2017-12-29 | 046 2017 SGDB EXTAdded · Updated
The Central Bank of Bolivia establishes minimum operational security requirements for electronic fund transfer orders, electronic cards, and mobile wallets, replacing Circular Externa SGDB No. 005/2016. Financial entities, payment service companies, ACCI S.A., and EDV S.A. must implement robust authentication mechanisms, including at least two-factor authentication for logins and transaction authorizations, and ensure data integrity, confidentiality, and non-repudiation. Specific mandates include the use of SSL/TLS protocols, EMV chip standards for card transactions, dynamic data authentication for offline operations, and mandatory user information campaigns regarding security practices.
BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA
CIRCULAR EXTERNA La Paz, December 29, 2017 SGDB No. 046/2017
FROM: GENERAL MANAGEMENT FINANCIAL ENTITIES MANAGEMENT
TO: FINANCIAL ENTITIES, PAYMENT SERVICE COMPANIES, ACCI S.A., EDV S.A.
SUBJECT: MINIMUM OPERATIONAL SECURITY REQUIREMENTS FOR ELECTRONIC PAYMENT INSTRUMENTS
Ladies and Gentlemen:
In the framework of its regulatory powers over the national payment system and in accordance with Article 27 of the Regulations on Payment Services, Electronic Payment Instruments, Compensation and Settlement, approved by Supreme Resolution No. 134/2015 of July 28, 2015, and its modifications approved by Supreme Resolution No. 071/2017 of May 23, 2017, the Central Bank of Bolivia transmits for application and compliance the update to the Minimum Operational Security Requirements for:
The Minimum Operational Security Requirements for the aforementioned electronic payment instruments constitute the normative reference framework for the application of standards and best practices in payment systems operating with these instruments. Circular Externa SGDB No. 005/2016 of February 12, 2016, is hereby repealed.
Sincerely,
Calle Ayacucho esquina Mercado. Phone: (591-2) 2409090. Fax: (591-2) 2661590 www.bcb.gob.bo bancocentraldebolivia@bcb.gob.bo . La Paz Bolivia
The following requirements mark the minimum operational conditions for EFTO application within the national territory.
Transactional services must operate using encrypted communication channels on a secure server under the SSL or TLS protocol.
The secure site (web page) must indicate the name of the entity issuing the certificate and a link to the certifying entity that allows access to the following information to verify its validity: certifying entity, web page name, name of the entity owning the site, and certificate validity. The provider of the transactional services must not enable an access account without prior consent from the client or holder.
The digital certificate will be valid until the expiration date indicated therein. In no case shall the validity of the digital certificate exceed that defined in the Digital Signature Regulations for the Payment System issued by the BCB.
Financial entities must implement robust authentication mechanisms in their operations, through internet portals and mobile banking. That is, establish at least double factor authentication for users in the following operational instances: a) Login to the mobile application or internet banking portal. b) Authorization for the processing of EFTOs. c) Authorization for the introduction and modification of beneficiary data or other sensitive information whose modification could facilitate the commission of crimes or fraud. d) Other authorizations involving the processing of EFTOs, such as enabling a debit card for internet payments. At least one of the applied factors must not be reusable, replicable, or susceptible to being stolen via the internet (for example, a one-time password specific for a payment generated by a key generator software (tokens) or a combination of numbers from a coordinate card, etc.).
Fund transfers must be credited to customer accounts once the validation processes required by the processing system are completed, and at the latest by the end of the cycle in case the processing involves compensation and settlement processes.
EFTOs must meet the following characteristics: a) Authenticity. They must have mechanisms that allow verification of the identity of the holder of the electronic payment instrument. b) Integrity. They must have the quality of being protected against accidental or fraudulent alterations during their processing, transport, and storage. c) Confidentiality. They must have standard encryption mechanisms that prevent unauthorized dissemination or disclosure of the information contained in the operation. d) Non-repudiation. They must guarantee that none of the parties involved in the transaction can deny their participation in it. e) Availability. The issuer, within its control, must guarantee that the processing system is available to users according to the advertised, informed, or agreed conditions with financial consumers and as established contractually.
The exchange of information between financial entities and external technology service providers must meet the security characteristics described in point 6.
The exchange of information for the processing of EFTOs between financial entities and compensation and settlement systems must comply with what is defined in the Digital Signature Regulations for the Payment System issued by the BCB.
Financial entities must carry out information campaigns regarding the security of the use of the instrument directed at EFTO users, which must also include: a) Description of operations and/or functionalities. b) Use of the service. c) Use of robust authentication mechanisms: operations and cases of application. d) Changes in operations and/or authentication mechanisms and/or processing of payment orders. e) Customer complaint and inquiry handling system.
Abbreviations SSL = Secure Sockets Layer, secure connection layer TLS = Transport Layer Security, transport layer security
Glossary Authentication: Procedure that allows verifying the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors: .. Something the user knows .. Something the user has .. Something the user is Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.
Calle Ayacucho esquina Mercado. Phone: (591-2) 2409090. Fax: (591-2) 2661590 www.bcb.gob.bo bancocentraldebolivia@bcb.gob.bo . La Paz Bolivia
The following requirements mark the minimum operational conditions for electronic cards for application within the national territory.
Electronic cards must be issued physically and may be used virtually at the holder's request.
Electronic cards must contain printed, engraved, or embossed, as appropriate, the following data: issuer name, card number, card verification value, and when applicable, name, logo, and hologram of the international brand. The credit card must include the expiration date.
The last four digits embossed, engraved, or printed on the card must match the digits appearing on the receipt generated by the terminal at the time of making withdrawals or in-person purchases.
In the case of debit or prepaid cards, the issuer must offer the holder the option of printing the cardholder's name on the plastic, explaining the advantages and disadvantages of the selection. In case the client does not wish to include this data, the issuer must record and save the selection made with the holder's signature.
The magnetic stripe of electronic cards must contain the following information: primary account number (PAN), expiration date, PIN verification value, card verification value (CVV/CW), and service code. This information must be validated by the issuer at the time of processing transactions.
The card validation code (CAV2, CID, CVC2, CW2) or PIN validation data must not be stored in systems or databases.
Messages exchanged between terminals must be generated under the ISO 8583 standard, which may be adapted to specific needs to facilitate the interoperability of the platforms involved.
Electronic Card Administrator Companies that process transactions with electronic cards must communicate to their participants, the BCB, and the ASFI, with a 30 calendar day advance, any updates made to the ISO 8583 standard.
The enabling of electronic cards for internet purchases and the processing of internet payments on national merchant web pages must be carried out in secure and trusted environments.
Issuers must implement robust authentication mechanisms for the authorizations of electronic cards used virtually, considering that at least one of the applied factors must not be reusable, replicable, or susceptible to being stolen via the internet (for example, a one-time password specific for a payment generated by a key generator software (tokens), a combination of numbers from a coordinate card, etc.).
As a robust authentication mechanism for chip cards, the holder or user of the instrument, to make in-person purchases at merchants with electronic cards, must enter the PIN once the merchant has entered the purchase amount, which must be visible for the security and certainty of the holder or user. In this sense, issuers must provide in the design of the instrument that the service code requires the entry of the PIN to perform transactions.
When chip cards are used to process in-person purchases at merchants, a printed voucher for the client will not be issued, unless requested by the client, in which case it will not require a handwritten signature.
In the case of electronic cards from foreign issuers that have only a magnetic stripe for processing at merchants in Bolivia, the holder or user of the instrument at the time of making an in-person purchase must enter their PIN or present their identification document and sign the transaction receipts.
Acquirers must instruct merchants to process transactions always using chip reading.
The commissions that merchants pay to Electronic Card Administrator Companies cannot be transferred to the holder or user of the electronic card.
Disputes or claims regarding the processing of transactions will fall on the issuing or acquiring entities that do not operate with chip cards under the EMV standard as follows: a) Responsibility for transactions processed with magnetic stripe on terminals that do not have the capacity to process chip cards will be with the acquirer. b) Responsibility for transactions processed with magnetic stripe-only cards on a terminal that has chip reading enabled will be with the issuer that does not operate under the EMV standard.
Standard encryption algorithms must be applied to authenticate the chip card and the operation data.
To verify the identity of the cardholder, biometric authentication systems may also be used.
In case the issuer authorizes the execution of offline operations, payment cards must use a dynamic Card Authentication Method (CAM) of type DDA or CDA that allows recalculating the digital signature value in each transaction, for which they must be equipped with a cryptoprocessor.
The operating system of the cards may be native platform or open; both must have the capacity to handle DDA or CDA, in case the issuer accepts the processing of offline transactions.
Abbreviations CAM = Card Authentication Method CW = Card Verification Value CDA = Combined Data Authentication DDA = Dynamic Data Authentication EMV = Europay, MasterCard and Visa PAN = Primary Account Number CAV2 = Card Security Code, card validation code for JCB CID = Card Security Code, card validation code for American Express CVC2 = Card Security Code, card validation code for MasterCard CW2 = Card Security Code, card validation code for VISA PIN = Personal Identification Number
Glossary Authentication: Procedure that allows verifying the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors: . Something the user knows . Something the user has . Something the user is Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.
Calle Ayacucho esquina Mercado. Phone: (591-2) 2409090. Fax: (591-2) 2661590 www.bcb.gob.bo bancocentraldebolivia@bcb.gob.bo . La Paz Bolivia
The following requirements mark the minimum operational conditions for mobile wallets for application within the national territory.
The issuer must link the mobile wallet account number to the holder's full name, identity document, and mobile device number, provided that positive verification of the mobile wallet holder's identity has been previously carried out. Likewise, the issuer must maintain a record of processed operations for a period of at least ten (10) years.
Payment orders must be processed through means that guarantee compliance with the following security characteristics: a) Authenticity. They must have mechanisms that allow verification of the identity of the holder of the electronic payment instrument in each transaction. b) Integrity. They must have the quality of being protected against accidental or fraudulent alterations during their processing, transport, and storage. c) Confidentiality. They must have standard encryption mechanisms that prevent unauthorized dissemination or disclosure of the information contained in the operation throughout the transaction. d) Non-repudiation. They must guarantee that none of the parties involved in the transaction can deny their participation in it. e) Availability. The issuer must guarantee that the processing system is available to users according to the advertised, informed, or agreed conditions with financial consumers and as established contractually.
The user must have a password to authenticate to the service. The issuer must generate mechanisms to remind the user to change their password periodically, at least every ninety (90) days. At no time shall this key be stored in the mobile wallet.
Financial entities and Payment Service Companies (ESP) must implement robust authentication mechanisms. That is, establish at least double factor authentication for users in the following operational instances: a) Login. b) Authorization for the processing of payment orders. c) Authorization for the introduction and modification of beneficiary data or other sensitive information whose modification could facilitate the commission of crimes or fraud. d) Other authorizations involving the processing of payment orders, such as payments at merchants or internet purchases. At least one of the applied factors must not be reusable, replicable, or susceptible to being stolen via the internet (for example, a one-time password specific for a payment generated by a key generator software (tokens), a combination of numbers from a coordinate card, etc.).
The issuer must ensure that the maximum inactivity time in a session does not exceed sixty (60) seconds.
Financial entities and Payment Service Companies (ESP) must carry out information campaigns regarding the security of the use of the instrument directed at mobile wallet users, which must also include: a) Description of operations and/or functionalities. b) Use of the service. c) Use of robust authentication mechanisms: operations and cases of application. d) Changes in operations and/or authentication mechanisms and/or processing of payment orders. e) Customer complaint and inquiry handling system.
Abbreviations ESP = Payment Service Company
Calle Ayacucho esquina Mercado. Phone: (591-2) 2409090. Fax: (591-2) 2661590 www.bcb.gob.bo bancocentraldebolivia@bcb.gob.bo . La Paz Bolivia
Glossary Authentication: Procedure that allows verifying the identity of the holder of the Electronic Payment Instrument. Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors: . Something the user knows . Something the user has . Something the user is Authorization: Procedure to check if the holder of the Electronic Payment Instrument has the right to perform a specific action, for example, the right to transfer funds or access sensitive data.
Calle Ayacucho esquina Mercado. Phone: (591-2) 2409090. Fax: (591-2) 2661590 www.bcb.gob.bo bancocentraldebolivia@bcb.gob.bo . La Paz Bolivia