2022-06-28 | CIEX N° 26/2022Added · Updated
The Central Bank of Bolivia mandates updated minimum operational security requirements for electronic fund transfer orders, electronic payment channels, electronic cards, and mobile wallets, replacing Circular Externa CIEX No. 08/2021. Financial entities must implement encrypted communication channels, robust multi-factor authentication, and specific data protection measures, including automatic session timeouts and restrictions on storing sensitive data. The regulation establishes liability frameworks for fraud based on security protocol compliance and sets a deadline of June 30, 2023, for replacing magnetic stripe-only cards with contactless-enabled chip cards.
EXTERNAL CIRCULAR La Paz, June 22, 2022 CIEX No. 26/2022 FROM: GENERAL MANAGEMENT MANAGEMENT OF FINANCIAL ENTITIES TO: FINANCIAL ENTITIES, PAYMENT SERVICE COMPANIES, ACCL S.A., UNILINK S.A., EDV S.A. SUBJECT: MINIMUM OPERATIONAL SECURITY REQUIREMENTS FOR ELECTRONIC PAYMENT INSTRUMENTS
Gentlemen:
In the framework of its regulatory powers over the national payment system and in accordance with Article 27 of the Regulation on Payment Services, Electronic Payment Instruments, Compensation and Settlement (RSPIEPCL), approved by BCB Board Resolution No. 069/2021 of April 27, 2021, and its amendments, the Central Bank of Bolivia transmits for application and compliance the update to the Minimum Operational Security Requirements for:
I. Electronic Fund Transfer Orders. II. Electronic payment channels. III. Electronic cards. IV. Mobile wallets.
The Minimum Operational Security Requirements for the aforementioned electronic payment instruments and channels constitute the normative reference framework for the application of standards and best practices in payment systems operating with these instruments. Circular Externa CIEX No. 08/2021 of February 24, 2021, is hereby repealed.
Sincerely.
DIGITALLY SIGNED DOCUMENT Rolando Sergio Colque Soldado MANAGER OF FINANCIAL ENTITIES Rubén Gonzalo Ticona Chique GENERAL MANAGER
Validate digital signatures at: validar.firmadigital.bo RGTCH/RSCS/ampm/pmms
I. Minimum Operational Security Requirements for Electronic Fund Transfer Orders
Transactional services must operate using encrypted communication channels on a secure server under the TLS protocol in version 1.2 or higher, applying the corresponding security updates.
The website must have a secure connection digital certificate, issued by a certification entity that allows validating the following information: the certifying entity, the website name, the legal name of the financial entity owning the site, and the certificate validity period. In no case shall the validity of this digital certificate exceed that defined in the Digital Signature Regulation for the Payment System issued by the BCB.
The financial entity shall not enable an access account to a web or mobile application that allows the processing of Electronic Fund Transfer Orders (OETF) without prior consent from the client or account holder associated.
Financial entities must implement in their operations, through web and mobile applications, robust authentication mechanisms for their users in the following authorization processes: a) Processing of OETF. b) Registration and modification of beneficiary data, as well as other sensitive or confidential information whose modification could facilitate the commission of crimes or fraud. c) Enabling electronic cards for internet payments, as well as for use abroad. d) Definition and modification of transaction limits. e) Others inherent to the processing of OETF. At least one of the applied factors must not be reusable, replicable, or susceptible to being stolen via the internet. In the event that a one-time password is used, its validity shall not exceed two (2) minutes. Only for login, single-factor authentication may be used, based on the security information risk analysis and evaluation conducted by the financial entity.
Fund transfers shall be credited to the beneficiaries' accounts once the validation processes required by the processing system are completed, and at the latest by the end of the cycle in case the processing involves compensation and settlement processes.
OETF must meet the following characteristics: a) Authenticity. Have mechanisms that allow verifying the identity of the holder of the electronic payment instrument and that they are duly authorized. b) Integrity. Be protected against alterations originating from technological contingencies, intentional or accidental actions during their processing, transport, and storage. c) Confidentiality. Have standard encryption mechanisms that prevent unauthorized dissemination or disclosure of the information contained in the operation that could be used to materialize fraud events. d) Non-repudiation. Guarantee that none of the parties involved in the transaction can deny their participation in it. e) Availability. The issuer must guarantee, within its control scope, that the OETF processing system is available to clients according to advertised, informed, or contractually agreed conditions.
The exchange of information between financial entities and external technology service provider companies must meet the security characteristics described in point 6.
The exchange of information for the processing of OETF between financial entities and compensation and settlement systems must comply with what is defined in the Digital Signature Regulation for the Payment System issued by the BCB.
Financial entities must implement in their monitoring and tracking systems, mechanisms for detection, alert, and, where appropriate, automated blocking of unusual operations to detect suspicious activities and prevent fraud events, based on the creation of rules for frequency, speed, limit amounts, trusted device usage, unusual geographic location, and others that respond to a security information risk analysis and evaluation.
Financial entities must carry out information campaigns regarding the security of using electronic payment instruments, directed at OETF users, with a minimum semi-annual periodicity and in case of changes in operations, including at least: a) Description of operations and/or functionalities. b) Use of the service. c) Utilization of robust authentication mechanisms, describing their operation and application cases. d) Customer complaint and inquiry handling system.
Abbreviations OETF = Electronic Fund Transfer Orders TLS = Transport Layer Security
Glossary Authentication: Procedure that allows checking the identity of the holder of the Electronic Payment Instrument. Authorization: Procedure to check if the holder of the electronic payment instrument has the right to perform a specific action, for example, to transfer funds or access sensitive data. One-time password: Random number generated by a key generator software (tokens), a combination of numbers from a coordinate card or some other mechanism, and which is used to authorize the processing of a specific action whose validity expires in a determined time. Trusted device: Computer, electronic tablet, smartphone, or other electronic artifact that allows verifying the identity of the transaction initiator and that they are duly enabled. Robust authentication mechanism or double-factor authentication: A way to verify user identity based on the use of the combination of at least two (2) of the following three (3) authentication factors: i. Something the user knows ii. Something the user has iii. Something the user is Initiator: Natural or legal person who initiates or originates a payment order from their account in favor of a beneficiary.
II. Minimum Operational Security Requirements for Electronic Payment Channels (Electronic Banking and Mobile Banking)
Entities must implement security measures for their web and mobile applications, based on their security information risk analysis and evaluation, as well as assume risk mitigation measures.
Entities must provide the customer with a password to authenticate to the service, with mandatory change after the first login and mechanisms to remind them to change it at least every ninety (90) days.
Entities must guarantee that their web and mobile applications do not store sensitive and/or confidential information in HTML hidden fields, cookies, or any other form of client-side storage that could compromise confidentiality or data integrity.
Web and mobile applications must not expose user data at login.
Session restoration in web or mobile applications, after interruptions or a period of inactivity, must require new user authentication. Any session must be automatically terminated after a maximum of five (5) minutes of inactivity.
Security controls, tracking, and notification of electronic device access to web and mobile applications must be implemented.
Mechanisms for device registration/linking for access to electronic services, detection of unsecured networks, and monitoring of suspicious transactions must be implemented.
Implement non-presence mechanisms for updating personal information, modifying enabled functionalities, confirming changes, and updates in electronic channels using digital signature at no additional cost to the client.
Communication messages sent by issuers via email and/or SMS must not be generic and must specify the operation to be authorized, considering, as appropriate, the confirmation code, amount, destination financial entity, beneficiary account, date, and time of the operation.
Abbreviations HTML = HyperText Markup Language SMS = Short Message Service
Glossary Authentication: Procedure that allows checking the identity of the holder of the Electronic Payment Instrument. Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data. Electronic Banking: The provision of financial services through the internet or other electronic and digital means without the need for the client's physical presence in the financial entity's offices. Electronic Payment Channels: Are, by way of example and not limitation, devices (ATMs, POS terminals), communication networks (internet, fixed or mobile telephony), payment gateways, or applications that allow processing payment orders originated with electronic payment instruments. One-time password: Random number generated by a key generator software (tokens), a combination of numbers from a coordinate card or some other mechanism, and which is used to authorize the processing of a specific action, whose validity expires in a determined time. Robust authentication mechanism or double-factor authentication: A way to verify user identity based on the use of the combination of at least two (2) of the following three (3) authentication factors: i. Something the user knows ii. Something the user has iii. Something the user is
III. Minimum Operational Security Requirements for Electronic Cards
Physically issued electronic cards may be used virtually at the holder's request.
Electronic cards must contain printed, engraved, or embossed, as appropriate, the following data: issuer name, card number, card verification value, and when applicable, name, logo, and hologram of the international brand and expiration date.
The last four digits embossed, engraved, or printed on the card must match the digits appearing on the receipt generated by the terminal at the time of making withdrawals or in-person purchases.
In the case of debit or prepaid cards, the issuer must offer the holder the option to print the cardholder's name on the plastic, explaining the advantages and disadvantages of the selection. In case the client does not wish to include this data, the issuer must record and save the selection made with the holder's signature.
The magnetic stripe of electronic cards must contain the following information: Primary Account Number (PAN), expiration date, PIN verification value, card verification value (CVV), and service code. This information must be validated by the issuer at the time of processing transactions.
The card validation code (CAV2, CID, CVC2, CVV2) or PIN validation data must not be stored in systems or databases.
Messages exchanged between terminals must be generated under the ISO 8583 standard, which may be adapted to particular needs to facilitate interoperability of the platforms involved.
Electronic Card Administrator Companies that process transactions with electronic cards must communicate to their participants, the BCB, and ASFI each update made to the ISO 8583 standard within five (5) business days following the update.
Financial entities must implement in their web and mobile applications the following functionalities at no cost to the client: a) Enabling and disabling electronic cards for internet purchases and for use abroad. b) Generation of historical and/or periodic statements of operations performed. Tariffs shall only be applied to the issuance of printed statements upon request of the holder of the electronic payment instrument.
Enabling electronic cards for internet purchases and processing internet payments on websites of national commercial or service establishments must be carried out in secure and trusted environments.
Financial entities have the obligation to inform the holder or user of the instrument that electronic cards are automatically exempt from the enabling process for internet purchases up to a maximum amount of Bs150 (One hundred fifty bolivianos) for debit cards and Bs250 (Two hundred fifty bolivianos) for credit cards. Financial entities must make available to the holder the necessary mechanisms to disable their electronic card for internet purchases for the amounts established automatically at any time.
Liability for claims and disputes regarding the processing of transactions or virtual purchases shall rest with the issuing or acquiring entities that do not operate under security protocols containing robust authentication mechanisms as follows: a) Liability for transactions processed with cards that are not under security protocols containing robust authentication mechanisms on e-commerce platforms that do not operate under security protocols containing robust authentication mechanisms, shall be the acquirer's. b) Liability for transactions processed with cards that are not under security protocols containing robust authentication mechanisms on e-commerce platforms that do operate under security protocols containing robust authentication mechanisms, shall be the issuer's. c) Liability for transactions processed with cards that are under security protocols containing robust authentication mechanisms that have been authenticated on e-commerce platforms that are not under security protocols containing robust authentication mechanisms, shall be the acquirer's.
Issuers must implement robust authentication mechanisms for the authorization of electronic cards used virtually, considering that at least one (1) of the applied factors must not be reusable, replicable, or susceptible to being stolen via the internet. When a one-time password is used, its validity shall not exceed two (2) minutes.
As a robust authentication mechanism for chip cards, the holder or user of the instrument, when making in-person payments at commercial or service establishments with electronic cards, must enter the corresponding PIN once the establishment manager enters the transaction amount, which must be visible for prior validation by the holder or user. In-person transactions with contactless technology cards are exempt from PIN application up to a maximum amount of Bs150 (One hundred fifty bolivianos).
When using chip cards to process in-person payments at commercial or service establishments, the client's handwritten signature is not necessary, nor will a printed voucher be issued, unless requested by the client.
In the case of electronic cards from foreign issuers that have only magnetic stripe for processing at commercial or service establishments in Bolivia, the holder or user of the instrument, when making an in-person purchase, must present their identification document and sign the transaction receipts.
Acquirers must instruct commercial or service establishments to process transactions always using chip reading, except in the case of contactless technology payments.
Commissions paid by commercial or service establishments to Electronic Card Administrator Companies cannot be transferred to the holder or user of the electronic card.
Disputes or claims regarding the processing of transactions shall rest with the issuing or acquiring entities that do not operate with chip cards under the EMV standard as follows: a) Liability for transactions processed with magnetic stripe on terminals that do not have the capacity to process chip cards, shall be the acquirer's. b) Liability for transactions processed with magnetic stripe-only cards on a terminal that has chip reading enabled, shall be the issuer that does not operate under the EMV standard.
Standard encryption algorithms must be applied to authenticate the chip card and the operation data.
In addition to robust authentication factors using PIN, biometric authentication systems can be used to verify the cardholder's identity.
In case the issuer authorizes the performance of offline operations, cards must use a dynamic authentication mechanism (CAM) of type DDA or CDA that allows recalculating the digital signature value in each transaction, for which they must be equipped with a cryptoprocessor.
The card operating system may be native or open platform, both must have the capacity to handle DDA or CDA, in case the issuer accepts the processing of offline transactions.
For contactless technology payments, issuers must implement in their monitoring and tracking systems, internal control mechanisms, strict security parameters, and alerts for fraud prevention based on the creation of rules for frequency, speed, limit amounts, and others that allow controlling the number of transactions approved under contactless technology that respond to a risk analysis by product type and transaction volume of said technology. Among these measures, they must offer their customers the possibility of establishing a daily limit amount per product.
For payments made with electronic cards in virtual environments, issuers must implement in their monitoring and tracking systems, mechanisms for detection, alert, and, where appropriate, automated blocking of unusual operations based on the creation of rules for frequency, speed, limit amounts, and others that respond to a risk analysis.
Issuers, in order to incentivize the secure use of contactless technology cards, must provide their customers with training on the use of this type of card and regarding the limit amount for in-person transactions exempt from PIN application.
Issuers must replace their entire fleet of cards in circulation that only have a chip with cards that include contactless technology by June 30, 2023.
Abbreviations CAM = Card Authentication Method CAV2 = Card Security Code (JCB) CDA = Combined Data Authentication CID = Card Security Code (American Express) CVC2 = Card Security Code (MasterCard) CVV = Card Verification Value CVV2 = Card Security Code (Visa) DDA = Dynamic Data Authentication EMV = Europay, MasterCard and Visa PAN = Primary Account Number PIN = Personal Identification Number
Glossary Authentication: Procedure that allows checking the identity of the holder of the Electronic Payment Instrument. Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data. One-time password: Random number generated by a key generator software (tokens), a combination of numbers from a coordinate card or some other mechanism, and which is used to authorize the processing of a specific action, whose validity expires in a determined time. Secure Environment: Environments under the issuer's responsibility where adequate client authentication is guaranteed as well as the protection of confidential and sensitive information. Robust authentication mechanism or double-factor authentication: A way to verify user identity based on the use of the combination of at least two (2) of the following three (3) authentication factors: i. Something the user knows ii. Something the user has iii. Something the user is Point of Sale Terminal: Device that allows the use of physical or virtual electronic payment instruments at points of sale of goods and/or services to process payment orders by contact or contactless; the information is captured in paper receipts (vouchers) or by te