2020-01-07 | CIEX N° 3/2020

Added · Updated

CIEX No. 3/2020: Minimum Operational Security Requirements for Electronic Payment Instruments

The Central Bank of Bolivia establishes minimum operational security requirements for electronic fund transfer orders, electronic cards, and mobile wallets, requiring financial entities, payment service companies, ACCL S.A., and EDV S.A. to implement robust authentication mechanisms, including dual-factor authentication for specific transactions. The regulation mandates the use of encrypted communication channels, standard encryption algorithms, and specific data handling protocols, while repealing previous circulars SGDB No. 046/2017 and SGDB No. 011/2018. It sets specific operational limits, such as a Bs150 PIN exemption for contactless transactions and a Bs20 exemption for mobile wallet top-ups, and assigns liability for magnetic stripe transactions based on terminal and issuer capabilities.

Banco Central de Bolivia logo

Bolivia

Banco Central de Bolivia

Click to view thumbnail

[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

EXTERNAL CIRCULAR

La Paz, January 2, 2020 CIEX No. 3/2020

FROM: GENERAL MANAGEMENT FINANCIAL ENTITIES MANAGEMENT TO: FINANCIAL ENTITIES, PAYMENT SERVICE COMPANIES, ACCL S.A., EDV S.A. SUBJECT: MINIMUM OPERATIONAL SECURITY REQUIREMENTS FOR ELECTRONIC PAYMENT INSTRUMENTS

Ladies and Gentlemen:

In the framework of Article 27 of the Regulation on Payment Services, Electronic Payment Instruments, Compensation and Settlement (RSPIEPCL), approved by BCB Board Resolution No. 137/19 of October 8, 2019, the Central Bank of Bolivia transmits for application and compliance the update of the Minimum Operational Security Requirements for:

I. Electronic fund transfer orders. II. Electronic cards. III. Mobile wallets.

These requirements constitute the normative reference framework for the application of standards and best practices in payment systems operating with electronic payment instruments. External Circular SGDB No. 046/2017 of December 29, 2017 and SGDB No. 011/2018 of February 16, 2018 on Minimum Operational Security Requirements for Electronic Payment Instruments are hereby repealed.

Sincerely,

[Signature] JULIO NUMEREZ QUIROZ FINANCIAL ENTITIES MANAGER a.i. BANCO CENTRAL DE BOLIVIA

[Signature] DAVID ESPINOZA TORRICO GENERAL MANAGER a.i. BANCO CENTRAL DE BOLIVIA

DIET/JHQ/ropr/pmms/jmkt. Attach.: The cited

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

I. Minimum Operational Security Requirements for Electronic Fund Transfer Orders – OETF

  1. Transactional services must operate using encrypted communication channels on a secure server under the SSL or TLS protocol.
  2. The secure web page must indicate the name of the entity issuing the digital certificate for the secure site and a link to the certification entity that allows validation of: the certifying entity, the web page name, the name of the entity owning the site, and the validity of the certificate. The provider of the transactional services must not enable an access account without the prior consent of the client or holder.
  3. The digital certificate will be valid until the expiration date indicated therein. In no case shall the validity of the digital certificate exceed that defined in the Digital Signature Regulation for the Payment System issued by the BCB.
  4. Financial entities must implement in their operations, through internet portals and mobile banking, robust authentication mechanisms, that is, establish at least double factor for user authentication in the following operational instances: a) Authorization for the processing of OETF. b) Authorization for the introduction and modification of beneficiary data or other sensitive information, whose modification could lead to the commission of crimes or fraud. c) Other authorizations involving the processing of OETF, such as the enabling of debit cards for internet payments.

At least one of the factors applied must not be reusable or replicable nor susceptible to being stolen via the internet. In this sense, it is feasible to use a one-time password, generated by a key generator software (tokens), or a combination of numbers from a coordinate card.

The use of double factor authentication at login is optional.

  1. Fund transfers must be credited to client accounts once the validation processes required by the processing system are completed, and at the latest by the end of the cycle in case the processing involves compensation and settlement processes.
  2. OETF must meet the following characteristics:

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

a) Authenticity. Have mechanisms that allow the verification of the identity of the holder of the electronic payment instrument.
b) Integrity. Be protected against accidental or fraudulent alterations during their processing, transport, and storage.
c) Confidentiality. Have standard encryption mechanisms that prevent the dissemination or unauthorized disclosure of the information contained in the operation.
d) Non-repudiation. Guarantee that none of the parties involved in the transaction can deny their participation in it.
e) Availability. The issuer within its scope of control must guarantee that the processing system is available to users according to the advertised, informed, or contractually agreed conditions with financial consumers.

7. The exchange of information between financial entities and external technology service provider companies must meet the security characteristics described in point 6. 8. The exchange of information for the processing of OETF between financial entities and compensation and settlement systems must comply with what is defined in the Digital Signature Regulation for the Payment System issued by the BCB. 9. Financial entities must carry out campaigns to inform about the security of the use of the instrument directed at OETF users, which must also include: a) Description of operations and/or functionalities. b) Use of the service. c) Use of robust authentication mechanisms: operation and cases of application. d) Changes in operation and/or authentication mechanisms and/or processing of payment orders. e) System for handling customer complaints and inquiries.

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

Abbreviations

SSL = Secure Sockets Layer, secure connection layer TLS = Transport Layer Security, transport layer security

Glossary

Authentication: Procedure that allows checking the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

II. Minimum Operational Security Requirements for Electronic Cards

  1. Electronic cards must be issued physically and can be used virtually at the holder's request.
  2. Electronic cards must contain printed, engraved, or embossed, as appropriate, the following data: issuer name, card number, card verification value, and when applicable, name, logo, and hologram of the international brand. The credit card must include the expiration date.
  3. The last four digits embossed, engraved, or printed on the card must match the digits shown on the receipt generated by the terminal, when printed at the time of making withdrawals or in-person purchases.
  4. When dealing with debit or prepaid cards, the issuer must offer the holder the option to print the cardholder's name on the plastic, explaining the advantages and disadvantages of the selection. In case the client does not wish to include this data, the issuer must record and save the selection made with the holder's signature.
  5. The magnetic stripe of electronic cards must contain the following information: primary account number (PAN), expiration date, PIN verification value, card verification value (CVV), and service code. This information must be validated by the issuer when processing transactions.
  6. The card validation code (CAV2, CID, CVC2, CVV2) or PIN validation data must not be stored in systems or databases.
  7. Messages exchanged between terminals must be generated under the ISO 8583 standard, which may be adapted to particular needs to facilitate the interoperability of the platforms involved.
  8. Electronic Card Administrator Companies that process transactions with electronic cards must communicate to their participants, the BCB, and the ASFI, with a 30 calendar day advance, the updates made to the ISO 8583 standard.
  9. The enabling of electronic cards for internet purchases and the processing of internet payments on web pages of national commercial or service establishments

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

must be carried out in secure and trusted environments. 10. Issuers must implement robust authentication mechanisms for the authorizations of electronic cards used virtually, considering that at least one of the factors applied must not be reusable or replicable nor susceptible to being stolen via the internet (for example, a one-time password specific for a payment and generated by a key generator software (tokens), a combination of numbers from a coordinate card, etc.). 11. As a robust authentication mechanism for chip cards, the holder or user of the instrument to make in-person payments in commercial or service establishments with electronic cards must enter the PIN once the establishment manager enters the transaction amount, which must be visible for the security and certainty of the holder or user. In this sense, issuers must foresee in the design of the instrument that the service code requires the entry of the PIN to perform transactions. In-person transactions with contactless technology cards are exempt from the application of the PIN up to a maximum amount of Bs150 (One hundred fifty Bolivianos). 12. When using chip cards to process in-person payments in commercial or service establishments, a handwritten signature or an issued printed receipt (voucher) for the client is not necessary, unless requested by the latter. 13. For the case of electronic cards from foreign issuers that have exclusively magnetic stripe for processing in commercial or service establishments in Bolivia, the holder or user of the instrument at the time of making an in-person purchase must present their identification document and sign the transaction receipts. 14. Acquirers must instruct commercial or service establishments to process transactions always using chip reading. 15. The commissions that commercial or service establishments pay to Electronic Card Administrator Companies cannot be transferred to the holder or user of the electronic card. 16. Disputes or claims regarding the processing of transactions will fall on the issuing or acquiring entities that do not operate with chip cards under the EMV standard as follows:

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

a) Liability for transactions processed with magnetic stripe on terminals that do not have the capacity to process chip cards will be that of the acquirer.
b) Liability for transactions processed with magnetic stripe-only cards on a terminal that has chip reading enabled will be that of the issuer that does not operate under the EMV standard.

17. Standard encryption algorithms must be applied to authenticate the chip card and the operation data. 18. In addition to robust authentication factors with the use of PIN, biometric authentication systems can be used to verify the cardholder's identity. 19. In case the issuer authorizes the performance of off-line operations, cards must use a dynamic authentication mechanism (CAM) of type DDA or CDA that allows recalculating the value of the digital signature in each transaction, for which they must be equipped with a cryptoprocessor. 20. The operating system of the cards can be native platform or open, both must have the capacity to handle DDA or CDA, in case the issuer accepts the processing of off-line transactions. 21. For contactless technology payments, issuers must implement in their monitoring and tracking systems internal control mechanisms, strict security parameters, and alerts for fraud prevention based on the creation of rules of frequency, speed, limit amounts, and others that allow controlling the number of transactions approved under contactless technology. Among these measures, they must establish for their customers a daily limit amount for this type of transaction, modifiable at the holder's request, so that when it is exceeded, transactions are rejected. 22. Issuers must provide their customers with secure mechanisms that allow them to enable and disable the use of PIN in in-person transactions with contactless technology cards.

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

Abbreviations

CAM = Card Authentication Method, card authentication method CVV = Card Verification Value, card verification value CDA = Combined Data Authentication, combined data authentication DDA = Dynamic Data Authentication, dynamic data authentication EMV = Europay, MasterCard and Visa PAN = Primary Account Number, primary account number CAV2 = Card Security Code, card validation code for JCB CID = Card Security Code, card validation code for American Express CVC2 = Card Security Code, card validation code for MasterCard CVV2 = Card Security Code, card validation code for VISA PIN = Personal Identification Number, personal identification number

Glossary

Authentication: Procedure that allows checking the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.

Secure Environment: Environments under the responsibility of the issuer in which adequate client authentication is guaranteed as well as the protection of confidential and sensitive information.

III.

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

IV. Minimum Operational Security Requirements for Mobile Wallet

  1. The issuer must link to the mobile wallet account number, the full name of the holder, identity document, and mobile device number, provided that positive verification of the identity of the mobile wallet holder has been previously carried out. Likewise, it must keep a record of the operations processed for a period of at least ten (10) years.
  2. Payment orders must be processed through means that guarantee compliance with the following security characteristics: a) Authenticity. Have mechanisms that allow verifying the identity of the holder of the electronic payment instrument in each transaction. b) Integrity. Be protected against accidental or fraudulent alterations during their processing, transport, and storage. c) Confidentiality. Have standard encryption mechanisms that prevent the dissemination or unauthorized disclosure of the information contained in the operation throughout the transaction. d) Non-repudiation. Guarantee that none of the parties involved in the transaction can deny their participation in it. e) Availability. The processing system must be available to users according to the advertised, informed, or contractually agreed conditions with financial consumers.
  3. The issuer must provide the user with a password to authenticate to the service and generate mechanisms to remind them to change it at least every ninety (90) days. At no time shall this password be stored in the mobile wallet.
  4. Issuers must implement robust authentication mechanisms. That is, establish at least a double factor for user authentication in the following operational instances: a) Authorization for the processing of payment orders. b) Authorization for the introduction and modification of beneficiary data or other sensitive information, whose modification could lead to the commission of crimes or fraud.

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

c) Other authorizations involving the processing of payment orders such as internet purchases or commercial and service establishments.

At least one of the factors applied must not be reusable or replicable nor susceptible to being stolen via the internet. In this sense, it is feasible to use a one-time password, generated by a key generator software (tokens), or a combination of numbers from a coordinate card.

The use of double factor authentication at login is optional.

Mobile phone balance purchase operations are exempt from the application of the double or multiple factor authentication mechanism up to a maximum amount of Bs20 (Twenty Bolivianos).

  1. For mobile phone balance purchase payments exempt from the application of the robust authentication mechanism, issuers must implement in their monitoring and tracking systems internal control mechanisms, strict security parameters, and alerts, for fraud prevention. Additionally, they must establish limits for transactions, modifiable at the client's request, so that when these are exceeded, transactions are rejected.
  2. Issuers must carry out information campaigns on the security of the use of the instrument directed at mobile wallet users, which must also include: a) Description of operations and/or functionalities b) Use of the service c) Use of robust authentication mechanisms: operation and cases of application. d) Changes in operation and/or in authentication mechanisms and/or processing of payment orders. e) System for handling customer complaints and inquiries.
  3. The maximum inactivity time in a session must not exceed 60 seconds.

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA 1928]

BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

Abbreviations

ESP = Payment Service Company

Glossary

Authentication: Procedure that allows checking the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.

The BCB contributes to the economic and social development of the country Ayacucho Street corner Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia