Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Security stories in online payment company
Search
Raden Ardiansyah Natakusumah
December 13, 2018
Technology
0
26
Security stories in online payment company
Raden Ardiansyah Natakusumah
December 13, 2018
Tweet
Share
More Decks by Raden Ardiansyah Natakusumah
See All by Raden Ardiansyah Natakusumah
Bug Bounty: Do and Don’t
rully
0
62
Protect your business with PCI DSS
rully
0
42
Intrusion Prevention System based on Machine Learning
rully
0
160
PCI DSS Security Awareness
rully
0
160
Other Decks in Technology
See All in Technology
OpenShiftでllm-dを動かそう!
jpishikawa
0
140
会社紹介資料 / Sansan Company Profile
sansan33
PRO
15
400k
Cosmos World Foundation Model Platform for Physical AI
takmin
0
970
量子クラウドサービスの裏側 〜Deep Dive into OQTOPUS〜
oqtopus
0
140
[CV勉強会@関東 World Model 読み会] Orbis: Overcoming Challenges of Long-Horizon Prediction in Driving World Models (Mousakhan+, NeurIPS 2025)
abemii
0
150
SREのプラクティスを用いた3領域同時 マネジメントへの挑戦 〜SRE・情シス・セキュリティを統合した チーム運営術〜
coconala_engineer
2
770
~Everything as Codeを諦めない~ 後からCDK
mu7889yoon
3
480
Codex 5.3 と Opus 4.6 にコーポレートサイトを作らせてみた / Codex 5.3 vs Opus 4.6
ama_ch
0
200
Agent Skils
dip_tech
PRO
0
130
フルカイテン株式会社 エンジニア向け採用資料
fullkaiten
0
10k
【Oracle Cloud ウェビナー】[Oracle AI Database + AWS] Oracle Database@AWSで広がるクラウドの新たな選択肢とAI時代のデータ戦略
oracle4engineer
PRO
2
180
顧客との商談議事録をみんなで読んで顧客解像度を上げよう
shibayu36
0
290
Featured
See All Featured
Six Lessons from altMBA
skipperchong
29
4.2k
Building Flexible Design Systems
yeseniaperezcruz
330
40k
I Don’t Have Time: Getting Over the Fear to Launch Your Podcast
jcasabona
34
2.6k
<Decoding/> the Language of Devs - We Love SEO 2024
nikkihalliwell
1
130
Optimising Largest Contentful Paint
csswizardry
37
3.6k
How To Speak Unicorn (iThemes Webinar)
marktimemedia
1
380
Building Experiences: Design Systems, User Experience, and Full Site Editing
marktimemedia
0
410
Crafting Experiences
bethany
1
50
The Illustrated Children's Guide to Kubernetes
chrisshort
51
51k
Learning to Love Humans: Emotional Interface Design
aarron
275
41k
Google's AI Overviews - The New Search
badams
0
910
Sam Torres - BigQuery for SEOs
techseoconnect
PRO
0
190
Transcript
13 December 2018 • Raden Ardiansyah Natakusumah • FintechNite •
UnionSPACE, Jakarta Security stories in online payment company
https://about.me/r_u_l_l_y
Newbie
14.5 years
None
None
None
None
None
Registered Penetration Tester
Practitioner Security Analyst
None
None
The Story ….
Online Payment Company
Potential Employees
Minimize the Risk
Human Resource Department
Background Checks
Criminal Record
Reference Checks
Credit History
1st Day!
Onboarding Process
Security Awareness Training
All New Hires
Information Security Policy
And Other Policies
Developer
Secure Coding Training
Incident Response Team
From various departments
Incident Response Training
See You Next Year!
Time to work!
Don’t forget …
Use Badge
Infra Team
Review the Network Diagram
Review the configuration
Review the rules
Update patches
Support Team
Anti Malware, Personal Firewall
Change default credential, default configuration
Asset inventory
Dev Team
Develop Secure Applications
Secure Coding Guidelines
OWASP, SANS CWE Top 25
Security Team
Security Code Review
Vulnerability Assessment
Penetration Testing
Examine documents changes
Business Justification? Tested? Approved?
Monitoring
Logs, Security Events
At a time ….
Incident occurred
Incident Response Plan
Roles, responsibilities, and communication
Follow the procedure
Post-incident investigation
Business Team
Business Needs
External Entity
Regulator
Need compliance!
None
ISO 27001
PCI DSS
Not that hard
Why?
Focus
Security
Not Compliance
Security
ALL responsibility
Security
Business as Usual
Questions?
Lawrence Lessig method - 2005
84 LET’S GO.