Skip to main content

What OJK POJK 11/2022 Actually Expects From Your Penetration Test

A practical breakdown of how Indonesian financial institutions can align penetration testing scope, frequency, and reporting with OJK expectations.

Siti Nurhaliza Rahmawati 8 min read

Indonesian financial institutions frequently commission penetration tests that are technically sound but fail to satisfy the evidence expectations of their regulator. The gap is rarely in the testing itself — it is in scope definition, documentation, and demonstrable remediation closure.

The three failure patterns we see most

Scope that excludes the actual risk. Many institutions scope only their public-facing internet banking portal. Supervisors increasingly ask about the internal segments reachable from that portal, the payment switch, and the third-party integrations that process customer data.

Findings without closure evidence. A report listing forty findings is not evidence of a mature control environment. What examiners want is a documented lifecycle: identification, risk acceptance or remediation decision, implementation, and independent verification.

Testing cadence that ignores change. Annual testing does not reflect a release cadence of weekly deployments. Where change velocity is high, a continuous or quarterly model on critical assets is far more defensible.

Structuring scope so it holds up

A defensible scope statement should explicitly enumerate:

  • Every internet-facing asset in the cardholder and customer data environment
  • The internal network segments that can be reached from a compromised DMZ host
  • Authentication and session management for all customer channels, including mobile
  • Any third-party or outsourced platform where your institution retains accountability

Where an asset is deliberately excluded, record the rationale. Unexplained exclusions attract far more scrutiny than documented ones.

Evidence that satisfies an examiner

For each finding, retain the original technical detail, the assigned risk rating with justification, the remediation owner, the implementation date, and the independent retest result. When these five elements are present, an examination conversation shifts from “why was this not found” to “your process is working.”

Building the cadence

We generally recommend a layered model: continuous automated coverage for surface monitoring, quarterly manual testing on the highest-value applications, an annual full-scope external and internal assessment, and a red team exercise every eighteen months to validate detection and response rather than just vulnerability presence.

That layered approach costs less than most institutions expect, because each tier is scoped to what it is genuinely good at measuring — and it produces exactly the trail of evidence a supervisor asks for.