2021-03-01 | CIEX N° 8/2021Added · Updated
The Central Bank of Bolivia updates the Minimum Operational Security Requirements for Electronic Payment Instruments, replacing Circular Externa CIEX No. 03/2020. The regulation mandates robust authentication mechanisms, including two-factor authentication for fund transfers and mobile wallets, and specifies security standards for electronic cards such as chip usage and contactless transaction limits. It establishes specific monetary thresholds for PIN exemptions, setting a maximum of Bs150 for contactless card transactions and Bs20 for mobile wallet balance purchases. The document also imposes obligations on issuers and payment service companies regarding data protection, fraud prevention monitoring, and user information campaigns.
Calle Ayacucho esquina Mercado - Teléfono: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz – Bolivia EXTERNAL CIRCULAR La Paz, February 24, 2021 CIEX No. 8/2021 FROM: GENERAL MANAGEMENT FINANCIAL ENTITIES DEPARTMENT TO: FINANCIAL ENTITIES, PAYMENT SERVICE COMPANIES, ACCL S.A., EDV S.A. SUBJECT: MINIMUM OPERATIONAL SECURITY REQUIREMENTS FOR ELECTRONIC PAYMENT INSTRUMENTS
Gentlemen:
In the framework of its regulatory powers over the national payment system and in accordance with Article 27 of the Regulation on Payment Services, Electronic Payment Instruments, Compensation and Settlement (RSPIEPCL), approved by BCB Board Resolution No. 137/2019 of 08.10.2019 and its modifications, the Central Bank of Bolivia transmits for application and compliance the update to the Minimum Operational Security Requirements for:
I. Electronic fund transfer orders. II. Electronic cards. III. Mobile wallets.
The Minimum Operational Security Requirements for the aforementioned electronic payment instruments constitute the normative reference framework for the application of standards and best practices in payment systems operating with these instruments. Circular Externa CIEX No. 03/2020 of 02.01.2020 is hereby repealed.
Sincerely,
DIGITALLY SIGNED DOCUMENT Sergio Marcelo Cerezo Aguirre MANAGER OF FINANCIAL ENTITIES Rubén Gonzalo Ticona Chique GENERAL MANAGER
Validate digital signatures at: validar.firmadigital.bo RGTCH/SMCA/ropr/pmms/aaoa Adj.: As cited
Calle Ayacucho esquina Mercado - Teléfono: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz – Bolivia
I. Minimum Operational Security Requirements for Electronic Fund Transfer Orders
Transactional services must operate using encrypted communication channels on a secure server under the SSL or TLS protocol.
The secure web page must indicate the name of the entity that issued the site's digital certificate and a link to the certification authority that allows validation of: the certifying entity, the web page name, the name of the entity owning the site, and the validity of the certificate. The provider of transactional services must not enable an access account without the prior consent of the client or holder.
The digital certificate will be valid until the expiration date indicated therein. Under no circumstances shall the validity of the digital certificate exceed that defined in the Digital Signature Regulation for the Payment System issued by the BCB.
Financial entities must implement in their operations, through internet portals and mobile banking, robust authentication mechanisms. That is, establish at least double factor authentication for users in the following operational instances: a) Authorization for the processing of Electronic Fund Transfer Orders (OETF). b) Authorization for the introduction and modification of beneficiary data or other sensitive information whose modification could facilitate the commission of crimes or fraud. c) Other authorizations involving the processing of OETF, such as enabling a debit card for internet payments. At least one of the factors applied must not be reusable, replicable, or susceptible to being stolen via the internet. In this sense, it is feasible to use a one-time password, generated by a key generator software (tokens) or a combination of numbers from a coordinate card. The use of double factor authentication at login is optional.
Fund transfers must be credited to clients' accounts once the validation processes required by the processing system are completed, and at the latest by the end of the cycle in case the processing involves compensation and settlement processes.
Calle Ayacucho esquina Mercado - Teléfono: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz – Bolivia
OETF must comply with the following characteristics: a) Authenticity. Have mechanisms that allow verifying the identity of the holder of the electronic payment instrument. b) Integrity. Be protected against accidental or fraudulent alterations during their processing, transport, and storage. c) Confidentiality. Have standard encryption mechanisms that prevent the unauthorized dissemination or disclosure of the information contained in the operation. d) Non-repudiation. Guarantee that none of the parties involved in the transaction can deny their participation in it. e) Availability. The issuer, within its control, must guarantee that the processing system is available to users according to the advertised, informed, or contractually agreed conditions with financial consumers.
The exchange of information between financial entities and external technology service provider companies must comply with the security characteristics described in point 6.
The exchange of information for the processing of OETF between financial entities and compensation and settlement systems must comply with what is defined in the Digital Signature Regulation for the Payment System issued by the BCB.
Financial entities must carry out information campaigns regarding the security of the use of the instrument directed at OETF users, which must also include: a) Description of operations and/or functionalities. b) Use of the service. c) Use of robust authentication mechanisms: operations and application cases. d) Changes in operations and/or authentication mechanisms and/or processing of payment orders. e) System for handling customer complaints and inquiries.
Abbreviations SSL = Secure Sockets Layer, secure connection layer TLS = Transport Layer Security, transport layer security
Calle Ayacucho esquina Mercado - Teléfono: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz – Bolivia
Glossary Authentication: Procedure that allows verifying the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of a combination of two of the following three authentication factors: • Something the user knows • Something the user has • Something the user is Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.
II. Minimum Operational Security Requirements for Electronic Cards
Electronic cards must be issued physically and can be used virtually at the holder's request.
Electronic cards must contain printed, engraved, or embossed, as appropriate, the following data: issuer name, card number, card verification value, and when applicable, name, logo, and hologram of the international brand. The credit card must include the expiration date.
The last four digits embossed, engraved, or printed on the card must match the digits appearing on the receipt generated by the terminal at the time of making withdrawals or in-person purchases.
In the case of debit or prepaid cards, the issuer must offer the holder the option of printing the cardholder's name on the plastic, explaining the advantages and disadvantages of the selection. In case the client does not wish to include this data, the issuer must record and save the selection made with the holder's signature.
The magnetic stripe of electronic cards must contain the following information: primary account number (PAN), expiration date, PIN verification value, card verification value (CVV), and service code. This information must be validated by the issuer at the time of processing transactions.
Calle Ayacucho esquina Mercado - Teléfono: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz – Bolivia
The card validation code (CAV2, CID, CVC2, CVV2) or PIN validation data must not be stored in systems or databases.
Messages exchanged between terminals must be generated under the ISO 8583 standard, which may be adapted to particular needs to facilitate the interoperability of the platforms involved.
Electronic Card Administrator Companies that process transactions with electronic cards must communicate to their participants, the BCB, and the ASFI, with a 30 calendar day advance notice, any updates made to the ISO 8583 standard.
The enabling of electronic cards for internet purchases and the processing of internet payments on web pages of national commercial or service establishments must be carried out in secure and trusted environments.
Issuers must implement robust authentication mechanisms for the authorizations of electronic cards used virtually, considering that at least one of the factors applied must not be reusable, replicable, or susceptible to being stolen via the internet (for example, a one-time password specific for a payment and generated by key generator software (tokens), a combination of numbers from a coordinate card, etc.).
As a robust authentication mechanism for chip cards, the holder or user of the instrument, to make in-person payments at commercial or service establishments, with electronic cards, must enter the PIN once the establishment manager enters the transaction amount, which must be visible for the security and certainty of the holder or user. In this sense, issuers must foresee in the design of the instrument that the service code requires the entry of the PIN to perform transactions.
In-person transactions with contactless technology cards are exempt from the application of the PIN up to a maximum amount of Bs150 (One hundred fifty Bolivianos).
When using chip cards to process in-person payments at commercial or service establishments, the handwritten signature or the issuance of a printed voucher for the client is not necessary, unless requested by the latter.
For the case of electronic cards from foreign issuers that have only a magnetic stripe for processing at commercial or service establishments in Bolivia, the holder or user of the instrument at the time of making an in-person purchase must enter their PIN or present their identification document and sign the transaction receipts.
Acquirers must instruct commercial or service establishments to always process transactions using chip reading.
The commissions paid by commercial or service establishments to Electronic Card Administrator Companies cannot be transferred to the holder or user of the electronic card.
Disputes or claims regarding the processing of transactions will fall on the issuing or acquiring entities that do not operate with chip cards under the EMV standard as follows: a) Responsibility for transactions processed with magnetic stripe on terminals that do not have the capacity to process chip cards, will be that of the acquirer. b) Responsibility for transactions processed with magnetic stripe-only cards on a terminal that has chip reading enabled, will be that of the issuer that does not operate under the EMV standard.
Standard encryption algorithms must be applied to authenticate the chip card and the operation data.
In addition to robust authentication factors with the use of PIN, biometric authentication systems can be used to verify the cardholder's identity.
In case the issuer authorizes the performance of offline operations, cards must use a dynamic authentication mechanism (CAM) of type DDA or CDA that allows recalculating the digital signature value in each transaction, for which they must be equipped with a cryptoprocessor.
The card operating system may be of native or open platform; both must have the capacity to handle DDA or CDA, in case the issuer accepts the processing of offline transactions.
Calle Ayacucho esquina Mercado - Teléfono: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz – Bolivia
For payments with contactless technology, issuers must implement in their monitoring and tracking systems, internal control mechanisms, strict security parameters, and alerts for fraud prevention based on the creation of rules for frequency, speed, limit amounts, and others that allow controlling the number of transactions approved under contactless technology responding to a risk analysis by product type and transaction volume of said technology. Among these measures, they must establish for their customers a daily limit amount per product.
Issuers, for the purpose of incentivizing the secure use of contactless technology cards, must provide their customers with training on the use of this type of card and regarding the limit amount for in-person transactions exempt from the application of PIN.
Abbreviations CAM = Card Authentication Method, card authentication method CVV = Card Verification Value, card verification value CDA = Combined Data Authentication, combined data authentication DDA = Dynamic Data Authentication, dynamic data authentication EMV = Europay, MasterCard and Visa PAN = Primary Account Number, primary account number CAV2 = Card Security Code, card validation code for JCB CID = Card Security Code, card validation code for American Express CVC2 = Card Security Code, card validation code for MasterCard CVV2 = Card Security Code, card validation code for VISA PIN = Personal Identification Number, personal identification number
Glossary Authentication: Procedure that allows verifying the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of a combination of two of the following three authentication factors: • Something the user knows • Something the user has • Something the user is Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data. Secure Environment: Environments under the responsibility of the issuer where adequate client authentication is guaranteed as well as the protection of confidential and sensitive information.
III. Minimum Operational Security Requirements for Mobile Wallet
The issuer must link the mobile wallet account number to the holder's full name, identity document, and mobile device number, provided that positive verification of the mobile wallet holder's identity has been previously carried out. Likewise, it must maintain a record of processed operations for a period of at least ten (10) years.
Payment orders must be processed through means that guarantee compliance with the following security characteristics: a) Authenticity. Have mechanisms that allow verifying the identity of the holder of the electronic payment instrument in each transaction. b) Integrity. Be protected against accidental or fraudulent alterations during their processing, transport, and storage. c) Confidentiality. Have standard encryption mechanisms that prevent the unauthorized dissemination or disclosure of the information contained in the operation throughout the transaction. d) Non-repudiation. Guarantee that none of the parties involved in the transaction can deny their participation in it. e) Availability. The processing system must be available to users according to the advertised, informed, or contractually agreed conditions with financial consumers.
Calle Ayacucho esquina Mercado - Teléfono: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz – Bolivia
The issuer must provide the user with a password to authenticate to the service and generate mechanisms to remind them to change it at least every ninety (90) days. Under no circumstances shall this key be stored in the mobile wallet.
Issuers must implement robust authentication mechanisms. That is, establish at least double factor authentication for users in the following operational instances: a) Authorization for the processing of payment orders. b) Authorization for the introduction and modification of beneficiary data or other sensitive information whose modification could facilitate the commission of crimes or fraud. c) Other authorizations involving the processing of payment orders such as payments at merchants or internet purchases. At least one of the factors applied must not be reusable, replicable, or susceptible to being stolen via the internet. In this sense, it is feasible to use a one-time password, generated by software, key generator (tokens), or a combination of numbers from a coordinate card. The use of authentication factor at login is optional. Mobile balance top-up operations are exempt from the application of the double or multiple factor authentication mechanism up to a maximum amount of Bs20 (Twenty Bolivianos).
For mobile balance top-up payments exempt from the application of the robust authentication mechanism, issuers must implement in their monitoring and tracking systems internal control mechanisms, strict security parameters, and alerts, for fraud prevention. Additionally, they must establish modifiable limits at the client's request for the processing of this type of transaction; when these limits are exceeded, transactions will be rejected.
Financial entities and PSPs must carry out information campaigns regarding the security of the use of the instrument directed at mobile wallet users, which must also include: a) Description of operations and/or functionalities b) Use of the service c) Use of robust authentication mechanisms: operations and application cases. d) Changes in operations and/or authentication mechanisms and/or processing of payment orders. e) System for handling customer complaints and inquiries.
The issuer must ensure that the maximum inactivity time in a session does not exceed 60 seconds.
Abbreviations PSP = Payment Service Company
Glossary Authentication: Procedure that allows verifying the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of a combination of two of the following three authentication factors: • Something the user knows • Something the user has • Something the user is Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.