2021-08-24 | SEOJK NOMOR 22/SEOJK.05/2021Added
Non-Bank Financial Service Institutions (LJKNB) are required to implement comprehensive information technology risk management, including active oversight by the Board of Directors and Board of Commissioners, adequate policies and procedures, and robust internal control systems. The regulation mandates documentation covering organizational structure, risk management components, IT policies, application architecture, data centers, disaster recovery plans, and third-party service providers. Specific requirements are imposed on the IT development lifecycle, procurement processes, system testing, implementation, maintenance, and destruction phases to ensure operational resilience and data integrity.
OJK published 7 documents in the last 30 days — get each new one by email the day it lands.
To:
COPY
CIRCULAR LETTER OF THE FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA NUMBER 22 /SEOJK.05/2021 CONCERNING THE IMPLEMENTATION OF INFORMATION TECHNOLOGY RISK MANAGEMENT BY NON-BANK FINANCIAL SERVICE INSTITUTIONS
In accordance with the mandate of Article 33 of Financial Services Authority Regulation Number 4/POJK.05/2021 concerning the Implementation of Information Technology Risk Management by Non-Bank Financial Service Institutions (State Gazette of the Republic of Indonesia Year 2021 Number 78, Supplement to the State Gazette of the Republic of Indonesia Number 6668), it is necessary to regulate further provisions regarding the implementation of information technology risk management by non-bank financial service institutions in this Financial Services Authority Circular as follows:
I. GENERAL PROVISIONS
In this Financial Services Authority Circular, the following definitions apply:
Non-Bank Financial Service Institution, hereinafter referred to as LJKNB, is an institution that conducts activities in the insurance, pension fund, financing institution, and other financial service sectors.
Information Technology is a technique to collect, prepare, store, process, announce, analyze, and/or disseminate information.
Electronic Financial Service is a service for consumers to obtain information, communicate, and conduct financial transactions through electronic media.
Electronic System is a series of electronic devices and procedures that function to prepare, collect, process, analyze, store, display, announce, send, and/or disseminate electronic information.
Data Center is a facility used to place an Electronic System and its related components for the purposes of placement, storage, and data processing.
Disaster Recovery Center is a facility used to restore data or information and important functions of an Electronic System that are disrupted or damaged due to disasters caused by nature or humans.
Database is a comprehensive set of data arranged systematically, accessible by users according to their respective authorities, and managed by a Database Administrator.
Disaster Recovery Plan is a document containing plans and steps to replace and/or restore access to data, hardware, and software required, so that LJKNB can carry out critical business operational activities after a disruption and/or disaster.
Board of Directors is a corporate organ authorized and fully responsible for managing the corporation for the interests of the corporation, in accordance with the purpose and objectives of the corporation, and representing the corporation, both in and out of court, in accordance with the articles of association for LJKNB in the form of a limited liability company or equivalent to the Board of Directors for LJKNB in the form of a cooperative legal entity, joint venture, pension fund, Indonesian Export Financing Institution, social security guarantee organization, or limited partnership company.
Board of Commissioners is a corporate organ tasked with conducting general and/or specific supervision in accordance with the articles of association and providing advice to the Board of Directors for LJKNB in the form of a limited liability company or equivalent to the Board of Commissioners for LJKNB in the form of a cooperative legal entity, joint venture, pension fund, Indonesian Export Financing Institution, social security guarantee organization, or limited partnership company.
II. SCOPE OF NON-BANK FINANCIAL SERVICE INSTITUTIONS
LJKNB as referred to in Section I number 1 includes:
Insurance companies, consisting of:
a. insurance companies; b. reinsurance companies;
c. sharia insurance companies;
d. sharia reinsurance companies; e. insurance brokerage companies; f. reinsurance brokerage companies; and g. insurance loss assessor companies, as referred to in legislation concerning insurance;
Pension funds as referred to in legislation concerning pension funds;
Financing institutions, consisting of:
a. financing companies; b. sharia financing companies;
c. venture capital companies;
d. sharia venture capital companies; and e. infrastructure financing companies, as referred to in legislation concerning financing institutions;
Other financial service institutions, consisting of:
a. pawnshop companies as referred to in legislation concerning pawnshops; b. guarantee institutions, consisting of
III. SCOPE OF INFORMATION TECHNOLOGY RISK MANAGEMENT
The implementation of information technology risk management covers at least:
a. active oversight by the Board of Directors and Board of Commissioners; b. adequacy of policies and procedures for the use of Information Technology;
c. adequacy of processes for identifying, measuring, controlling, and monitoring information technology usage risks; and
d. internal control systems regarding the use of Information Technology.
The implementation of risk management as referred to in number 1 is carried out in an integrated manner in every stage of Information Technology usage, from the planning, procurement, development, operational, maintenance, to the cessation and deletion of Information Technology resources.
The implementation of information technology risk management as referred to in number 1 must be adjusted to the purpose, business policies, size, and complexity of the LJKNB's business.
The implementation of information technology risk management as referred to in number 1 is manifested in good documentation of at least the following aspects:
a. organization and management supporting the implementation of information technology risk management; b. application of risk management components in the use of Information Technology;
c. policies and procedures for the use of Information Technology;
d. application architecture; e. application list; f. communication network; g. Data Center and Disaster Recovery Center; h. Information Technology security;
i. Disaster Recovery Plan;
j. Information Technology service providers; and k. Information Technology costs.
The documentation as referred to in number 4 is prepared in accordance with formats 1 through 11 contained in the Appendix, which is an integral part of this Financial Services Authority Circular.
IV. ACTIVE OVERSIGHT BY THE BOARD OF DIRECTORS AND BOARD OF COMMISSIONERS
LJKNB must establish clear authority and responsibility of the Board of Directors, Board of Commissioners, and officials at every level of position related to the use of Information Technology in writing.
For LJKNB that has an Information Technology oversight committee, the execution of the duties and responsibilities of the Information Technology oversight committee is manifested through regular meetings documented in meeting minutes.
Regular meetings as referred to in number 2 may involve relevant working units within LJKNB and can be conducted physically or virtually.
The Information Technology steering committee establishes the time frame for regular meetings as referred to in number 3 in written policies.
V. ADEQUACY OF POLICIES AND PROCEDURES FOR THE USE OF INFORMATION TECHNOLOGY
Policies and procedures for the use of Information Technology must contain at least the following aspects:
a. management; b. development and procurement;
c. Information Technology operations;
d. communication network; e. information security; f. Disaster Recovery Plan; g. use of Information Technology service providers; and h. Electronic Financial Services, for LJKNB that provide Electronic Financial Services.
Policies and procedures for the management aspect as referred to in number 1 letter a must consist of at least:
a. risk awareness regarding the provision of Information Technology from management; b. clear understanding of the risk level to be taken (risk appetite), risk tolerance, and risk limits of LJKNB;
c. understanding of legislation concerning Information Technology; and
d. transparency and responsibility regarding significant risks of each aspect related to the provision of Information Technology.
Policies and procedures for the development and procurement aspect as referred to in number 1 letter b include:
a. development stages:
The initiation and planning stage as referred to in number 3 letter a number 1) must consist of at least:
a. Preparation of a proposal containing:
The user needs definition stage as referred to in number 3 letter a number 2) must consist of at least:
a. needs collection, which is a process of collecting information, either through interviews, research, or filling out specific forms, regarding the objectives of system development, desired output, system capabilities to accommodate business process needs and system working mechanisms, and system usage procedures; b. needs analysis, which is a process of understanding problems and needs to determine solutions that can be developed;
c. needs specification, which is a process to describe the functionality of the system to be developed, process or procedure specifications, and existing systems, both in terms of software and supporting hardware as well as Database design; and
d. needs management, which is a process to identify, control, and store every change to needs during the system development process.
The system design stage as referred to in number 3 letter a number 3) is a process of converting identified information needs, functions, and infrastructure during the initiation and planning stage into design specifications or designs that form the basis for system development. During the system design stage, control must be exercised over aspects including authorized, accurate, complete, and secure input information, processes, and output.
The programming stage as referred to in number 3 letter a number 4) must consist of at least:
a. programming standards, which include the elaboration of programmer responsibilities and the rights of parties directly involved in the programming process, namely by:
The testing stage as referred to in number 3 letter a number 5) includes among others:
a. unit test, which is a trial conducted by the developer on the functionality of each unit or sub-module of the system that has been fully developed; b. system integration test, which is testing conducted by the developer on the overall functionality of the system after being integrated into a complete whole;
c. stress test, which is a resilience test conducted by the developer on the system's ability to handle processes or transactions on a large scale or quantity, with further criteria regarding processes or transactions on a large scale or quantity to be determined further by LJKNB; and
d. user acceptance test, which is a final trial conducted by the end-user on the system that has been fully developed to test the functionality of the entire system, whether it has met the user needs defined in the user needs definition stage before deciding that implementation can be carried out.
In the event that the results of testing at the user acceptance test stage as referred to in number 8 letter d have met user needs and LJKNB's security standards, a minutes of the test approved by the end-user must be created.
The implementation stage as referred to in number 3 letter a number 6) must consider among others:
a. program integrity checks, which are adequate controls over the conversion from source code to the system to be implemented; b. data migration from the old system to the new system;
c. checks on the accuracy and security of migrated data in the new system;
d. the possibility of implementing a parallel run 2 between the old and new systems, until it is certain that the data in the new system is accurate and reliable; e. certainty of data integrity, namely the accuracy and reliability of the Database, including data stored within it; f. direct data and reference repairs (patching data) during implementation must be avoided as it can affect data integrity in the production server Database; g. storage arrangements for source code and Database from the old system; and h. anticipation of weaknesses in the operating system, developed systems, Database, and network, including threats from unauthorized parties such as viruses 3, trojan horses 4, worms 5, spyware 6, Denial-of-Service (DoS) 7, wardriving, spoofing 8, and logic bombs 9, by testing and applying security controls over the system to be implemented.
The post-implementation review stage as referred to in number 3 letter a number 7) includes analysis of:
a. the effectiveness of project management activities by comparing among others plans and actual costs, benefits obtained, and project schedule accuracy; and b. system performance, problems encountered, and steps taken to resolve those problems.
The results of the analysis as referred to in number 11 are documented and reported to management.
The maintenance stage as referred to in number 3 letter a number 8) is conducted to establish maintenance methodologies appropriate to the characteristics and risks of each project of the systems owned by LJKNB.
The destruction stage as referred to in number 3 letter a number 9) is the final process of system development by deleting or destroying systems, including data that are no longer used, to avoid misuse by unauthorized parties.
Procurement guidelines as referred to in number 3 letter b number 1) must consider among others:
a. submission or proposal of procurement plans to obtain management approval, which must contain at least analysis of user needs regarding the expected objectives and benefits, cost-benefit analysis, and the benefits of the system to be procured to support LJKNB's business needs; b. the suitability of Information Technology service providers, contracts, licenses, and products obtained with LJKNB's Information Technology provision needs;
c. the suitability of specifications offered by Information Technology service providers with the specifications of Information Technology provision needs at LJKNB;
d. comparison of offers submitted among Information Technology service providers; and e. the financial condition of Information Technology service providers and the commitment of Information Technology service providers to the services provided to LJKNB.
Purchase and license contracts as referred to in number 3 letter b number 2) must consider among others:
a. written explanation that the use of software is exclusive or not; b. information and the number of users who can use the software;
c. a list of other related entities that can use the software, such as subsidiaries or corporate groups;
d. information regarding software development in-house or outsourcing by Information Technology service providers, and whether software purchases include source code or not, or are only usage rights or rentals with time or feature restrictions; and e. usage location, whether the license usage location is limited to a specific location or not.
Maintenance as referred to in number 3 letter b number 3) covers at least:
a. training by Information Technology service providers to LJKNB; b. Information Technology service providers providing software documentation, including technical instructions for using the software;
c. implementation and costs for software updates and/or modifications;
d. the possibility for LJKNB to access source code in the event that Information Technology service providers can no longer provide services or there is a need for modifications that cannot be performed by Information Technology service providers; and e. the possibility for Information Technology service providers to assist in the data conversion process during system replacement in the future.
Warranty as referred to in number 3 letter b number 4) has aspects covering at least:
a. not violating the intellectual property rights of other parties, both domestically and internationally; b. not containing secret codes, undisclosed restrictions, or automatic restrictions in the agreement;
c. functioning according to specifications and must state the limitations of the responsibility of Information Technology service providers in the event of problems;
d. maintenance is carried out by Information Technology service providers during the agreed period; and e. remains valid in the event of mergers, consolidations, takeovers, or changes in ownership, both for LJKNB or Information Technology service providers.
Dispute resolution as referred to in number 3 letter b number 5) covers at least dispute resolution clauses in license agreements between LJKNB and Information Technology service providers.
Contract amendments as referred to in number 3 letter b number 6) must be based on agreements containing clauses that clearly state that Information Technology service providers
--- Footnotes ---
cannot modify the agreement without the consent of both parties.
Security as referred to in item 3 letter b item 7) includes at least:
a. continuous responsibility of the Information Technology service provider to protect the security and confidentiality of Information Technology resources and LJKNB data; b. prohibition for the Information Technology service provider to use or disclose information owned by LJKNB without LJKNB's consent;
c. assurance from the Information Technology service provider that the software does not contain features that can access the system and/or data without authentication process (back door 10) that allows access by unauthorized parties to LJKNB's system and data; and
d. an explicit statement that the Information Technology service provider will not use features that could cause the software to malfunction.
The transfer of some activities (subcontracting) to other parties as referred to in item 3 letter b item 8) includes at least clauses stating that the Information Technology service provider:
a. can only transfer some activities (subcontracting) to third parties based on LJKNB's consent, evidenced by written documents; and b. is responsible for the software even if the software is designed and/or developed by other parties.
Policies and procedures for IT operational aspects as referred to in item 1 letter c include at least:
a. Data management policies and procedures, which consist of at least:
10 Method to bypass normal authentication or secure remote access from a computer to access a system but not identified through normal inspection.
11 A set of code added to software to fix an error, usually a temporary correction between two software version releases.
b) avoiding the use of room windows that directly face sunlight, unless the room windows have adequate covering media to prevent sunlight exposure into the room; c) the use of raised floors; d) availability of emergency doors; and e) management of support equipment such as the availability of racks with non-flammable materials, placement of cables and other network infrastructure, and others; d. Data Center operational activities, including:
In formulating policies and procedures regarding Disaster Recovery Center management as referred to in item 23 letter a item 2), LJKNB must pay attention to the following:
a. the placement of the Disaster Recovery Center is not located in earthquake, flood, or lightning-prone areas and is connected to communication and electricity infrastructure different from the Data Center, as well as other facilities necessary for the continued operation of the system; b. the system at the Disaster Recovery Center must be compatible with the system used at the Data Center and must be adjusted if there are changes at the Data Center;
c. considering the travel time to ensure the recovery process; and
d. agreements with Information Technology service providers, in the event that the provision and management of Disaster Recovery Centers are carried out by Information Technology service providers, concerning the performance, reputation of the service provider, and continuity of service provision.
In formulating policies and procedures regarding Database management as referred to in item 23 letter a item 3), LJKNB must pay attention to the following:
a. the availability of human resources with competence in Database management, specifically regarding access, maintenance, problem handling, and Database administration; and b. the existence of a data backup mechanism where:
Policies and procedures for communication network aspects as referred to in item 1 letter d include at least:
a. network performance measurement and capacity planning; b. network security;
c. network management;
d. network problem handling procedures; e. network communication usage mechanism, including internet, intranet, and wireless networks; f. problem resolution procedures; g. facilities for backup and recovery; and h. agreements and contracts containing fulfillment of service levels in accordance with the service level agreement with Information Technology service providers, in the event that the provision and management of communication networks are carried out by Information Technology service providers.
Information security policies as referred to in item 1 letter e include at least:
a. information security objectives; b. management commitment to information security;
c. framework for establishing controls and handling information security problems;
d. compliance with internal regulations and legislation regarding information security; e. training and increasing awareness of the importance of information security; f. duties and responsibilities of parties in information security; g. analysis of the impact of information security on the continuity of LJKNB's business and operations; h. sanctions for violations of information security policies; and
i. documents or other regulations supporting information security policies.
Information security procedures as referred to in item 1 letter e include at least:
a. asset management, which includes at least:
12 User id that has very broad authority.
13 Special code or symbol to secure computer systems, i.e., to identify parties accessing data, programs, or computer applications used.
number 15, or biometrics 16, completeness of security equipment inside the room (e.g., alarms, detectors and fire extinguishers, temperature and humidity measuring instruments, or CCTV) and maintenance of room and equipment cleanliness (e.g., from dust, cigarettes, food, drinks, or flammable items);
3) support facilities such as air conditioners and electricity resources must ensure capacity and availability in supporting the operation of information processing facilities;
4) assets belonging to Information Technology service providers must be clearly identified and given adequate protection, for example by applying sufficient security, dual control 17, or placing them separately from LJKNB assets; and
5) periodic maintenance and inspection of information processing facilities and support facilities in accordance with established procedures;
d. Access control, which includes at least:
14 Electronic device used to provide environmental access security using cards.
15 A unique series of digits consisting of letters, numbers, or ASCII codes used to identify, among others, computer users, ATM users, internet banking users, and mobile banking users.
16 Utilization of technology by identifying a person's biological characteristics.
17 Security performed in layers involving the approval of 2 (two) or more people.
18 Basic principle in automatic processing
(3) not based on the user's personal data such as name, phone number, or date of birth; and (4) not using common words and easily guessed by software (to avoid brute force attacks), e.g., the word 'pass', 'password', 'adm', or common words in the dictionary; d) change passwords periodically; and e) avoid using the same password repeatedly;
7) procedures to disable access rights if user-ids are not used for a certain period, set the maximum number of password failures, and disable users after reaching the maximum number of password failures;
8) periodic review procedures by work units not involved in operational access control, regarding user access rights to ensure that access rights correspond to the authority granted;
9) operating systems, application systems, Databases, utilities, and other devices owned by LJKNB can help implement password security, for example:
a) forcing users to change passwords after a certain period and rejecting if users enter the same password as previously used when changing passwords; b) storing passwords securely (encrypted); c) disconnecting or accessing users if there is no response for a certain period; d) disabling or deleting user access rights if users do not log-in for a certain period, e.g., due to leave, rotation, and/or transfer; and e) access restriction procedures at least through the use of passwords and setting authorized parties for access for LJKNB using file sharing; e. IT operational security, which includes at least:
Policies and procedures for Disaster Recovery Plan aspects as referred to in item 1 letter f include at least:
a. analysis of the Disaster Recovery Plan; b. types of Disaster Recovery Plan procedures;
c. components of Disaster Recovery Plan procedures;
d. determination of clear responsibilities for related parties in the implementation of the Disaster Recovery Plan; e. Disaster Recovery Plan testing; and f. updating of the Disaster Recovery Plan.
Analysis of the Disaster Recovery Plan as referred to in item 30 letter a is an analysis of the possibility of risks arising from factors including:
a. fire factors; b. natural disaster factors such as floods and earthquakes;
c. technical disturbance factors such as hardware failure, software failure, electricity disturbances, data transmission disturbances, and
d. human factors such as human error and/or sabotage.
Types of Disaster Recovery Plan procedures as referred to in item 30 letter b include at least:
a. emergency response procedures, to control systems during disturbances/disasters, reduce loss impacts, and determine disaster status; b. system recovery procedures that allow LJKNB's operational activities to return to normal conditions; and
c. data synchronization procedures used to ensure equality between machine data used for operations and data backups, as well as to ensure that all business processing results during the recovery period have entered the system.
Components of Disaster Recovery Plan procedures as referred to in item 30 letter c include at least:
a. human resources, namely the Disaster Recovery Plan must explain the composition, authority, and responsibilities of every human resource related to the implementation of Information Technology and have adequate communication channels; b. Information Technology resources and core applications of Non-Bank Financial Service Institutions (LJKNB), namely LJKNB must have complete procedures and documentation to restore main applications related to LJKNB's business activities as well as other LJKNB operations; and
c. communication facilities, to ensure the availability of alternative communication channels that can be used in the internal and/or external environment in the event of disruption or disaster.
The determination of clear responsibilities for related parties in the implementation of the Disaster Recovery Plan as referred to in item 30 letter d includes at least regarding responsibilities:
a. management; b. the Information Technology implementation work unit; and
c. supporting work units, such as work units that oversee logistics functions.
Management responsibilities as referred to in item 34 letter a cover at least:
a. establishing written policies and procedures for the Disaster Recovery Plan; b. reviewing and approving the Disaster Recovery Plan;
c. evaluating the feasibility of the Disaster Recovery Plan of third-party Information Technology service providers, in the event LJKNB uses the services of third-party Information Technology service providers; and
d. determining the level of disruption and disaster and its recovery.
Information Technology implementation work unit responsibilities as referred to in item 34 letter b cover at least:
a. the effectiveness of the Disaster Recovery Plan implementation; b. the determination of recovery scenarios to be used in the event of disruption or disaster based on prioritization of systems considered critical; and
c. evaluation of reports regarding each stage in the testing and implementation of the Disaster Recovery Plan.
Supporting work unit responsibilities as referred to in item 34 letter c cover at least:
a. the application of the Disaster Recovery Plan; and b. supporting the work unit responsible for the implementation of Information Technology.
Disaster Recovery Plan testing as referred to in item 30 letter e covers at least:
a. testing frequency; b. testing scope;
c. testing scenarios; and
d. analysis, reports, and documentation of testing results.
In the event LJKNB uses third-party Information Technology service providers, the implementation of Disaster Recovery Plan testing as referred to in item 30 letter e must involve the relevant third-party Information Technology service provider.
LJKNB must update the Disaster Recovery Plan as referred to in item 30 letter f to ensure the alignment of business processes, human resources, and Information Technology resources with current and future external and/or internal conditions.
Policies and procedures regarding the use of third-party Information Technology service providers as referred to in item 1 letter g cover at least:
a. the determination of criteria for the use of third-party Information Technology service providers, which contains at least regarding criteria for Information Technology implementation that can be done independently (in-house) or through third-party Information Technology service providers; b. principles for the use of third-party Information Technology service providers, which at least contain information regarding:
Policies and procedures regarding Electronic Financial Services as referred to in item 1 letter h contain at least:
a. scope and description of Electronic Financial Services; and b. responsibilities and authority for the management of Electronic Financial Services.
VI. ADEQUACY OF THE PROCESS OF IDENTIFICATION, MEASUREMENT, CONTROL, AND MONITORING OF INFORMATION TECHNOLOGY USAGE RISKS
The process of identification, measurement, control, and monitoring of risks is carried out at least regarding aspects:
a. management; b. development and procurement;
c. Information Technology operations;
d. communication networks; e. information security; f. Disaster Recovery Plan; g. use of third-party Information Technology service providers; and h. Electronic Financial Services, for LJKNB that organizes Electronic Financial Services.
LJKNB must have an integrated or unified risk management approach to be able to carry out identification, measurement, control, and monitoring of risks effectively.
The risk identification process as referred to in item 1 covers at least the following steps:
a. collection of data or information regarding activities related to the implementation of Information Technology that have the potential to cause or increase risks, both from activities that are currently ongoing or will be carried out, including data or information originating from:
The risk measurement process as referred to in item 1 can be carried out quantitatively and/or qualitatively, using methods established by the Financial Services Authority and/or other regulators for risk assessment purposes or methods developed independently by LJKNB.
The risk measurement process must clearly contain the validation process, validation frequency, data and information documentation requirements, and evaluation requirements for assumptions used, before a model is applied by LJKNB.
The risk control process as referred to in item 1 takes into account the following categories:
a. accept, namely LJKNB decides to accept the risk if the magnitude of the impact caused is still within tolerance limits; b. control, namely LJKNB decides to reduce the impact caused or the likelihood of the risk occurring;
c. avoid, namely LJKNB decides not to carry out an activity or chooses alternative activities that produce the same output to avoid the occurrence of risk; or
d. transfer, namely LJKNB decides to transfer all or part of the responsibility for the implementation of Information Technology to third-party Information Technology service providers.
LJKNB must take handling steps for the risk control process for each category as referred to in item 6, including preventing the occurrence of greater risk losses.
Risk control can be carried out by LJKNB, among others, by applying policies, procedures, organizational structure including workflows, and other risk mitigation methods to absorb potential losses.
In the event that the development and procurement of Information Technology is carried out by third-party Information Technology service providers, the risk control process carried out includes ensuring the existence of a written agreement in the form of an escrow agreement for applications or software considered important by LJKNB.
The risk monitoring process as referred to in item 1 regarding the risk control process as referred to in item 6 is carried out by evaluating the compliance, adequacy, and effectiveness of Information Technology implementation performance.
Follow-up on evaluation results can be formulated in the form of decisions or actions to improve the effectiveness of Information Technology implementation.
VII. INTERNAL CONTROL SYSTEM OVER THE USE OF INFORMATION TECHNOLOGY
LJKNB implements an internal control system containing at least:
a. management supervision; b. risk identification and assessment;
c. control activities and segregation of functions;
d. information systems, accounting systems, and communication systems; and e. monitoring activities and correction of deviations carried out by:
Information systems, accounting systems, and communication systems as referred to in item 1 letter d must be supported by adequate technology, human resources, and organizational structure of LJKNB.
Monitoring activities and correction of deviations as referred to in item 1 letter e cover at least:
a. continuous monitoring activities; b. effective and comprehensive internal audit functions; and
c. correction of deviations identified by Information Technology implementation and user work units, work units or functions that oversee internal audit, and/or other parties.
The implementation of effective and comprehensive internal audit functions as referred to in item 3 letter b covers at least:
a. background and objectives of audit implementation; b. auditor duties and responsibilities;
c. auditor authority;
d. audit process; and e. follow-up on audit results.
VIII. PROCEDURES FOR SUBMITTING REPORTS ON CERTAIN CONDITIONS, REQUESTS FOR APPROVAL FOR THE PLACEMENT OF DATA CENTERS AND/OR DISASTER RECOVERY CENTERS OUTSIDE THE TERRITORY OF INDONESIA, CRITICAL INCIDENT REPORTS, AND REPORTS ON THE CURRENT DEVELOPMENT OF CONDITIONS RELATED TO INFORMATION TECHNOLOGY
LJKNB submits:
a. reports as specific actions that must be reported to the Financial Services Authority as referred to in Article 21 paragraph (6) letter a and letter c of Financial Services Authority Regulation Number 4/POJK.05/2021 regarding the Implementation of Risk Management in the Use of Information Technology by Non-Bank Financial Service Institutions; b. requests for approval for the placement of Electronic Systems in Data Centers and/or Disaster Recovery Centers outside the territory of Indonesia as referred to in Article 23 paragraph (3) of Financial Services Authority Regulation Number 4/POJK.05/2021 regarding the Implementation of Risk Management in the Use of Information Technology by Non-Bank Financial Service Institutions; and/or
c. reports on critical incidents, misuse, and/or crimes in the implementation of Information Technology as referred to in Article 31 paragraph (1) of Financial Services Authority Regulation Number 4/POJK.05/2021 regarding the Implementation of Risk Management in the Use of Information Technology by Non-Bank Financial Service Institutions,
via online through the Financial Services Authority's data communication network system.
LJKNB ensures that the reports as referred to in item 1 letter a and letter c and the approval requests as referred to in item 1 letter b submitted online as referred to in item 1 are correct and identical to the hardcopy documents submitted.
In the event that the Financial Services Authority's data communication network system as referred to in item 1 is not yet available or experiences technical disruptions, the reports as referred to in item 1 letter a and letter c and the approval requests as referred to in item 1 letter b are submitted to the Financial Services Authority offline by:
a. being handed over directly; or b. being sent through a courier service company.
In the event of technical disruptions as referred to in item 3, the Financial Services Authority announces this through the Financial Services Authority website.
Submission of reports offline as referred to in item 3 must be submitted in electronic data (softcopy) form using media in the form of a compact disc (CD) or other electronic data storage media.
Submission of reports as referred to in item 3 is accompanied by a cover letter in the form of a hardcopy copy signed by the Board of Directors.
The format for the approval request as referred to in item 1 letter b is as stated in Format 12 of the Appendix which is an integral part of this Financial Services Authority Circular.
Submission of the cover letter as referred to in item 6, reports as referred to in item 1 letter a and letter c, and approval requests as referred to in item 1 letter b are addressed to the Supervision Director of each respective LJKNB as stated in Format 13 of the Appendix which is an integral part of this Financial Services Authority Circular.
LJKNB is deemed to have submitted reports as referred to in item 1 letter a and letter c and/or approval requests as referred to in item 1 letter b with the following provisions:
This copy is in accordance with the original
Acting Director of Legal Affairs 1
Legal Department signed
Evi Maria
a. for online submission via the Financial Services Authority's data communication network system, evidenced by a receipt from the Financial Services Authority's data communication network system; or b. for offline submission, evidenced by a receipt from the Financial Services Authority.
IX. CLOSING
The provisions in this Financial Services Authority Circular apply in accordance with the implementation for each respective LJKNB in Financial Services Authority Regulation Number 4/POJK.05/2021 regarding the Implementation of Risk Management in the Use of Information Technology by Non-Bank Financial Service Institutions.
Determined in Jakarta on August 24, 2021
EXECUTIVE HEAD OF SUPERVISOR
FOR INSURANCE, PENSION FUNDS,
LENDING INSTITUTIONS, AND
OTHER FINANCIAL SERVICE INSTITUTIONS
FINANCIAL SERVICES AUTHORITY
REPUBLIC OF INDONESIA, signed
RISWINANDI
APPENDIX
FINANCIAL SERVICES AUTHORITY CIRCULAR
REPUBLIC OF INDONESIA
NUMBER 22 /SEOJK.05/2021
REGARDING
IMPLEMENTATION OF RISK MANAGEMENT IN THE USE OF INFORMATION TECHNOLOGY BY NON-BANK FINANCIAL SERVICE INSTITUTIONS
TABLE OF CONTENTS
FORMAT 1: ORGANIZATION AND SUPPORTING MANAGEMENT FOR THE IMPLEMENTATION OF INFORMATION TECHNOLOGY RISK MANAGEMENT .............................................. 2
FORMAT 2: IMPLEMENTATION OF RISK MANAGEMENT COMPONENTS IN THE USE OF INFORMATION TECHNOLOGY......................................................... 3
FORMAT 3: POLICIES AND PROCEDURES FOR THE USE OF INFORMATION TECHNOLOGY..................................................................................................... 4
FORMAT 4: APPLICATION ARCHITECTURE .......ERROR! BOOKMARK NOT DEFINED.
FORMAT 5: APPLICATION LIST........................................................................ 6
FORMAT 6: COMMUNICATION NETWORK.............................................................. 7
FORMAT 7: DATA CENTERS AND DISASTER RECOVERY CENTERS........................ 8
FORMAT 8: INFORMATION TECHNOLOGY SECURITY ...................................... 9
FORMAT 9: DISASTER RECOVERY PLAN.............................................. 10
FORMAT 10: THIRD-PARTY INFORMATION TECHNOLOGY SERVICE PROVIDERS..................... 11
FORMAT 11: INFORMATION TECHNOLOGY COSTS ............................................... 12
FORMAT 12: REQUEST FOR APPROVAL FOR THE PLACEMENT OF ELECTRONIC SYSTEMS IN DATA CENTERS AND/OR DISASTER RECOVERY CENTERS OUTSIDE THE TERRITORY OF INDONESIA..................................................................... 13
FORMAT 13: LIST OF DESTINATIONS FOR SUBMISSION OF COVER LETTERS, REPORTS AS SPECIFIC ACTIONS THAT MUST BE REPORTED TO THE FINANCIAL SERVICES AUTHORITY, CRITICAL INCIDENT REPORTS, MISUSE, AND/OR CRIMES IN THE IMPLEMENTATION OF TECHNOLOGY, AND REQUESTS FOR APPROVAL FOR THE PLACEMENT OF ELECTRONIC SYSTEMS IN DATA CENTERS AND/OR DISASTER RECOVERY CENTERS OUTSIDE THE TERRITORY OF INDONESIA ……………………………………………………………..17
FORMAT 1: ORGANIZATION AND SUPPORTING MANAGEMENT FOR THE IMPLEMENTATION OF INFORMATION TECHNOLOGY RISK MANAGEMENT (to be filled with organizational structure and number of human resources of the Information Technology implementation work unit, membership data and implementation of Information Technology steering committee meetings)
FORMAT 2: IMPLEMENTATION OF RISK MANAGEMENT COMPONENTS IN THE USE OF INFORMATION TECHNOLOGY No. Item Description
FORMAT 3: POLICIES AND PROCEDURES FOR THE USE OF INFORMATION TECHNOLOGY
LIST OF INFORMATION TECHNOLOGY USE POLICIES
No. Document Title 1) Description 2) Category 3) Review and Update Time 4) 1.
2. etc.
Notes:
LIST OF INFORMATION TECHNOLOGY USE PROCEDURES
No. Document Title 1) Description 2) Category 3) Review and Update Time 4) 1.
2. etc.
Notes:
FORMAT 4: APPLICATION ARCHITECTURE
(to be filled with application architecture image)
No. Application Name 1) Description 2) Platform 3) Data Center Location 4) Data Center Operator 5) Disaster Recovery Center Location 6) Disaster Recovery Center Operator 7) Application Developer 8) Implementation Date 9) Ownership 10) 1. 2. etc.
FORMAT 5: APPLICATION LIST
Notes:
FORMAT 6: COMMUNICATION NETWORK
(to be filled with communication network topology image)
DATA CENTER
Address
Area Size
Ownership: Own/Information Technology Service Provider *) Controls Environmental Factor (fill in an explanation regarding the control of environmental factors as referred to in Roman V number 24 letter c) Physical Controls (fill in an explanation regarding the control of environmental factors as referred to in Roman V number 24 letter a, letter b, and letter d) DISASTER RECOVERY CENTER Address Area Size Ownership: Own/Information Technology Service Provider *) Disaster Recovery Center Location Different from Data Center Yes/No *) Environmental Factor Controls (fill in an explanation regarding the control of environmental factors as referred to in Roman V number 24 letter c) Physical Controls (fill in an explanation regarding the control of environmental factors as referred to in Roman V number 24 letter a, letter b, and letter d) FORMAT 7: DATA CENTER AND DISASTER RECOVERY CENTER
FORMAT 8: INFORMATION TECHNOLOGY SECURITY
No. Asset Name 1) Asset Type 2) Description 3) Notes:
Disaster Level and/or Disturbance
Minor disaster/major disaster/catastrophic disaster *) Date of Last Test Last Disaster Recovery Plan Test (fill in the date of the last test of the disaster recovery plan) List of Applications and/or Information Technology Resources Tested (fill in with a list of applications and/or Information Technology resources that were tested) Test Results (fill in with a brief explanation of the test results) Execution Time Review (fill in the time of the review execution) Review Results (fill in with the review results) Review Follow-up (fill in with the steps that need to be taken after the review execution) FORMAT 9: DISASTER RECOVERY PLAN
FORMAT 10: INFORMATION TECHNOLOGY SERVICE PROVIDER No. Name 1) Address 2) Services Provided 3) Notes:
No. Information Technology Resources 1) Costs Incurred 2) FORMAT 11: INFORMATION TECHNOLOGY COSTS Notes:
APPLICATION FOR APPROVAL OF PLACEMENT OF ELECTRONIC SYSTEMS IN DATA CENTERS AND/OR DISASTER RECOVERY CENTERS OUTSIDE INDONESIAN TERRITORY
the operation of
Electronic Systems outside Indonesian territory does not reduce the effectiveness of supervision by the Financial Services Authority Cooperation agreement between LJKNB and the Information Technology service provider to ensure that information regarding LJKNB's secrets is only disclosed as long as it meets the provisions of Indonesian legislation. Yes/No *) (Attach) Written agreement with the Information Technology service provider contains a choice of law clause Yes/No *) (Attach) Statement letter of non-objection from the supervisory authority of the Information Technology service provider outside Indonesian territory that the Financial Services Authority is granted access to conduct examinations against the Information Technology service provider Yes/No *) (Attach) Statement letter that LJKNB will periodically submit the results of assessments conducted by the parent company, the main entity, Yes/No *) (Attach)
and/or other entities that have similar business activities within one LJKNB group outside Indonesian territory regarding the implementation of risk management on the Information Technology service provider Analysis containing that the benefits obtained by LJKNB from the planned placement of Electronic Systems outside Indonesian territory are greater than the burdens borne by LJKNB (fill in LJKNB's analysis and explanation containing that the benefits obtained by LJKNB from the planned placement of Electronic Systems outside Indonesian territory are greater than the burdens borne by LJKNB) LJKNB's Plan to enhance LJKNB's human resource capabilities both related to the operation of Information Technology as well as business transactions or products offered Yes/No *) (Attach)
No. LJKNB PURPOSE OF SUBMISSION
This copy is consistent with the original
Acting Director of Law 1
Legal Department signed
Evi Maria
5. Financing Companies,
Venture Capital Companies, and Infrastructure Financing Companies Head of Executive Supervisor for Insurance, Pensions, Financing Institutions, and Other Financial Service Institutions Financial Services Authority attn. Director of Financing Institution Supervision Wisma Mulia Building 2, 15th Floor Jalan Jenderal Gatot Subroto Kav. 40 Jakarta 12710
6. Pawnshop Companies,
Guarantee Companies,
Reinsurance Guarantee Companies,
Indonesia Export Financing Institutions, Secondary Housing Financing Companies, PT Permodalan Nasional Madani (Persero) Head of Executive Supervisor for Insurance, Pensions, Financing Institutions, and Other Financial Service Institutions Financial Services Authority attn. Director of Special Financial Institution Supervision Wisma Mulia Building 2, 15th Floor Jalan Jenderal Gatot Subroto Kav. 40 Jakarta 12710
7. Organizers of Technology-Based
Peer-to-Peer Lending Services
Head of Executive Supervisor for
Insurance, Pensions,
Financing Institutions, and Other
Financial Service Institutions Financial Services Authority attn. Director of Financial Technology Regulation, Licensing, and Supervision Wisma Mulia Building 2, 12th Floor Jalan Jenderal Gatot Subroto Kav. 40 Jakarta 12710 Established in Jakarta on the date of August 24, 2021 HEAD OF EXECUTIVE SUPERVISOR FOR INSURANCE, PENSIONS, FINANCING INSTITUTIONS, AND OTHER FINANCIAL SERVICE INSTITUTIONS FINANCIAL SERVICES AUTHORITY REPUBLIC OF INDONESIA, signed RISWINANDI
Read the rest free
Source: Otoritas Jasa Keuangan (Financial Services Authority) — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from OJK
OJK published 7 documents in the last 30 days. We email you each new one the day it's published.