Cloud 101CircleEventsBlog
Join us at CSA's third annual Virtual Zero Trust Summit from November 20 - 21. Register now!

Download Publication

Crypto-Asset Exchange Security Guidelines
Crypto-Asset Exchange Security Guidelines
Who it's for:
 Users, operators, and auditors of crypto-asset exchanges 

Crypto-Asset Exchange Security Guidelines

Release Date: 04/13/2021

Thanks to the blockchain technology that makes them possible, crypto-assets are becoming massively successful. As with any successful industry, a multitude of security questions arise: What risks should cryptocurrency users be aware of? How can they protect themselves? What security controls should operators put in place?

Experts have identified crypto-asset exchanges as a major pain point of crypto security. Exchanges are platforms that mediate crypto-asset transactions between entities. There are several types of attacks that are successful against exchanges. In this document, we give an overview of these attacks, describe an exchange security reference architecture, and then provide a detailed list of crypto-asset exchange security best practices, administrative controls, and physical controls. This is part of an ongoing project by the Blockchain/Distributed Ledger Working Group.

Key Takeaways:
  • The types of attacks that threaten crypto-asset exchanges
  • The details of a centralized exchange reference architecture that applies to a broad spectrum of crypto-asset exchanges
  • Crypto-asset exchange security best practices for end-users, exchange operators, and auditors
  • Crypto-asset exchange administrative and physical security control measures including: legal considerations, risk management, information access management, security awareness and training, workstation security, and more
This publication is part of a larger series on Securing DLT Frameworks for Financial Institutes. If you’re interested in learning more, you can find all the papers in the series here
Download this Resource

Bookmark
Share
Related resources
AI Organizational Responsibilities - Governance, Risk Management, Compliance and Cultural Aspects
AI Organizational Responsibilities - Governance...
AI in Medical Research: Applications & Considerations
AI in Medical Research: Applications & Consider...
Don’t Panic! Getting Real about AI Governance
Don’t Panic! Getting Real about AI Governance
How CSA Research Uses the Cloud Controls Matrix to Address Diverse Security Challenges
How CSA Research Uses the Cloud Controls Matrix to Address Diverse ...
Published: 10/25/2024
Reflections on NIST Symposium in September 2024, Part 2
Reflections on NIST Symposium in September 2024, Part 2
Published: 10/10/2024
Empowering BFSI with Purpose-Built Cloud Solutions
Empowering BFSI with Purpose-Built Cloud Solutions
Published: 10/01/2024
Leveraging Zero-Knowledge Proofs in Machine Learning and LLMs: Enhancing Privacy and Security
Leveraging Zero-Knowledge Proofs in Machine Learning and LLMs: Enha...
Published: 09/20/2024
It’s Time to Reclaim Control Over Your Non-Human Identities
November 8 | Online

Acknowledgements

Ashish Mehta
Ashish Mehta
Cybersecurity - Sr. Risk Manager & Security Architect

Ashish Mehta

Cybersecurity - Sr. Risk Manager & Security Architect

Ashish Mehta has extensive experience in cybersecurity, blockchain, web development, IT management, financial markets, and the energy industry.

He currently serves as Co-Chair of the Blockchain Working Group and is a part of the Internet of Things (IoT) and Quantum-Safe Security Leadership Teams at the Cloud Security Alliance. In that capacity, he is responsible for pushing their multiple research efforts as well as coordinating with ...

Read more

Hillary Baron
Hillary Baron
Senior Technical Director - Research, CSA

Hillary Baron

Senior Technical Director - Research, CSA

Frank Guanco
Frank Guanco
Research Program Manager, CSA

Frank Guanco

Research Program Manager, CSA

Jyoti Ponnapalli
Jyoti Ponnapalli

Jyoti Ponnapalli

Jyoti Ponnapalli is the SVP, Head of Blockchain Innovation Strategy at Truist. She has more than 18 years of experience leading emerging technology and complex digital transformations for fortune 500 companies across a range of industries including Finance, Telecom, Airline, Energy, and Food & Beverage. Prior to joining Truist, she was a Director of Blockchain at DTCC leading strategic initiatives in support of efforts to modernize the fina...

Read more

Ken Huang
Ken Huang
Chief AI Officer at DistributedApps.ai

Ken Huang

Chief AI Officer at DistributedApps.ai

Ken Huang is an acclaimed author of 8 books on AI and Web3. He is the Co-Chair of the AI Organizational Responsibility Working Group and AI Control Framework at the Cloud Security Alliance. Additionally, Huang serves as Chief AI Officer of DistributedApps.ai, which provides training and consulting services for Generative AI Security.

In addition, Huang contributed extensively to key initiatives in the space. He is a core contributor t...

Read more

Dave Jevans Headshot Missing
Dave Jevans

Dave Jevans

Boulevard A. Aladetoyinbo Esq. Headshot Missing
Boulevard A. Aladetoyinbo Esq.

Boulevard A. Aladetoyinbo Esq.

Abdulwahab AL-Zuaby Headshot Missing
Abdulwahab AL-Zuaby

Abdulwahab AL-Zuaby

Kurt Seifried
Kurt Seifried
Chief Innovation Officer, CSA

Kurt Seifried

Chief Innovation Officer, CSA

For over two decades, Kurt has excelled in information security, starting with Windows and Linux, and advancing to cloud computing and AI. With a strong focus on AI security, privacy, and open source, Kurt brings extensive expertise to the Cloud Security Alliance (CSA).

Read more

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training