2018-02-20 | 011 2018 SGDB EXTAdded · Updated
The Central Bank of Bolivia amends point 4 of the Minimum Operational Security Requirements for Electronic Funds Transfer Orders (OETF) and Mobile Wallets by adding an exception to the rule prohibiting internet-based theft of authentication factors. This exception allows the use of optional login factors, as established in subsection a), which were previously subject to the same security constraints. The modification applies to financial entities, payment service companies, ACCI S.A., and EDV S.A.
EXTERNAL CIRCULAR
La Paz, February 16, 2018
SGDB No. 011/2018
FROM: GENERAL MANAGEMENT, FINANCIAL ENTITIES MANAGEMENT - FINANCIAL ENTITIES, PAYMENT SERVICE COMPANIES, ACCI S.A., EDV S.A.
MODIFICATION OF EXTERNAL CIRCULAR SGDB No. 046/2017 of December 28, 2017
TO:
SUBJECT:
Ladies and Gentlemen:
The Central Bank of Bolivia submits for your application and compliance the modification to point 4, of the Minimum Operational Security Requirements for Electronic Funds Transfer Orders (OETF) and Mobile Wallet, in the following terms:
Where it says:
"At least one of the applied factors must not be reusable or replicable, nor susceptible to being stolen via the internet (for example, a one-time password specific for a payment and generated by a key generator software (tokens) or a combination of numbers from a coordinate card, etc.)."
It must say:
"At least one of the applied factors must not be reusable or replicable, nor susceptible to being stolen via the internet (for example, a one-time password specific for a payment and generated by a key generator software (tokens) or a combination of numbers from a coordinate card, etc.), with the exception of the login case, established in subsection a), where its use is optional."
Sincerely,
[Signature]
Calle Ayacucho esquina Mercado - Telephone: (591-2) 2409090 - Fax: (591-2) 2661590 www.bcb.gob.bo - bancocentraldebolivia@bcb.gob.bo - La Paz - Bolivia