Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Security stories in online payment company
Search
Raden Ardiansyah Natakusumah
December 13, 2018
Technology
0
25
Security stories in online payment company
Raden Ardiansyah Natakusumah
December 13, 2018
Tweet
Share
More Decks by Raden Ardiansyah Natakusumah
See All by Raden Ardiansyah Natakusumah
Bug Bounty: Do and Don’t
rully
0
61
Protect your business with PCI DSS
rully
0
39
Intrusion Prevention System based on Machine Learning
rully
0
160
PCI DSS Security Awareness
rully
0
160
Other Decks in Technology
See All in Technology
「どこから読む?」コードとカルチャーに最速で馴染むための実践ガイド
zozotech
PRO
0
590
Evolución del razonamiento matemático de GPT-4.1 a GPT-5 - Data Aventura Summit 2025 & VSCode DevDays
lauchacarro
0
220
なぜテストマネージャの視点が 必要なのか? 〜 一歩先へ進むために 〜
moritamasami
0
250
OCI Oracle Database Services新機能アップデート(2025/06-2025/08)
oracle4engineer
PRO
0
190
組織規模に応じたPlatform Engineeringの実践
hacomono
PRO
0
110
データ分析エージェント Socrates の育て方
na0
9
3.4k
Oracle Base Database Service 技術詳細
oracle4engineer
PRO
10
75k
20250913_JAWS_sysad_kobe
takuyay0ne
2
260
[ JAWS-UG 東京 CommunityBuilders Night #2 ]SlackとAmazon Q Developerで 運用効率化を模索する
sh_fk2
3
480
AWSを利用する上で知っておきたい名前解決のはなし(10分版)
nagisa53
10
3.3k
dbt開発 with Claude Codeのためのガードレール設計
10xinc
3
1.4k
AIがコード書きすぎ問題にはAIで立ち向かえ
jyoshise
4
1.6k
Featured
See All Featured
Designing for Performance
lara
610
69k
How To Stay Up To Date on Web Technology
chriscoyier
790
250k
ピンチをチャンスに:未来をつくるプロダクトロードマップ #pmconf2020
aki_iinuma
127
53k
Measuring & Analyzing Core Web Vitals
bluesmoon
9
590
The Power of CSS Pseudo Elements
geoffreycrofte
77
6k
Imperfection Machines: The Place of Print at Facebook
scottboms
268
13k
Building Flexible Design Systems
yeseniaperezcruz
329
39k
YesSQL, Process and Tooling at Scale
rocio
173
14k
Evolution of real-time – Irina Nazarova, EuRuKo, 2024
irinanazarova
8
930
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
How to train your dragon (web standard)
notwaldorf
96
6.2k
BBQ
matthewcrist
89
9.8k
Transcript
13 December 2018 • Raden Ardiansyah Natakusumah • FintechNite •
UnionSPACE, Jakarta Security stories in online payment company
https://about.me/r_u_l_l_y
Newbie
14.5 years
None
None
None
None
None
Registered Penetration Tester
Practitioner Security Analyst
None
None
The Story ….
Online Payment Company
Potential Employees
Minimize the Risk
Human Resource Department
Background Checks
Criminal Record
Reference Checks
Credit History
1st Day!
Onboarding Process
Security Awareness Training
All New Hires
Information Security Policy
And Other Policies
Developer
Secure Coding Training
Incident Response Team
From various departments
Incident Response Training
See You Next Year!
Time to work!
Don’t forget …
Use Badge
Infra Team
Review the Network Diagram
Review the configuration
Review the rules
Update patches
Support Team
Anti Malware, Personal Firewall
Change default credential, default configuration
Asset inventory
Dev Team
Develop Secure Applications
Secure Coding Guidelines
OWASP, SANS CWE Top 25
Security Team
Security Code Review
Vulnerability Assessment
Penetration Testing
Examine documents changes
Business Justification? Tested? Approved?
Monitoring
Logs, Security Events
At a time ….
Incident occurred
Incident Response Plan
Roles, responsibilities, and communication
Follow the procedure
Post-incident investigation
Business Team
Business Needs
External Entity
Regulator
Need compliance!
None
ISO 27001
PCI DSS
Not that hard
Why?
Focus
Security
Not Compliance
Security
ALL responsibility
Security
Business as Usual
Questions?
Lawrence Lessig method - 2005
84 LET’S GO.