation Exercise (AASE) is testing that uses simulations of tactics, techniques, and procedures from real-world cyber attacks to target the personnel, processes, and technology supporting the bank's critical functions. AASE provides a more realistic picture of the organization's ability to prevent, detect, and respond to attacks. In AASE, there are generally red teams and blue teams. The red team acts as attackers simulating attacks using tactics, techniques, and procedures from real-world cyber attacks. Meanwhile, the blue team acts as the party conducting detection and/or prevention of the simulated attacks conducted by the red team and handling the resulting cyber incidents.
Points to note in implementing scenario-based testing, namely:
ensure that the testing does not interfere with the Bank's production systems; and
2) threat scenarios must be designed and based on potential cyber threats. Banks may also design scenarios through a comprehensive proactive cyber threat search process, including by using threat intelligence relevant to the Bank's IT environment to identify threat actors that may pose cyber threats to the Bank, and to identify the tactics, techniques, and procedures that could be used in such attacks.
Banks may conduct cyber security testing independently or use third parties. In the event that cyber security testing uses third parties, the Bank must:
a. ensure that the third party has adequate competence according to the needs of the cyber security testing; and b. remain responsible for the implementation of the cyber security testing. Competence of the third party is evidenced, among others, by the existence of certification and/or recognition from a competent institution in Indonesia or abroad.
The first cyber security testing is conducted by the Bank in 2023.
The Bank documents and secures the results of the cyber security testing conducted adequately to maintain the confidentiality of the cyber security testing results.
VIII. UNIT OR FUNCTION HANDLING CYBER RESILIENCE AND SECURITY OF THE BANK
IX. CYBER INCIDENT REPORTING
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
X. CLOSING
The provisions in this Financial Services Authority Circular take effect on the date of establishment.
Established in Jakarta on December 27, 2022
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
DIAN EDIANA RAE
APPENDIX I
FINANCIAL SERVICES AUTHORITY CIRCULAR
REPUBLIC OF INDONESIA
NUMBER 29 /SEOJK.03/2022
REGARDING
CYBER RESILIENCE AND SECURITY FOR COMMERCIAL BANKS
I.a. Inherent Risk Assessment related to Cyber Security Matrix of Parameters or Indicators for Inherent Risk Assessment related to Cyber Security No. Parameter or Indicator Description
No. Parameter or Indicator Description
1.5. Use of IT service providers in data center implementation.
Forms of IT service provision can include:
a. cloud services, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS); and/or b. non-cloud services, such as colocation. The use of cloud services provides higher inherent risk compared to the use of non-cloud IT service provision.
1.6. Management of software used to support Bank operational activities (including back-office and IT needs).
Software management refers to the development and implementation of such software. This management can be done by the Bank itself and/or using third parties. The greater the Bank's dependence on third parties in managing software used to support Bank operational activities, the higher the Bank's inherent risk.
1.7. Use of hardware and/or software that has entered/near End-of-life (EOL).
The use of hardware and/or software that has entered/near EOL affects the Bank's inherent risk. The greater the Bank's use of hardware and/or software that has entered/near EOL, the higher the Bank's inherent risk.
1.8. Number of employees with access to connect personal devices to the Bank network (Bring Your Own Device).
The number of employees with access to the Bank network via personal devices affects the Bank's inherent risk. The greater the percentage of employees with access via personal devices, the higher the Bank's inherent risk.
1.9. Software accessible using personal devices to the Bank network.
Internal Bank software accessible by personal devices is divided into 4 (four), namely:
a. email applications; b. supporting applications;
c. critical applications; and
d. core banking system.
No. Parameter or Indicator Description
The higher the criticality of applications accessible by personal devices, the higher the Bank's inherent risk.
1.10.Third parties with access to Bank internal systems and/or sensitive information.
Third parties in this context include companies (external and intragroup) and individuals from vendors and/or subcontractors. The number of third parties with access to Bank internal systems and/or sensitive information affects the Bank's inherent risk. The greater the number of third parties with access to Bank internal systems and/or sensitive information, the higher the Bank's inherent risk.
2. Bank Products 2.1. Use of online and mobile channels in providing services.
Online and mobile channels can be used by Banks for:
a. providing general Bank information to the public (e.g., office network locations, and available Bank products); b. banking transaction services (Bank products); and/or
c. interconnection with the digital economy ecosystem (super apps).
The broader the use of online and mobile channels owned by the Bank, the higher the Bank's inherent risk.
2.2. Mechanism for Automated Teller Machine (ATM) management.
Bank ATM management can be done by the Bank itself or using third parties, or a combination of both. The greater the role of third parties in ATM management, the higher the Bank's inherent risk.
2.3. Bank products in the form of card payment instruments (APMK).
Bank products in the form of APMK affect the Bank's inherent risk. Banks issuing APMK have higher inherent risk compared to Banks that do not issue APMK.
2.4. Types of IT-based Bank products. Types of IT-based Bank products affect the Bank's inherent risk. The greater the number of types of IT-based Bank products, the higher the Bank's inherent risk.
2.5. Bank as an IT service provider. The provision of IT services by the Bank affects the Bank's inherent risk. The greater the number of IT services provided by the Bank to others, the higher the Bank's inherent risk.
No. Parameter or Indicator Description
3 Organizational Characteristics 3.1. Turnover in HR handling IT/cyber resilience and security.
Turnover in HR in IT/cyber resilience and security affects the Bank's inherent risk. The more frequent the HR turnover, the higher the Bank's inherent risk.
3.2. Changes in the IT environment. Changes in the IT environment are reflected in the implementation of critical systems in the Bank. The greater the number of critical systems implemented by the Bank, the higher the Bank's inherent risk.
3.3. Management of privilege access (administrator and administrator-level) across all devices (hosts, networks, databases, applications, and cloud).
Management of privilege access on Bank devices affects the Bank's inherent risk. The greater the number of device types managed by parties other than the IT unit, the higher the Bank's inherent risk. 4 Cyber Incident Track Record 4.1. Percentage of cyber incidents with significant impact in the last 12 (twelve) months. The percentage of cyber incidents with significant impact affects the Bank's inherent risk. The higher the percentage of cyber incidents with significant impact, the higher the Bank's inherent risk. The percentage of incidents calculated includes actual incidents that occurred at the Bank, not just those reported to the Financial Services Authority. The significance of an incident can consider, among others, the type of data leaked, application downtime, and financial impact.
4.2. Scope of cyber incident impact in the last 12 (twelve) months.
The impact of cyber incidents affects the Bank's inherent risk. The more critical the impact of cyber incidents that occur, the higher the Bank's inherent risk.
I.b. Assessment of the Quality of Cyber Security Risk Management Implementation Matrix of Controls for Cyber Security Risk Management Implementation No. Domain Subdomain Control Explanation/Control Fulfillment Criteria
and sufficient resources to effectively perform the necessary tasks;
appoint officials with appropriate skills, knowledge, and experience to be responsible for the Bank's cybersecurity strategy and to lead the function tasked with implementing cybersecurity risk management within the Bank organization;
ensure that the appointed officials can directly report the implementation and/or issues related to cybersecurity to the Board of Directors periodically, including any changes in the Bank's vulnerability points or changes in cyber threats;
ensure that all material cybersecurity risks and their impacts have been followed up on, and submit accountability reports to the Board of Commissioners periodically, including reports on the progress and issues regarding material cybersecurity risks, accompanied by improvement steps that have been, are being, and will be taken;
ensure the implementation of improvement steps for cybersecurity issues or deviations found;
ensure that the cybersecurity risk management function has been implemented independently, reflected by, among others, the separation of functions between operational units and units responsible for identifying, measuring, monitoring, and controlling cybersecurity risks;
form a change advisory board tasked with reviewing all configuration changes made within the Bank's systems through a change management system reviewed periodically, and providing recommendations to the Board of Directors for approval of such changes; and
ensure that the review of the Bank's cyber incident mitigation and recovery plans is carried out periodically.
1.1.b. The Bank establishes the authority and responsibilities of the Board of Commissioners regarding the implementation of cybersecurity risk management.
The authority and responsibilities of the Board of Commissioners include at least:
having adequate understanding of the types and levels of cybersecurity risks inherent in the Bank;
ensuring the Bank has sufficient human resources and infrastructure to support the implementation of cybersecurity risk management and the Bank's cyber resilience processes;
supporting the creation of a cybersecurity risk management culture by giving sufficient attention to the implementation of cybersecurity risk management by all elements of the Bank organization;
serving as an example of behavioral standards that prioritize awareness of cybersecurity risks for employees and all elements of the Bank organization;
conducting active supervision over the implementation of cybersecurity risk management;
approving policies and strategic plans related to cybersecurity risk management established in accordance with the Bank's risk appetite and risk tolerance;
evaluating cybersecurity risk management policies and strategies periodically, at least once a year or more frequently if there are significant changes in factors affecting the Bank's business activities;
evaluating the Board of Directors' accountability and providing improvement directives regarding the implementation of cybersecurity risk management policies periodically; and
ensuring that cybersecurity risk management policies and processes are implemented effectively and integrated into the overall risk management process.
1.2. Formulation of Risk Appetite (Risk Appetite)
1.2.a. The Board of Directors is responsible for establishing the risk appetite related to the Bank's cybersecurity.
The risk appetite is the level of risk the Bank is willing to take in order to achieve the target quality level of cybersecurity risk management implementation. The risk appetite is reflected in
and Risk Tolerance (Risk Tolerance)
related to
Cybersecurity
1.2.b. The Board of Directors is responsible for establishing the risk tolerance related to the Bank's cybersecurity.
strategy and overall cybersecurity risk management objectives of the Bank.
Cybersecurity risk tolerance is the Bank's ability to accept cybersecurity risk events and their impacts. This risk tolerance is a further elaboration of the risk appetite related to cybersecurity.
In establishing the risk appetite and risk tolerance related to cybersecurity, the Board of Directors must consider the Bank's strategy, objectives, and risk-bearing capacity.
1.3. Culture and Awareness of Cybersecurity Risks
1.3.a. The Board of Directors develops a culture regarding cybersecurity responsibilities for employees at all levels.
This culture is communicated through clear and effective communication and includes relevant information about cybersecurity strategy to all employees to ensure the creation of cybersecurity.
1.3.b. The Board of Directors builds and maintains strong awareness and commitment to the Bank's cybersecurity.
This can be done, among others, through periodic and continuous awareness enhancement programs at least once a year, including through seminars, discussions, workshops, and/or dissemination of cybersecurity policies and procedures. The awareness program must be reviewed periodically and refined to ensure the program's substance aligns with relevant and developing cyber threats and risks.
1.3.c. The Bank ensures the effectiveness of understanding and implementation of cybersecurity policies for all employees and relevant stakeholders.
One way to verify understanding and awareness of cybersecurity is by conducting phishing simulations by sending email blasts to all employees to measure responses to phishing and similar email attacks at least once every year.
2 Cybersecurity Risk Management Framework
2.1. Cybersecurity Risk Management Strategy
2.1.a. The Bank formulates a cybersecurity risk management strategy commensurate with the Bank's vulnerabilities and level of exposure to cyber threats, aligned with the Bank's risk appetite and risk tolerance related to cybersecurity, as well as the overall business strategy.
The cybersecurity risk management strategy is formulated to ensure that the Bank's cybersecurity risk exposure is managed in accordance with internal policies and procedures, as well as applicable laws and regulations.
In formulating the cybersecurity risk management strategy, the Bank considers at least:
the Bank's current cybersecurity needs;
being oriented towards the medium and long term to ensure the Bank's business continuity; and
other factors, such as the results of cybersecurity policy implementation evaluations, technology developments and recent cyber threats or attack modes, adequacy of human resources and supporting infrastructure, characteristics and complexity of business activities, and the Bank's financial condition.
2.1.b. The Bank ensures clarity of all roles and responsibilities related to cybersecurity within the cybersecurity risk management strategy.
The cybersecurity risk management strategy includes at least a description of the following:
understanding of overall cybersecurity risks and their relation to the Bank's business, the level of exposure to cybersecurity risks, and the Bank's current cybersecurity condition;
identification, classification, and prioritization of critical functions, IT assets, and system interconnectivity to obtain a complete and accurate understanding of the Bank's cybersecurity risk profile;
identification of threats and cybersecurity risk mitigation, including steps necessary to address reputation risks that could damage customer trust in the Bank;
security controls to protect the Bank's IT assets from developing cyber threats;
timely detection of cyber incidents through periodic supervision and monitoring; and
detailed policies and procedures for handling cyber incidents to support fast and effective recovery from impacts caused, among others, by cyber incidents.
2.1.c. The Board of Directors effectively communicates the cybersecurity risk management strategy to all units and employees so that it is clearly understood.
2.1.d. The Board of Directors periodically reviews the cybersecurity risk management strategy to determine whether changes to the strategy are necessary.
2.2. Organizational Device Adequacy related to Cybersecurity
2.2.a. The Board of Directors ensures that the Bank's organizational structure includes clear tasks and responsibilities regarding the implementation of cybersecurity risk management in all units, adjusted to business objectives and policies, as well as the size and complexity of the Bank's business activities.
2.2.b. The organizational structure is designed to ensure that units performing internal control functions regarding cybersecurity risk management have independence from business units.
2.2.c. The Bank ensures that the risk management unit has functions handling the implementation of cybersecurity risk management.
The authority and responsibilities of the function handling the implementation of cybersecurity risk management include at least:
providing input to the Board of Directors in formulating policies, strategies, and cybersecurity risk management frameworks;
developing procedures and tools for implementing cybersecurity controls;
designing and implementing devices required for implementing cybersecurity controls;
monitoring the implementation of policies, strategies, and cybersecurity risk management frameworks established by the Board of Directors and approved by the Board of Commissioners;
conducting tests to determine the impact of implementing cybersecurity risk management policies and strategies on the Bank's overall risk profile;
reviewing proposals for new products and the use of new technologies developed by specific units within the Bank, focusing primarily on the impact of new products and new technology usage on the Bank's overall cybersecurity risk exposure; and
providing recommendations for implementing cybersecurity risk management to the Board of Directors and/or other units.
2.2.d. The Bank has a unit or function tasked with handling cyber resilience and cybersecurity.
The structure of the unit or function handling cyber resilience and cybersecurity is adjusted to the size and complexity of the Bank's business activities and the Bank's cybersecurity risks.
2.3. Adequacy of Policies, Procedures, and Cybersecurity Risk Limit Setting
2.3.a. The Board of Directors establishes written policies and procedures for implementing cybersecurity risk management and cyber resilience.
These policies and procedures must align with the Bank's vision, mission, and business strategy.
2.3.b. The Bank designs and implements policies and procedures considering the characteristics and complexity of business activities, risk appetite and risk tolerance, risk profile, and regulations established by relevant authorities regarding cybersecurity.
2.3.c. The Bank internalizes cybersecurity risk management policies, including cybersecurity risk management strategies and objectives, into business processes across all business lines and support activities, including policies specific to the needs of business lines and support activities.
2.3.d. The Bank formulates adequate cybersecurity risk management policies.
Cybersecurity risk management policies are formulated using standards and guidelines applicable nationally and internationally as comparative material, and are consistent with the Bank's overall risk management framework. These policies include at least:
how the Bank establishes cybersecurity risk tolerance and procedures for identifying, reducing, and managing cybersecurity risks;
business continuity plans for possible worst-case external and internal conditions from cyber attacks, including through the implementation of business impact analysis;
specific matters related to cybersecurity, including:
a) employee compliance with cybersecurity risk management policies, including sanctions imposed in case of violations;
b) information security, including arrangements regarding authentication, such as through a unique single ID and arrangements for account access expiration deadlines, as well as procedures for adding/changing/removing access rights in case of employee transfers;
c) reporting methods from Bank employees and customers regarding the loss of hardware or software devices that could be used as tools for cyber attacks;
d) data management methods, including but not limited to data protection, data transfer, and data deletion;
e) cryptographic control methods;
f) compliance with laws and regulations regarding intellectual property rights;
g) methods for verifying integrity and testing hardware and software obtained from outside the Bank; and
h) methods for verifying the implementation of secure coding in software developed by the Bank to ensure that the software does not contain security vulnerabilities, conducted through, among others, static and dynamic analysis.
2.3.e. The Bank has procedures that are derivatives of cybersecurity risk management policies, which can be general controls across all business lines and support activities, and specific controls for each business line and support activity.
2.3.f. The Bank has cybersecurity policies and procedures used to regulate the protection of IT assets.
Cybersecurity policies and procedures include at least the objectives, scope, functions, responsibilities, management commitment, and coordination between units or organizational units within the Bank.
2.3.g. The Bank has cybersecurity risk management policies and procedures for third parties and third-party subcontractors that regulate the management of the Bank's digital data/information (including customer data owned by the Bank) by third parties and third-party subcontractors.
The management of digital data and information includes processing and deletion of data and information.
Cybersecurity risk management policies and procedures for third parties and third-party subcontractors include at least:
processes to block access attempts to devices belonging to employees, as well as devices belonging to third parties and third-party subcontractors that are not secure;
validation and documentation of the security implications of all changes in external network connections or third parties and third-party subcontractors;
arrangements for third-party employees and third-party subcontractors' access to the Bank's sensitive or critical data in hosted systems, with third parties and third-party subcontractors actively tracked based on the principle of privilege;
strong authentication to secure all third-party and third-party subcontractor access to the Bank's networks and/or systems and applications;
periodic monitoring and testing of controls for main external connections and backups, or third parties and third-party subcontractors;
security controls designed and verified to detect and prevent intrusions from external connections or third parties and third-party subcontractors;
clarity of responsibilities for responding to cyber incidents, as well as notifications of cyber incidents and vulnerabilities by third parties and third-party subcontractors connected to the network or having access to the Bank's sensitive or critical data;
clear identification and documentation of data flows, networks, and systems from external connections and third parties and third-party subcontractors connected to the Bank's network; and
there is a process for updating data flow diagrams, networks, and systems from external connections and third parties and third-party subcontractors connected to the Bank's network in the event of changes, reviewed periodically.
2.3.h. The Bank applies cybersecurity risk management for third parties and third-party subcontractors.
2.3.i. The Bank establishes minimum cybersecurity control standards for third parties and third-party subcontractors, namely:
confidentiality provisions in cooperation contracts;
the availability of cybersecurity governance at third parties and third-party subcontractors (policies, procedures, regulations, etc.); and
cybersecurity risk management, including cyber incident management at third parties and third-party subcontractors.
2.3.j. The Bank has cybersecurity risk limits appropriate to the risk appetite, risk tolerance, and overall cybersecurity strategy, while considering the Bank's ability to absorb cybersecurity risk exposure or resulting losses, past loss experience, human resource capabilities, and compliance with applicable external regulations.
In controlling cybersecurity risks, limits are used as thresholds to determine the level of intensity of cybersecurity risk mitigation to be implemented by management.
2.3.k. Policies, procedures, and limits in the implementation of cybersecurity risk management must be adequately documented and communicated to all employees.
2.3.l. The Board of Directors periodically reviews policies, procedures, and limits in the implementation of cybersecurity risk management to adjust to current conditions.
3 Risk Management Process, Human Resource Adequacy, and Information System Adequacy for Cybersecurity Risk Management
3.1. Cybersecurity Risk Management Process (Identification, Measurement, Monitoring, and Control)
3.1.a. The Bank periodically identifies all cybersecurity risks.
The cybersecurity risk identification process is conducted by analyzing all sources of cybersecurity risks. These risk sources can come from the Bank's human resources, processes, systems, or external factors, as explained below:
Human Resources
Human resources are a source of cybersecurity risks in the form of human resource inability to perform tasks related to securing the Bank's IT assets, or factors such as insufficient human resource security awareness in performing daily tasks and work processes, and other factors related to the integrity of Bank employees.
Processes
The design and implementation of business processes within the Bank can cause cyber incidents for the Bank. Weaknesses in these processes include, among others, the absence of secure channels during transmission, security aspects not being audited periodically, poor password management, and the use of insecure public internet access.
Systems
Weaknesses in the Bank's IT and infrastructure can be sources of cybersecurity risks. Lack of security testing, control, and monitoring of threats and vulnerabilities, system weaknesses (such as the absence of anti-malware/antivirus), and unupdated systems, become pathways for cybersecurity risks to enter the Bank.
External Factors
External factors that are the main causes of cybersecurity risks for the Bank include insufficient customer security awareness. Additionally, the evolving tactics and sophistication of cyber attackers are also external factors causing the emergence of cybersecurity risks.
3.1.b. The Bank ensures the availability of methods or systems to identify risks in all Bank activities related to cybersecurity.
3.1.c. The Bank periodically measures risks for all Bank activities related to cybersecurity.
3.1.d. The Bank has a risk measurement system to measure the Bank's cybersecurity risk exposure as a basis for control.
This system can measure at least:
the sensitivity of the Bank's activities related to cybersecurity to changes in influencing factors, both under normal and abnormal conditions;
the tendency of changes in the aforementioned factors based on fluctuations that have occurred in the past and their correlations;
cybersecurity risk factors;
cybersecurity risk exposure; and
all risks inherent in the Bank's activities related to cybersecurity.
Cybersecurity risk measurement methods can be conducted quantitatively and/or qualitatively. The choice of measurement method is adjusted to the characteristics and complexity of the Bank's business activities.
3.1.e. The Bank periodically or ad hoc evaluates and improves the cybersecurity risk measurement system to ensure the relevance of assumptions, accuracy, fairness and data integrity, and procedures used to measure cybersecurity risks.
3.1.f. The Bank has systems and procedures for monitoring cybersecurity risks, including monitoring of cybersecurity risk exposure levels, risk tolerance, internal limit compliance, and stress test results.
Monitoring is conducted by both business units and risk management units.
Monitoring results are presented in periodic reports submitted to Bank management for the purpose of mitigating cybersecurity risks and determining necessary actions.
or consistency of implementation with established policies and procedures.
3.1.g. Banks prepare an effective backup system and procedure to prevent disruptions in the cyber security risk monitoring process and conduct periodic checks and re-evaluations of the backup system.
3.1.h. Banks have adequate cyber security risk control systems referring to established policies and procedures.
The cyber security risk control process applied by the Bank must be adjusted to the risk exposure and the level of risk to be taken (risk appetite) and risk tolerance. Cyber security risk controls can be carried out by the Bank, including providing backup systems and organizing disaster recovery plans (Disaster Recovery Plan/DRP).
3.2. Adequacy of Human Resources Related to Cyber Security
3.2.a. The Board of Directors ensures the adequacy of the quantity and quality of existing Human Resources (HR) in the Bank and ensures that the aforementioned HR understands their tasks and responsibilities in implementing cyber security risk management, for business units, risk management work units, and supporting units responsible for implementing cyber security risk management.
3.2.b. The Board of Directors develops a system for employee recruitment, development, and training, including managerial succession plans and adequate remuneration, to ensure the availability of competent employees in cyber security risk management.
3.2.c. The Board of Directors ensures that all HR has adequate understanding of risks related to cyber security and is able to communicate the implications of cyber security risks to the Board of Directors, Board of Commissioners, management, and customers.
3.2.d. The Board of Directors ensures that all HR understands the strategy, level of cyber security risk to be taken (risk appetite) and risk tolerance related to cyber security, the cyber security risk management framework established by the Board of Directors and approved by the Board of Commissioners, and ensures that all HR apply it consistently in the activities handled.
3.2.e. The Bank has complete information regarding all Bank employees, including knowledge, skills, abilities, and character of employees. Actions that can be taken by the Bank include conducting background checks for new employees, in order to protect stakeholders and the Bank's reputation, as well as preventing potential fraud.
3.2.f. The Bank develops and implements a continuous capacity enhancement program for cyber security for all relevant employees, including the Board of Directors, Board of Commissioners, and management, to ensure that every employee has the competence and expertise to perform their roles and responsibilities effectively.
Capacity enhancement programs can include training on:
The frequency and substance of capacity enhancement are adjusted according to the role and responsibilities of each employee.
3.2.g. The Bank conducts a gap analysis to understand the level of employee knowledge and capabilities related to cyber security and uses this information to create an employee capacity enhancement action plan.
Examples of employee capacity enhancement include periodic education and training related to cyber security.
In enhancing employee capacity, the Bank may refer to applicable laws and regulations regarding the protection of vital information infrastructure and its implementing regulations.
3.3. Adequacy of Information Systems for Cyber Security Risk Management
3.3.a. The Bank has a cyber security risk management information system and develops it according to the Bank's needs to implement effective cyber security risk management.
As part of the risk management process, the Bank's cyber security risk management information system is used to support the implementation of the cyber security risk identification, measurement, monitoring, and control processes.
The cyber security risk management information system can ensure at least:
3.3.b. The Bank ensures that the cyber security risk management information system and the information generated are in accordance with the characteristics and complexity of the Bank's business activities and are adaptive to changes.
3.3.c. The Bank periodically reviews the adequacy of the information coverage generated from the cyber security risk management information system to ensure that the information coverage is adequate according to the development of the complexity of the Bank's business activities.
3.3.d. As part of the cyber security risk management information system, the cyber security maturity level report is prepared periodically by the unit or function responsible for handling the Bank's cyber resilience and security. The frequency of submitting the cyber security maturity level report to the relevant Board of Directors and risk management committee must be increased according to needs, especially in the event of rapidly changing cyber attacks and threats.
3.3.e. The Bank ensures that the cyber security risk management information system supports the reporting of the cyber security maturity level to the Financial Services Authority (OJK).
4.1. Adequacy of Internal Control System
4.1.a. The Bank implements an internal control system effectively in the implementation of cyber security risk management referring to established policies and procedures.
In implementing the internal control system, the Bank ensures that the application of the separation of functions (four eyes principle) is adequate and implemented consistently.
The internal control system is the responsibility of all business work units and supporting work units, including compliance work units, risk management work units, and internal audit work units.
In implementing the internal control system, the Bank pays attention to at least:
4.1.b. The Bank implements an internal control system effectively in the implementation of the cyber resilience process referring to established policies and procedures.
In implementing the internal control system effectively, the Bank pays attention to at least:
4.1.c. The internal audit work unit monitors the improvement of finding results. Findings that have not been followed up must be reported to the Board of Directors and/or Board of Commissioners to take necessary actions.
4.1.d. The Bank has a routine rotation system to avoid potential self-dealing, collusion, or concealment of documentation or unusual activities.
4.2. Adequacy of Review
4.2.a. The Bank conducts periodic reviews and evaluations of the implementation of cyber security risk management in accordance with the Bank's characteristics and complexity.
Such reviews and evaluations are conducted by work units performing cyber security risk management functions and internal audit work units.
4.2.b. The Bank ensures that work units performing cyber security risk management functions conduct adequate reviews and evaluations.
The implementation of reviews and evaluations by work units performing cyber security risk management functions covers at least:
4.2.c. The Bank ensures that internal audit work units conduct adequate reviews and evaluations.
The implementation of reviews and evaluations by internal audit work units covers at least:
4.2.d. The Bank ensures that parties conducting reviews and evaluations of the implementation of cyber security risk management have good independence and competence and reliable review methods.
4.2.e. The Bank ensures that the results of reviews and evaluations of the implementation of cyber security risk management have been submitted to the Board of Directors and Board of Commissioners to take improvement and/or refinement actions for cyber security risk management.
I.c. Quality Assessment of Cyber Resilience Process Implementation
Cyber Resilience Process Implementation Control Matrix
1.a. The Bank implements asset management through inventory and assessment of IT assets (including hardware, software, networks, and infrastructure) and effective recording of configurations.
In managing IT assets, the Bank must at least:
1.b. The Bank conducts vulnerability identification and monitoring of current cyber developments to identify cyber threats.
In conducting vulnerability identification and monitoring of cyber developments, the Bank must at least:
1.c. The Bank conducts periodic cyber security testing.
In conducting cyber security testing, the Bank must at least conduct:
2.a. The Bank implements comprehensive security controls in accordance with the results of asset, threat, and vulnerability identification.
Comprehensive security controls aim to ensure:
2.b. The Bank maintains and repairs security controls over IT assets in accordance with applicable policies and procedures.
2.c. The Bank applies a security system managed well in accordance with applicable policies and procedures.
2.d. The Bank periodically reviews its security controls to ensure the adequacy of security controls used in accordance with the latest results from the identification process.
Review of the applied cyber security controls in the Bank is conducted according to the criticality of IT assets based on the latest identification.
2.e. The Bank applies data and information security management and ensures that data and/or information are managed in accordance with the organization's cyber security risk management strategy to protect the confidentiality, integrity, and availability of data and information.
In implementing data and information security management, the Bank must at least conduct:
2.f. The Bank applies protection management for networks, hardware, and software.
In implementing protection management, the Bank must at least:
have adequate perimeter network protection devices (such as border routers and firewalls) that are periodically verified, including implicit deny rules or explicit deny rules;
have IPS to prevent cyber attack attempts;
implement restrictions on inbound and outbound network traffic in the network to prevent malware;
use next-generation endpoint protection to limit applications that are downloaded, installed, and used;
periodically monitor network ports;
use centralized authentication for all network devices;
ensure that encryption processes are conducted for authentication and transmission of data through wireless networks and mobile devices, as well as external storage media;
have network security devices, for example
Domain Name System (DNS) filtering service or DNS security extensions ;
have an automatic checking system against
spam/phishing/malware on electronic mail including those in the cloud ;
use restrictions on the use of scripting tools
;
ensure that all networks, applications, and IT
developments of the Bank still receive support updates, including among others web browsers, email clients, operating systems (operating system), database servers, network devices, security devices, and ensure that support updates are carried out promptly in the event of security patches ;
use application add-ons and plug-ins in accordance
with organizational regulations;
ensure:
a) adequacy of the formal process for managing configuration of routers, switches, and firewalls, including changes and testing of all configuration changes to routers, switches, and firewalls; b) documentation of configuration and periodic review of router and switch configuration at least every 6 (six) months; c) synchronization of switch and router startup configuration with running configuration; d) default configuration account policies, as well as back -up of the configuration of such devices;
identify and restrict access to unauthorized devices;
restrict the use of assets for personal purposes and the use of third-party assets on the Bank's network;
establish administrator access rights on Bank devices for employees;
disable unused device assets and applications by the Bank (examples: USB ports, DVD, and
mobile device access); and
apply application whitelisting to ensure
that only authorized software libraries and signed scripts can be executed by the system.
2.g. The Bank implements protection management against access and users to prevent unauthorized actions on devices, network infrastructure, and system components that are managed by the Bank. In implementing protection management against access and users, the Bank at least:
implements identification and authentication
of access management for all software and hardware;
controls user access, including
password complexity, restriction of attempts and reuse of passwords, and password requests after the device has been inactive for a while;
implements endpoint security including by
using web URL filtering, device control, and application control on all user endpoint devices including endpoints connected to Virtual Private Network (VPN);
uses One Time Password (OTP) verification
for high-risk transactions;
implements IP reputation to verify allowed
IP addresses in the transaction process;
ensures access limits on databases, for example
by implementing read-only access for users other than database admins;
uses Multi-Factor Authentication (MFA) for
access to sensitive data or access to all networks if necessary;
disables communication between workstations to
prevent cyber attacks and disabled peer to peer on wireless clients on devices;
ensures all employees use wireless features only for Bank purposes;
disables auto-run content features against
devices connected to the system or devices at the Bank; and
implements authentication methods through
encrypted channels, both for logging into the network and applications.
2.h. The Bank implements adequate protection in the implementation of cooperation between the Bank and third-party IT service providers, including in the use of cloud. In implementing adequate protection related to the implementation of cooperation between the Bank and third parties IT service providers, the Bank at least:
ensures that adequate controls have been established
for logical access to the Bank's systems;
implements policies for classifying criticality and
sensitivity of data and information stored on the cloud;
ensures that security that is the Bank's responsibility
has been configured according to standards and best practices;
ensures the Bank's human resource capabilities to be able to
perform system configuration and implement security controls on the cloud;
uses authorized cloud storage;
ensures traffic authorization on cloud services is only
for the Bank's business and operational needs;
restricts cloud traffic access only to IP addresses
known by the Bank;
ensures the cloud provider has implemented MFA;
ensures the cloud provider has a data recovery
center that is geographically separated and has recovery point objective and recovery time objective that are documented; and
ensures the implementation of single-sign on and its access
through Secure Socket Layer (SSL) VPN tunnel.
2.i. The Bank ensures the implementation of secure coding in the development of systems and applications to minimize vulnerabilities in systems and applications. In ensuring the implementation of secure coding as intended, the Bank at least:
ensures that system and application development
follows secure coding practices as part of the system development life cycle;
conducts source code reviews to detect
vulnerabilities in software, especially before entering the production stage;
ensures the compatibility of secure coding practices with
the programming language standards established by the Bank and the integrated development environment (integrated development environment) used by the Bank; and
conducts periodic reviews and tests
on the security of software developed by internal Bank staff as well as third parties.
2.j. The Bank ensures the implementation of patching runs well and ensures the reliability and up-to-dateness of all components of software, network communications, databases, and operating systems (operating system) of the Bank. In ensuring that patching runs well, the Bank at least:
cyber security and remain commensurate with threats and cyber vulnerabilities of the Bank;
5) centralizes and coordinates the process
of cyber security and technology (examples: Security Operations Center (SOC) or similar); and
6) ensures that baseline performance documentation is stored
in a secure medium and has a back-up.
3.b. The Bank monitors suspicious activities and manages and tests the detection process and procedures to ensure that anomalous activities can be detected accurately timely. In monitoring suspicious activities and managing and testing processes and detection procedures, the Bank at least:
implements detailed logging that includes
detailed information, such as event source, date, user, timestamp, source addresses, destination addresses, and other components as a source of continuous monitoring;
implements Security Information and Event
Management (SIEM) or log analytic tools for documentation, correlation, and log analysis purposes;
backs up audit logs, system logs, and
configuration logs on a centralized log server to prevent unauthorized access or changes to logs and ensure log storage capacity is in accordance with needs;
detects unauthorized access,
anomalies in the network, as well as login failures on network devices, servers, and applications;
has a warning system for suspicious activities
and is followed up and communicated to relevant stakeholders; and
determines priority for events (events) in the log
based on severity/impact level and security category.
3.c. The Bank conducts continuous monitoring or detection of vulnerabilities to ensure the effectiveness of protection efforts that have been implemented. In conducting continuous monitoring or detection of vulnerabilities, the Bank at least:
detects malicious code,
unauthorized encryption and mobile code, and detection of wireless access points to LAN (ethernet), as well as understanding the potential impact caused by such events;
monitors information systems and IT assets to
identify cyber security events and verify the effectiveness of protection measures taken;
makes efforts to detect the presence of malicious
domains (examples: use of DNS query logging to know the presence of unauthorized domains);
conducts periodic reviews of test results based on
vulnerability analysis as well as ensures follow-up on test results;
analyzes security control gaps
based on test results;
makes efforts to obtain up-to-date information
regarding cyber security (examples: through obtaining information from managed security service providers or providers of cyber security products, multiple threat intelligence feeds, and cyber threat intelligence units); and
implements an early warning system against anomalies
in the system.
3.d. The Bank ensures the availability of processes to detect cyber incidents adequately.
In ensuring the availability of processes to detect cyber incidents, the Bank at least:
the risk of fraud occurrence, including notification time, and scope of information that needs to be communicated. The level of stakeholder engagement is determined by the severity and impact level of the cyber incident. In compiling the aforementioned response and recovery plan, the Bank:
and tackling such cyber incidents.
2) takes response and recovery steps
for cyber incidents in accordance with the plan;
3) conducts root cause analysis of cyber incidents to prevent recurrence of similar events; and
4) reviews the recapitulation of cyber incident reports to study the compatibility of cyber incident procedures with standards and procedures that have been established.
4.d. The Bank conducts analysis to ensure that steps for response and recovery of cyber incidents are carried out correctly.
In conducting analysis, the Bank at least:
This copy is in accordance with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
2) establishes communication procedures in response and recovery of cyber incidents;
3) escalates to report the implementation of response and recovery of cyber incidents to executive officials, the Board of Directors, and the Board of Commissioners based on criteria
of potential impact and criticality;
4) escalates to competent parties to carry out response and analysis of cyber incidents in accordance with
certain service level agreements; and
5) has procedures and communicates to customers and other related parties (including media if necessary)
when a cyber incident occurs that can cause disruption to or reduction of Bank services to customers.
4.f. The Bank conducts post-incident analysis as a source of extracted lessons (lesson learned) in response and recovery of cyber incidents for continuous improvement. In conducting post-incident analysis, the Bank at least:
APPENDIX II
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 29 /SEOJK.03/2022 REGARDING CYBER RESILIENCE AND SECURITY FOR GENERAL BANKS
II.a. Working Paper on Inherent Risk Assessment related to Cyber Security Inherent Risk Assessment related to Cyber Security for Technology Factors
Technology
Assessment Result 1) Explanation 2)
Low (1) Low to
Moderate (2) Moderate (3) Moderate to
High (4) High (5)
1.1. Interconnection to
public internet
Less than or equal to 2 connections
4 connections
6 connections
8 connections
More than or equal to
10 connections
1.2. Interconnection to third
parties (third party)
More than 80% of total connections to third parties using Application Programming Interface (API) Up to 50% of total connections to third parties using API More than 80% of total connections to third parties using host to host Up to 50% of total connections to third parties using host to host More than 50% of total connections to third parties using direct connection
1.3. Access to Bank IT assets
Cable connections only for employees
Cable connections for employees only and Wi-Fi for third parties unauthorized All connections for employees and third parties authorized All connections for employees and third parties authorized, however Wi-Fi for public All connections for all parties
1.4. Intranet network from
the Bank's office network
The Bank has the Bank's office network that is The Bank has the Bank's office network that is distributed in 100 The Bank has the Bank's office network that is distributed in The Bank has the Bank's office network that is distributed in The Bank has the Bank's office network that is distributed
Technology
Assessment Result 1) Explanation 2)
Less than
100 locations up to 300 locations more than 300 up to 500 locations more than 500 up to 700 locations in more than 700 locations
1.5. Use of third-party
IT service providers in the operation of data centers No use of third-party IT service providers in the operation of data centers Use of third-party IT service providers other than cloud service providers in the operation of data centers Use of cloud service providers in the form of SaaS Use of cloud service providers in the form of PaaS Use of cloud service providers in the form of IaaS
1.6. Management of software used
to support
Bank's operational activities
(including back-office and IT needs)
All software used for supporting operational activities of the Bank (including back-office & IT needs) is managed (developed More than 70% of software used for supporting operational activities of the Bank (including back-office & IT needs) is managed (developed More than 50% of software used for supporting operational activities of the Bank (including back-office & IT needs) More than 30% of software used for supporting operational activities of the Bank (including back-office & IT needs) Up to 30% of software used for supporting operational activities of the Bank (including back-office & IT needs) is managed (developed and organized) by the Bank's IT team and organized) by the Bank's IT team is managed (developed and organized) by the Bank's IT team is managed (developed and organized) by the Bank's IT team and IT needs) is managed (developed and organized) by the Bank's IT team
1.7. Use of hardware and/or
software that has entered/is approaching
End of Life (EOL)
No hardware and/or software that exceeds the EOL period or approaching EOL (2 years from now will enter the EOL period) Up to 30% of hardware and/or software exceeds the EOL period or approaching EOL (2 years from now will enter the EOL period) Up to 50% of hardware and/or software exceeds the EOL period or approaching EOL (2 years from now will enter the EOL period) Up to 70% of hardware and/or software exceeds the EOL period or approaching EOL (2 years from now will enter the EOL period) More than 70% of hardware and/or software exceeds the EOL period or approaching EOL (2 years from now will enter the EOL period)
Technology
Result Assessment 1) Explanation 2)
Low (1) Low to Moderate (2) Moderate (3) Moderate to High (4) High (5)
1.8. Number of employees with access to connect personal devices to the Bank's network (Bring Your Own Device)
No access to connect personal devices to the Bank's network exists.
Access to connect personal devices to the Bank's network is held by less than 5% of employees.
Access to connect personal devices to the Bank's network is held by less than 10% of employees.
Access to connect personal devices to the Bank's network is held by less than 25% of employees.
Access to connect personal devices to the Bank's network is held by 25% of employees or more.
1.9. Software accessible using personal devices connected to the Bank's network
No software is accessible using personal devices.
Personal devices connected to the Bank's network can only access email.
Personal devices connected to the Bank's network can only access email and supporting applications (non-critical).
Personal devices connected to the Bank's network can access critical applications.
Personal devices connected to the Bank's network can access all systems/applications (including core banking system).
1.10. Third parties having access to the Bank's internal systems and/or sensitive information
No third parties or individuals from third parties have access to the Bank's internal systems and/or sensitive information.
Minimum number (1 – 3 entities or less than 10 individuals) have access to the Bank's internal systems and/or sensitive information.
Moderate number (4 – 6 entities or less than 20 individuals) have access to the Bank's internal systems and/or sensitive information.
Significant number (7 – 10 entities or less than 30 individuals) have access to the Bank's internal systems and/or sensitive information.
Substantial number (More than 10 entities or 30 individuals or more) have access to the Bank's internal systems and/or sensitive information.
Note:
Inherent Cyber Risk Assessment for Bank Product Factors
2. Bank Products
Assessment 1) Explanation 2)
Low (1) Low to Moderate (2) Moderate (3) Moderate to High (4) High (5)
2.1. Use of online and mobile channels in providing services
No applications (both back-office and for customers) use online and mobile channels.
Online and mobile channels are used for delivering general Bank information to the public (including notifications/news, office network locations, and available Bank products). Online and mobile channels are used for banking transaction services (Bank products) for corporate customers domestically. Online and mobile channels are used for banking transaction services (Bank products) for retail customers domestically. Online and mobile channels are used for:
Note:
Inherent Cyber Risk Assessment for Organizational Characteristics Factors
3. Organizational Characteristics
Assessment 1) Explanation 2)
Low (1) Low to Moderate (2) Moderate (3) Moderate to High (4) High (5)
3.1. Turnover in Human Resources handling IT/cyber resilience and security
Percentage of turnover in Human Resources handling IT/cyber resilience and security <5% in the last 1 year.
Percentage of turnover in Human Resources handling IT/cyber resilience and security <10% in the last 1 year.
Percentage of turnover in Human Resources handling IT/cyber resilience and security <15% in the last 1 year.
Percentage of turnover in Human Resources handling IT/cyber resilience and security < 20% in the last 1 year.
Percentage of turnover in Human Resources handling IT/cyber resilience and security ≥ 20% in the last 1 year.
3.2. Changes in the IT environment
Less than 3 critical system implementations in the last 1 year.
3-5 critical system implementations in the last 1 year.
6-8 critical system implementations in the last 1 year.
9-11 critical system implementations in the last 1 year.
11 critical system implementations in the last 1 year.
3.3. Management of privilege access (administrator and administrator-level) for all devices
All privilege access for all types of devices (host, network, database, application, and cloud) is managed by the IT unit.
Privilege access for 1 or 2 types of devices is managed by parties other than the IT unit.
Privilege access for 3 types of devices is managed by parties other than the IT unit.
Privilege access for 4 types of devices is managed by parties other than the IT unit.
Privilege access for more than 4 types of devices is managed by parties other than the IT unit.
Note:
Inherent Cyber Risk Assessment for Cyber Incident History Factors
4. Cyber Incident History
Assessment 1) Explanation 2)
Low (1) Low to Moderate (2) Moderate (3) Moderate to High (4) High (5)
4.1. Percentage of significant cyber incidents in the last 12 (twelve) months
No significant cyber incidents occurred.
Up to 30% of total cyber incidents were significant.
Up to 50% of total cyber incidents were significant.
Up to 70% of total cyber incidents were significant.
More than 70% of total cyber incidents were significant.
4.2. Scope of impact of cyber incidents in the last 12 (twelve) months
No impact (no cyber incidents occurred).
Cyber incidents only impacted the Bank internally.
Cyber incidents impacted third parties other than customers.
Cyber incidents impacted the availability of Bank products.
Cyber incidents impacted customer losses (e.g., leakage of customer personal data).
Note:
II.b. Cyber Resilience Management Implementation Quality Assessment Worksheet No. Domain 1) Subdomain 1) Control 1) Control Implementation 2) Explanation 3) Document Reference 4) Department/Unit/Position Responsible
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
II.c. Cyber Resilience Process Implementation Quality Assessment Worksheet No. Domain 1) Control 1) Control Implementation 2) Explanation 3) Document Reference 4) Department/Unit/Position Responsible
Established in Jakarta on 27 December 2022
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
DIAN EDIANA RAE
APPENDIX III
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 29 /SEOJK.03/2022 CONCERNING CYBER RESILIENCE AND SECURITY FOR GENERAL BANKS
III.a. Inherent Cyber Risk Level Determination Matrix Rating Rating Definition Low (1) Considering the business activities conducted by the Bank, the potential loss faced by the Bank from inherent cyber risk is classified as very low during a specific period in the future. Example characteristics of Banks included in the Low (1) rating:
a. The Bank uses very limited IT and vulnerability to cyber attacks is very low; b. no Bank products are distributed using IT and/or online and mobile channels;
c. turnover in Human Resources handling IT/cyber resilience and security is very low;
d. no significant cyber incidents occurred during the last 12 (twelve) months.
Low to Moderate (2) Considering the business activities conducted by the Bank, the potential loss faced by the Bank from inherent cyber risk is classified as low during a specific period in the future. Example characteristics of Banks included in the Low to Moderate (2) rating:
a. The Bank uses limited IT, vulnerability to cyber attacks is low, and the Bank conducts IT outsourcing with very low complexity; b. the type of Bank products distributed using IT and/or online and mobile channels is very limited;
c. turnover in Human Resources handling IT/cyber resilience and security is low;
d. the percentage of significant cyber incidents during the last 12 (twelve) months is very low and only impacts the Bank internally.
Moderate (3) Considering the business activities conducted by the Bank, the potential loss faced by the Bank from inherent cyber risk is classified as moderately high during a specific period in the future. Example characteristics of Banks included in the Moderate (3) rating:
a. The Bank uses moderately limited IT, vulnerability to cyber attacks is moderately low, and the Bank conducts IT outsourcing with low complexity; b. the type of Bank products distributed using IT and/or online and mobile channels is limited;
c. turnover in Human Resources handling IT/cyber resilience and security is moderately high;
d. the percentage of significant cyber incidents during the last 12 (twelve) months is low and impacts third parties other than customers.
Moderate to High (4) Considering the business activities conducted by the Bank, the potential loss faced by the Bank from inherent cyber risk is classified as high during a specific period in the future. Example characteristics of Banks included in the Moderate to High (4) rating:
a. The Bank uses complex IT in terms of scope and sophistication, vulnerability to cyber attacks is moderately high, and the Bank conducts critical IT outsourcing with moderately high complexity; b. the type of Bank products distributed using IT and/or online and mobile channels is quite numerous;
c. turnover in Human Resources handling IT/cyber resilience and security is high;
d. the percentage of significant cyber incidents during the last 12 (twelve) months is moderately high and impacts the availability of Bank products. High (5) Considering the business activities conducted by the Bank, the potential loss faced by the Bank from inherent cyber risk is classified as very high during a specific period in the future. Example characteristics of Banks included in the High (5) rating:
a. The Bank uses very complex IT in terms of scope and sophistication, vulnerability to cyber attacks is very high, and the Bank conducts critical IT outsourcing with high complexity; b. the type of Bank products distributed using IT and/or online and mobile channels is very high;
c. turnover in Human Resources handling IT/cyber resilience and security is very high;
d. the percentage of significant cyber incidents during the last 12 (twelve) months is very high and directly impacts customer losses.
III.b. Cyber Risk Management Implementation Quality Determination Matrix Rating Rating Definition Strong (1) The quality of cyber risk management implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored. Example characteristics of Banks included in the Strong (1) rating:
a. active oversight by the Board of Directors and Board of Commissioners overall is very adequate; b. Human Resources are very adequate, both in terms of quantity and competence in the cyber risk management function;
c. organizational structure related to the implementation of cyber risk management across all work units has operated very well;
d. the Board of Directors and Board of Commissioners have very good awareness and understanding of cyber risk management; e. cyber risk management culture and awareness have been developed and implemented very well throughout the Bank's organizational environment; f. Human Resources capacity building programs in information security and cyber risk management are very adequate; g. the determination of risk levels to be taken (risk appetite) and risk tolerance are very adequate and very consistent with the Bank's strategic objectives and business strategy; h. cyber risk management strategy is very consistent with the risk levels to be taken (risk appetite) and risk tolerance regarding cyber security;
i. risk management policies and procedures and the determination of risk limits regarding cyber security are very adequate and available for all areas of cyber risk management, consistent with implementation, and well understood by employees;
j. the cyber risk management process is very adequate in identifying, measuring, monitoring, and controlling cyber risk; k. the cyber risk management information system is very good, producing comprehensive and integrated cyber risk reports to the Board of Directors and Board of Commissioners;
l. the internal control system is very effective in supporting the implementation of cyber risk management;
m. independent review implementation by internal audit work units and work units performing cyber risk management functions is very adequate, in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners; n. generally, no significant weaknesses exist based on independent review results; o. follow-up on independent reviews has been implemented very adequately. Satisfactory (2) The quality of cyber risk management implementation is adequate. Although there are several minor weaknesses, these weaknesses can be resolved in normal business activities. Example characteristics of Banks included in the Satisfactory (2) rating:
a. active oversight by the Board of Directors and Board of Commissioners overall is adequate; b. Human Resources are adequate, both in terms of quantity and competence in the cyber risk management function;
c. organizational structure related to the implementation of cyber risk management across all work units has operated well;
d. the Board of Directors and Board of Commissioners have good awareness and understanding of cyber risk management; e. cyber risk management culture and awareness have been developed and implemented well throughout the Bank's organizational environment; f. Human Resources capacity building programs in information security and cyber risk management are adequate; g. the determination of risk levels to be taken (risk appetite) and risk tolerance are adequate and consistent with the Bank's strategic objectives and business strategy; h. cyber risk management strategy is consistent with the risk levels to be taken (risk appetite) and risk tolerance regarding cyber security;
i. risk management policies and procedures and the determination of risk limits regarding cyber security are adequate and available for all areas of cyber risk management, consistent with implementation, and well understood by employees although there are minor weaknesses;
j. the cyber risk management process is adequate in identifying, measuring, monitoring, and controlling cyber risk; k. the cyber risk management information system is good, producing comprehensive and integrated cyber risk reports to the Board of Directors and Board of Commissioners;
l. the internal control system is effective in supporting the implementation of cyber risk management;
m. independent review implementation by internal audit work units and work units performing cyber risk management functions is adequate, in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners; n. there are weaknesses that are not significant based on independent review results; o. follow-up on independent reviews has been implemented adequately. Fair (3) The quality of cyber risk management implementation is fairly adequate. Although minimum requirements are met, there are several weaknesses requiring management attention. Example characteristics of Banks included in the Fair (3) rating:
a. active oversight by the Board of Directors and Board of Commissioners overall is fairly adequate; b. Human Resources are fairly adequate, both in terms of quantity and competence in the cyber risk management function;
c. organizational structure related to the implementation of cyber risk management across all work units has operated fairly well;
d. the Board of Directors and Board of Commissioners have fairly good awareness and understanding of cyber risk management; e. cyber risk management culture and awareness have been developed and implemented fairly well throughout the Bank's organizational environment; f. Human Resources capacity building programs in information security and cyber risk management are fairly adequate; g. the determination of risk levels to be taken (risk appetite) and risk tolerance are fairly adequate but not always consistent with the Bank's strategic objectives and business strategy; h. cyber risk management strategy is fairly consistent with the risk levels to be taken (risk appetite) and risk tolerance regarding cyber security;
i. risk management policies and procedures and the determination of risk limits regarding cyber security are fairly adequate but not always consistent with implementation;
j. the cyber risk management process is fairly adequate in identifying, measuring, monitoring, and controlling cyber risk; k. the cyber risk management information system is fairly good, including comprehensive and integrated cyber risk reporting to the Board of Directors and Board of Commissioners;
l. the internal control system is fairly effective in supporting the implementation of cyber risk management;
m. independent review implementation by internal audit work units and work units performing cyber risk management functions is fairly adequate, in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners; n. there are weaknesses that are fairly significant based on independent review results requiring management attention;
o. Follow-up on independent review has been implemented adequately.
Marginal (4) The quality of cyber-related risk management implementation is inadequate. There are significant weaknesses in various aspects of cyber-related risk management requiring immediate corrective action.
Examples of Bank characteristics included in the Marginal (4) rating:
a. Active supervision by the Board of Directors and Board of Commissioners as a whole is inadequate, and there are weaknesses in various assessment aspects requiring immediate improvement; b. Human resources are inadequate, both in quantity and competence in the cyber-related risk management function;
c. organizational structure related to the implementation of cyber-related risk management across all work units does not function well;
d. significant weaknesses in the awareness and understanding of the Board of Directors and Board of Commissioners regarding cyber-related risk management; e. the culture and awareness of cyber-related risk management are less developed and implemented well throughout the Bank's organizational environment; f. human resource capacity enhancement programs in the field of information security and cyber-related risk management are inadequate; g. the determination of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and does not align with the Bank's strategic objectives and business strategy; h. the cyber-related risk management strategy is less aligned with the level of risk to be taken (risk appetite) and risk tolerance related to cyber security;
i. risk management policies and procedures and the determination of risk limits related to cyber security are inadequate and not aligned with implementation;
j. the cyber-related risk management process is inadequate in identifying, measuring, monitoring, and controlling cyber-related risks; k. significant weaknesses in the information system for cyber-related risk management, including reporting on cyber-related risks to the Board of Directors and Board of Commissioners, which require immediate improvement;
l. the internal control system is less effective in supporting the implementation of cyber-related risk management;
m. the implementation of independent review by the internal audit work unit and the work unit performing the cyber-related risk management function is inadequate, both in terms of methodology, frequency, and reporting to the Board of Directors and Board of Commissioners;
n. there are significant weaknesses based on the results of independent review requiring immediate improvement; o. follow-up on independent review is implemented inadequately.
Unsatisfactory (5) The quality of cyber-related risk management implementation is inadequate. There are significant weaknesses in various aspects of cyber-related risk management whose resolution is beyond the management's capability.
Examples of Bank characteristics included in the Unsatisfactory (5) rating:
a. active supervision by the Board of Directors and Board of Commissioners as a whole is inadequate and there are weaknesses in almost all assessment aspects and the resolution is beyond the Bank's capability; b. human resources are inadequate, both in quantity and competence in the cyber-related risk management function;
c. organizational structure related to the implementation of cyber-related risk management across all work units does not function well;
d. the awareness and understanding of the Board of Directors and Board of Commissioners regarding cyber-related risk management is very weak; e. the culture and awareness of cyber-related risk management are not developed and implemented in the Bank's organizational environment or do not exist at all; f. human resource capacity enhancement programs in the field of information security and cyber-related risk management are inadequate; g. the determination of the level of risk to be taken (risk appetite) and risk tolerance is inadequate and there is no connection with the Bank's strategic objectives and business strategy; h. the cyber-related risk management strategy is not aligned with the level of risk to be taken (risk appetite) and risk tolerance related to cyber security;
i. very significant weaknesses in risk management policies and procedures and the determination of risk limits related to cyber security;
j. the cyber-related risk management process is inadequate in identifying, measuring, monitoring, and controlling cyber-related risks; k. fundamental weaknesses in the information system for cyber-related risk management;
l. the internal control system is ineffective in supporting the implementation of cyber-related risk management;
m. the implementation of independent review by the internal audit work unit and the work unit performing the cyber-related risk management function is inadequate, and there are weaknesses in methodology, frequency, and/or reporting to the Board of Directors and Board of Commissioners requiring fundamental improvement;
n. there are very significant weaknesses based on the results of independent review requiring immediate improvement; o. follow-up on independent review is inadequate or non-existent.
Rating Definition Rating
Strong (1) The quality of cyber resilience process implementation is very adequate. Although there are minor weaknesses, these weaknesses are not significant and can be ignored.
Examples of Bank characteristics included in the Strong (1) rating:
a. the asset, threat, and vulnerability identification process is very adequate; b. the asset protection process is implemented very well;
c. the cyber incident detection process is very reliable and tested;
d. the cyber incident response and recovery process is implemented very well and does not cause significant disruption.
Satisfactory (2) The quality of cyber resilience process implementation is adequate. Although there are some minor weaknesses, these weaknesses can be resolved in normal business activities.
Examples of Bank characteristics included in the Satisfactory (2) rating:
a. the asset, threat, and vulnerability identification process is adequate; b. the asset protection process is implemented well;
c. the cyber incident detection process is reliable and tested;
d. the cyber incident response and recovery process is implemented well although there is disruption but it is not significant.
Fair (3) The quality of cyber resilience process implementation is fairly adequate. Although minimum requirements are met, there are some weaknesses that require management attention.
Examples of Bank characteristics included in the Fair (3) rating:
a. the asset, threat, and vulnerability identification process is fairly adequate; b. the asset protection process is implemented fairly well;
c. the cyber incident detection process is fairly reliable and tested;
d. the cyber incident response and recovery process is implemented fairly well but still causes minor disruption.
Marginal (4) The quality of cyber resilience process implementation is inadequate. There are significant weaknesses in various processes to maintain cyber resilience requiring immediate corrective action.
Examples of Bank characteristics included in the Marginal (4) rating:
a. the asset, threat, and vulnerability identification process is inadequate; b. the asset protection process is implemented less well;
c. the cyber incident detection process is less reliable and tested;
d. the cyber incident response and recovery process is implemented less well and causes significant disruption.
Unsatisfactory (5) The quality of cyber resilience process implementation is inadequate. There are significant weaknesses in various processes to maintain cyber resilience whose resolution is beyond management's capability.
Examples of Bank characteristics included in the Unsatisfactory (5) rating:
a. the asset, threat, and vulnerability identification process is inadequate; b. the asset protection process is not implemented well;
c. the cyber incident detection process is not reliable and tested;
d. the cyber incident response and recovery process is not implemented well so as to cause very significant disruption.
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
Rating Definition Rating
Level 1 Reflects the Bank's cyber security maturity condition which is generally very high, reflected in the implementation of cyber-related risk management and cyber resilience processes which are generally very good. In case there are weaknesses, generally these weaknesses are not significant.
Level 2 Reflects the Bank's cyber security maturity condition which is generally high, reflected in the implementation of cyber-related risk management and cyber resilience processes which are generally good. In case there are weaknesses, generally these weaknesses are less significant.
Level 3 Reflects the Bank's cyber security maturity condition which is generally fair, reflected in the implementation of cyber-related risk management and cyber resilience processes which are generally fairly good. In case there are weaknesses, generally these weaknesses are fairly significant and if not successfully addressed well by management, it can disrupt the Bank's business continuity.
Level 4 Reflects the Bank's cyber security maturity condition which is generally low, reflected in the implementation of cyber-related risk management and cyber resilience processes which are generally less good. There are weaknesses that are generally significant and cannot be addressed well by management and disrupt the Bank's business continuity.
Level 5 Reflects the Bank's cyber security maturity condition which is generally very low, reflected in the implementation of cyber-related risk management and cyber resilience processes which are generally less good. There are weaknesses that are generally very significant so that to address them, funding support from shareholders or funding sources from other parties is required to strengthen the implementation of cyber-related risk management and cyber resilience processes at the Bank.
Established in Jakarta on December 27, 2022
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
DIAN EDIANA RAE
FINANCIAL SERVICES AUTHORITY CIRCULAR LETTER
NUMBER 29 /SEOJK.03/2022
CONCERNING
CYBER RESILIENCE AND SECURITY FOR COMMERCIAL BANKS
INITIAL CYBER INCIDENT NOTIFICATION
A. BANK INFORMATION
B. GENERAL CYBER INCIDENT INFORMATION
Notes:
CYBER INCIDENT REPORT
A. REPORTER INFORMATION
B. GENERAL CYBER INCIDENT INFORMATION 2)
C. ASSESSMENT OF CYBER INCIDENT IMPACT ON THE BANK 7)
D. INCIDENT CHRONOLOGY INFORMATION
Duration of the cyber incident occurrence.
Steps taken for cyber incident escalation.
Steps taken for cyber incident response.
Steps taken for cyber incident recovery.
Involvement of third parties in cyber incident response and recovery.
Parties receiving information related to the cyber incident (stakeholders, examples: authorities, service partners, and customers).
Supporting information used to identify the cyber attack, if known.
(example: suspicious IP addresses, unusual network traffic, high authentication failure rates, and repeated file requests)
E. ANALYSIS OF THE CAUSE OF THE INCIDENT
c. Attack Motif : …………………..
15)
2. Incident causing factors : ………………….. 16)
F. FINAL ANALYSIS
Notes:
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
Established in Jakarta on December 27, 2022
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
DIAN EDIANA RAE
FINANCIAL SERVICES AUTHORITY CIRCULAR LETTER
NUMBER 29 /SEOJK.03/2022
CONCERNING
CYBER RESILIENCE AND SECURITY FOR COMMERCIAL BANKS
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
Bank Cyber Security Assessment Results
Bank Name :
Year :
Inherent Cyber Security Risk Assessment
| No. | Assessment Factor | Rating |
|---|---|---|
| 1. | Technology | |
| 2. | Bank Products | |
| 3. | Organizational Characteristics |
Cyber Security Maturity Level Assessment
| No. | Assessment Factor | Rating |
|---|---|---|
| 1. | Quality of Cyber-Related Risk Management Implementation | |
| 2. | Quality of Cyber Resilience Process Implementation | |
| 3. | Cyber Incident Track Record |
Inherent Cyber Security Risk Rating
Cyber Security Maturity Level Rating
Analysis
Further explanation regarding the assessment of inherent cyber security risk at the Bank, including the Bank's considerations for each assessment factor to obtain the inherent cyber security risk rating.
Analysis
Further explanation regarding the assessment of cyber security maturity level at the Bank, including the Bank's considerations for each assessment factor to obtain the cyber security maturity level rating.
Cyber Security Risk Level Rating
Analysis
Further explanation regarding the determination of the cyber security risk level at the Bank, including the Bank's considerations regarding the inherent cyber security risk rating and the cyber security maturity level rating to obtain the cyber security risk level.
Attachments:
Established in Jakarta on December 27, 2022
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
DIAN EDIANA RAE
FINANCIAL SERVICES AUTHORITY CIRCULAR LETTER
NUMBER 29 /SEOJK.03/2022
CONCERNING
CYBER RESILIENCE AND SECURITY FOR COMMERCIAL BANKS
This copy is consistent with the original
Legal Director 1
Legal Department signed
Mufli Asmawidjaja
Report on Cyber Security Testing Results Based on Scenarios
Bank Name :
Year :
| No. | Testing Objective | Testing Type 1) | Testing Scope | Testing Start Date | Testing End Date | Involved Party 2) | Testing Summary | Testing Result 3) | Improvements Made 4) | Follow-up Plan 5) |
|---|---|---|---|---|---|---|---|---|---|---|
Notes:
Established in Jakarta on December 27, 2022
EXECUTIVE HEAD OF BANKING SUPERVISOR
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
DIAN EDIANA RAE
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.