2021-01-28 | DOF 5610487Added · Updated
The Bank of Mexico and the National Banking and Securities Commission issue general provisions establishing regulatory requirements for electronic payment fund institutions, including definitions for key terms such as authentication, instruction channels, and security incidents. The document mandates specific security standards for technological infrastructure, business continuity plans, and the notification of security incidents and operational contingencies to clients and regulators. It also regulates the contracting of third-party services and commissionaires, requiring independent third-party evaluations of security and operational continuity compliance.
If the document appears incomplete on the right margin, it contains tables that exceed the default width. If this is the case, click here to view it correctly.
DOF: 28/01/2021
PROVISIONS applicable to electronic payment fund institutions referenced in Articles 48, second paragraph; 54, first paragraph, and 56, first and second paragraphs of the Law for Regulating Financial Technology Institutions
At the margin, a seal with the National Coat of Arms, which reads: United Mexican States.- TREASURY.- Ministry of
Treasury and Public Credit.- National Banking and Securities Commission.- Bank of Mexico.
The Bank of Mexico, based on the provisions of Articles 28, sixth and seventh paragraphs of the
Political Constitution of the United Mexican States; 24, 26 and 36 of the Bank of Mexico Law; 4th, first paragraph;
8th, fourth and eighth paragraphs; 10, first paragraph; 14 Bis in relation with 17, fraction I, and 15 in
relation with 20 Quáter, fraction IV of the Internal Regulations of the Bank of Mexico; Second, fractions
VIII and
X of the Agreement on the Assignment of Administrative Units of the Bank of Mexico, and 48, second paragraph;
54, first paragraph and 56 of the Law for Regulating Financial Technology Institutions; and the National
Banking and Securities Commission, based on the provisions of Articles 48, second paragraph;
54, first paragraph and 56 of the Law for Regulating Financial Technology Institutions; 98 Bis of the Credit
Institutions Law, as well as 4, fractions XXXVI and XXXVIII, and 16, fractions I and XVII of the Law of the
National Banking and Securities Commission, and
CONSIDERING
That, in accordance with Article 78 of the General Law for Regulatory Improvement and with the purpose of reducing the
cost of compliance with these provisions, the National Banking and Securities Commission, through
resolution published in the Official Gazette of the Federation on December 26, 2017, modified the
General Provisions applicable to credit institutions, to flex the deadline to which
multiple banking institutions were subject to establish their capital requirements for operational risk;
That on March 9, 2018, the "Decree by which the
Law for Regulating Financial Technology Institutions is issued and various provisions of the Credit Institutions Law, the Securities Market Law, the General Law of Organizations and Auxiliary Credit Activities, the Law for Transparency and Orderly Management of Financial Services, the Law for Regulating Credit Information Societies, the Law for Protection and Defense of Users of Financial Services, the Law for Regulating Financial Aggregations, the Law of the National Banking and Securities Commission and, the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin" was published in the Official Gazette of the Federation;
That the Law for Regulating Financial Technology Institutions incorporates, within the framework of the
national financial system, financial technology institutions, while empowering the Bank of Mexico and the
National Banking and Securities Commission to jointly issue the general provisions that must be observed by
electronic payment fund institutions, which shall be governed by the principles of inclusion and financial innovation, promotion of competition, consumer protection, preservation of financial stability and technological neutrality;
That, in order to have adequate regulation for electronic payment fund institutions and
in accordance with the principles stated in the immediate preceding Consideration, these
general provisions are issued as a unified, systematic, coherent and clear regulatory framework that
provides legal certainty to participants in the financial technology market, fosters the growth of
electronic payment fund institutions and safeguards the interests of the clients of these institutions and
of the financial system as a whole;
That, to guarantee the security of operations conducted with clients, the
requirements that the authentication of the client themselves and the notification made to them at the
moment of agreeing or conducting such operations must meet are established, as well as the terms and conditions of the provision of
services through instruction channels, while also establishing the requirements
for information security regarding these instruction channels in order to guarantee
confidentiality and avoid vulnerabilities, in accordance with best practices and international
standards;
That, to safeguard the sequence in the activities and operations carried out by electronic payment fund institutions, it is indispensable to establish the obligation to have a business continuity plan that must be implemented upon verification of any event that hinders, prevents or limits them from carrying out their operations or processes with an impact on their clients in the eventuality of failures due to unforeseen situations or events, which is strengthened by the obligation to have mechanisms for the administration of operational contingencies that reduce the risks to which they are exposed, such as the designation of the person responsible for the administration of contingencies and the necessary certifications in this matter when the aforementioned financial institutions hire third-party services to support their operation;
That, regarding those electronic payment fund institutions that have a higher
volume of accounts or operations and carry out their main processes through cloud computing
provided by a third party, it is necessary that these include in their respective business continuity plans
special measures for prudential reasons, in order to protect the interests of their clients, as well as to
maintain the operational and financial security and integrity of these institutions individually, and the
operational security and integrity of the payment system as a whole, without prejudice to any other
measures imposed by these and other applicable provisions;
That, in protection of the interests of the clients of electronic payment fund institutions,
it is necessary to establish the obligation for these institutions to notify their clients of the existence
of information security incidents involving the loss, extraction, deletion or alteration of personal information or sensitive information of these clients, whether it is in the possession of the electronic payment fund institutions themselves or of third parties providing services to them, indicating the deadlines and terms for such notification, the measures that will be implemented to safeguard client information and, if applicable, the replacement or substitution of the means of disposal or authentication factors that the electronic payment fund institutions themselves consider necessary to carry out;
That, with the purpose that clients have knowledge of the degree of operational efficiency that electronic payment fund institutions have with which they conduct operations, it is considered relevant to establish that these financial entities must inform the National Banking and Securities Commission and the Bank of Mexico of operational contingencies lasting at least 30 minutes, occurring in any of the public service channels or within the electronic payment fund institution itself, while also specifying the elements that such communication must meet and the deadline by which it must be made once the operational contingency in question has occurred; in addition to the above and in protection of the interests of their clients or users of means of disposal, the minimum elements of the notification that these financial entities must make when one or more instruction channels are affected as a result of these operational contingencies are established;
That, in order to procure greater legal certainty and security for the operations of electronic payment fund institutions and thereby protect the interests of their clients, it is considered indispensable to indicate the terms and requirements that these financial technology institutions must observe to contract services with third parties and to conduct commercial commissions, establishing the circumstances in which they will require the authorization of the National Banking and Securities Commission and the Bank of Mexico for the execution of such contracts;
That, in order to have transparency in the information generated due to the relationships that electronic payment fund institutions have with third parties, the characteristics of the registry of all their service providers, including sub-contracted providers by these, as well as administrators of commissionaires and commissionaires, with which electronic payment fund institutions have contracted service provision or commercial commission agreements are specified, also providing for the dissemination that these financial institutions will give, through their Internet page or mobile application, of the list of modules or establishments of commissionaires, in which they will indicate the operations and the allowed operation amounts;
And that, in order to have transparent, reliable and comparable financial information, for the benefit of the
electronic payment fund institutions themselves, their clients and the supervisory functions of the
Bank of Mexico and the National Banking and Securities Commission, it is established that these financial
institutions must hire the services of an independent third party for the evaluation of compliance with the information security requirements, the use of instruction channels and operational continuity that they must observe, indicating the characteristics that said independent third party must meet; therefore, they have resolved to issue the following:
PROVISIONS APPLICABLE TO ELECTRONIC PAYMENT FUND INSTITUTIONS
REFERENCED IN
ARTICLES 48, SECOND PARAGRAPH; 54, FIRST PARAGRAPH,
AND 56, FIRST AND
SECOND PARAGRAPHS OF THE LAW FOR REGULATING
FINANCIAL TECHNOLOGY INSTITUTIONS
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
ON INFORMATION SECURITY
First Section
On Technological Infrastructure vis-à-vis Clients
Section A
On the execution of contracts through Instruction Channels and Operations through them
Section B
On Authentication in Instruction Channels
Section C
On information security requirements in Instruction Channels
Second Section
On Technological Infrastructure in internal processes
Third Section
General Provisions for Technological Infrastructure
CHAPTER III
ON OPERATIONAL CONTINUITY
CHAPTER IV
COMMON PROVISIONS ON INFORMATION SECURITY AND OPERATIONAL CONTINUITY
CHAPTER V
ON THE CONTRACTING OF SERVICES WITH THIRD PARTIES AND COMMISSIONAIRES
CHAPTER VI
ON EVALUATION THROUGH INDEPENDENT THIRD PARTIES
CHAPTER VII
COMPLEMENTARY PROVISIONS
ANNEX 1
Information security indicators.
ANNEX 2
Minimum requirements to develop the Business Continuity Plan.
ANNEX 3
Incidents in matters of information security.
ANNEX 4
Information Security Incident Report.
ANNEX 5
Report on Operational Contingencies.
ANNEX 6
Characteristics of Independent Third Parties.
ANNEX 7
Technical requirements to carry out Operations through commissionaires.
ANNEX 8
Specifications of the information system developed by a third party for the encryption of
information shared with the National Banking and Securities Commission and the Bank of
Mexico.
CHAPTER I
GENERAL PROVISIONS
Article 1.- For the purposes of these Provisions, the following terms, in singular or plural, in addition to
those used in the Law for Regulating Financial Technology Institutions, shall be understood as:
Administrator of
Commissionaires:
the person who, in terms of Article 46 of these Provisions,
organizes a network of commissionaires and acts as an intermediary between them
and the electronic payment fund institution, so that said
commissionaires conduct Operations and services with Clients.
Authentication:
the verification of the identity of (i) a Client, in order to allow them to
carry out the Operations they require, or (ii) a User
of the Technological Infrastructure of the electronic payment fund
institution in question, in order for them to access, use
or operate any component of said Technological Infrastructure.
Instruction Channels:
equipment, electronic, optical or any other technology media,
automated data processing systems and networks of
telecommunications that are part of the Technological Infrastructure
of the electronic payment fund institution in question and that,
through them, this allows the Client to carry out Operations.
Encryption:
the mechanism that electronic payment fund institutions must use to protect the confidentiality of information through
cryptographic methods in which algorithms and encryption keys are used.
Cloud Computing:
the model of computing services provided by a third party, on
demand and on shared, private or hybrid infrastructure,
regardless of the physical location of the third party's Technological
Infrastructure, which may consist, among others, of one or more
of the following digital service schemes: infrastructure as a service, platform as a service or software as a service.
Operational Contingency:
any event that hinders, limits or prevents an electronic payment fund institution from carrying out its Operations, or those processes that could have an impact on its Clients or on the electronic payment fund institution itself.
Account:
that accounting record in which the electronic payment fund institution makes, among others, the entries of (a) credits corresponding to (i) the amount of electronic payment funds that it issues in favor of the Client in whose name said record has been opened, in accordance with Article 22, fraction I of the Law, against the receipt of an amount of money, in national currency, or subject to the authorization of the Bank of Mexico, in foreign currency, object of a Fund Transfer, Money Transmission, upon receipt of cash or operations with Card; (ii) the amount of electronic payment funds object of the Electronic Payment Fund Transfers that it receives in favor of said Client, as well as (b) charges corresponding to (i) the disposal of electronic payment funds due to their redemption, object of a Fund Transfer, payment operations with any type of disposal means that the electronic payment fund institution has allowed its client to carry out, direct debits, Money Transmission, or the delivery of cash; (ii) the amount of electronic payment funds object of the Electronic Payment Fund Transfers in question.
Information Security Event:
any event, internal or external, related, among others, to
Clients, third parties contracted by the electronic payment fund
institution, persons or operational processes, as well as with components
of the Technological Infrastructure, devices, physical media, or other
elements that store information, that constitutes some indication of the
possible impact on the confidentiality, integrity or availability of
the information that such institution manages or to which it has access
in the
own Technological Infrastructure.
Authentication Factor:
the mechanism of Authentication, based on the physical characteristics of
the Client, on devices or information that only the Client possesses or
knows, as provided in Article 5 of these
Provisions.
Client Identifier:
the alphanumeric character string, or the information of a
device, or any other information known by both the
electronic payment fund institution and the Client holding the respective
Account that it administers, which allows identifying them through the Instruction Channel of said electronic payment fund institution. Among others, the Client Identifier may be the mobile phone line number that the Client uses to access the Instruction Channels, the email address, the number of their Card or another unique identifier associated with the use of the corresponding Instruction Channel.
Information Security Incident:
any event, internal or external, related, among others, to
Clients, third parties contracted by the electronic payment fund
institution, persons and operational processes, as well as with components
of the Technological Infrastructure, devices, physical media or other
elements that store information, that:
a)
Compromises the confidentiality, integrity or availability of one
or more components of the Technological Infrastructure with an adverse effect on the electronic payment fund institution, its
Clients, third parties, providers or counterparties, among others.
b)
Violates the Technological Infrastructure in such a way that it compromises
the information it processes, stores or transmits.
c)
Constitutes a violation of the information security policies and procedures.
d)
Constitutes the materialization of a detriment to the institution of
electronic payment funds, whether by extraction, alteration or
loss of information; by failures derived from the use of
hardware, software, systems, applications, networks and any other
channel of information transmission; by unauthorized accesses
that result in the improper use of information or systems;
by fraud or theft; by an interruption of the activities carried out
by the institution itself caused by some action; or by
attacks against interconnected infrastructures known
as cyberattacks.
Personal Information:
the combination of name, surname and another element of information that
allows identifying the Client or the recipient of Transfers, such as
address, phone numbers or email addresses, among others.
Sensitive Information:
the combination of name, surname or another element of information that
allows identifying the Client or the recipient of Transfers, as well as the information of the Client Identifier, of the Accounts, of the respective Card numbers, of the information of previous Operations, as well as information that allows Authentication
and other data of a financial nature.
Administrative Body:
the sole administrator or the board of directors of an electronic payment fund institution, as the case may be.
Business Continuity Plan:
the document that integrates the set of strategies, procedures and
actions previously determined by the corresponding electronic payment fund
institution, to allow, upon the occurrence of
Operational Contingencies, the continuity in the Operations, activities
or in the performance of the critical processes of said electronic payment fund institution, or its timely restoration, as well as the
mitigation of the impacts resulting from said Operational
Contingencies.
Master Security Plan:
the document that integrates the set of projects determined by the
corresponding electronic payment fund institution, which must
be executed in the short, medium and long term, to establish a
correct management of information security and avoid that Security Events of Information materialize into Information Security Incidents.
Strategic Policy of
Business Continuity and
Information Security:
the document that integrates the strategies of the electronic payment fund
institution in matters of business continuity and information security related to its operation in accordance with these Provisions, without prejudice to any other element in matters of risk management subject to the general provisions that, to this effect, the CNBV issues in accordance with Article 48 of the Law for Regulating Financial Technology Institutions.
Session:
the period during which the Client, holder of an Account administered by the
electronic payment fund institution, can carry out balance inquiries or of their Operations carried out or initiate others, once they have entered the Instruction Channel with their Client Identifier.
Card:
the means of disposal of the electronic payment funds registered in
the Account in question, constituted as the set of data that, when
processed through determined systems, allow initiating a charge instruction to said Account, distinct from any other instruction that is made to execute a Transfer.
Independent Third Party:
the professional competent to carry out evaluation tasks on the
compliance with the requirements that electronic payment fund institutions must comply with in accordance with these Provisions, who is external to the electronic payment fund institution and who meets, insofar as applicable, the characteristics and requirements provided in Article 58 of these Provisions.
Transfer:
Fund Transfers, Electronic Payment Fund Transfers and Money Transmissions, interchangeably or jointly.
Fund Transfer:
that Operation referred to in Article 22, fraction III of the Law
for Regulating Financial Technology Institutions carried out between the
electronic payment fund institution in question and another
electronic payment fund institution, Financial Entity, foreign financial entity or foreign electronic payment fund institution, in accordance with which the first one makes (i) the credit in an Account for the equivalent amount of money to that indicated in the respective order it receives, derived from the charge that said other electronic payment fund institution or entity makes in the corresponding account, or (ii) the charge in an Account equivalent to that amount of money that the Client has indicated in the order they issue so that, once the redemption of the referred funds is carried out, said amount is credited in favor of the other electronic payment fund institution or entity to whom said order is sent for credit in the deposit account indicated in the order itself.
For the purposes of this definition, foreign electronic payment fund institutions shall be understood as legal entities located outside national territory that, in accordance with the applicable legislation in their respective jurisdiction, carry out activities similar to those of issuing, administering, redeeming, and transmitting instruments equivalent to electronic payment funds.
Electronic Payment Fund Transfer: That Operation referred to in Article 22, Section II of the Law for Regulating Financial Technology Institutions, carried out by the same electronic payment fund institution in accordance with the contracts entered into with its Clients for the opening of Accounts, under which said institution credits a determined amount of electronic payment funds into one of said Accounts, resulting from the charge of said amount in any other of those Accounts.
Money Transmission: That Operation referred to in Article 25, Section II of the Law for Regulating Financial Technology Institutions that is carried out by the authorized electronic payment fund institution.
UDI: The accounting units called "Investment Units" established in the "Decree establishing the obligations that may be denominated in Investment Units and reforming and adding various provisions of the Federal Tax Code and the Income Tax Law", published in the Official Gazette of the Federation on April 1, 1995, as it may be modified or added from time to time.
User of the Technological Infrastructure: The person or component of the Technological Infrastructure of the electronic payment fund institution, which has the respective authorization to access, use, or operate any component thereof. Clients of the electronic payment fund institution shall not be included in this definition.
CHAPTER II ON INFORMATION SECURITY
First Section On Technological Infrastructure vis-à-vis Clients
Section A On the execution of contracts through Instruction Channels and Operations through them
Article 2.- Electronic payment fund institutions, when agreeing on the execution of Operations and the provision of services through Instruction Channels, must require the express consent of their Clients for such purposes, which may be obtained through the Authentication process referred to in Article 7 of these Provisions. Additionally, electronic payment fund institutions must:
I. In the respective contracting, clearly and precisely establish the following:
a) The Operations and services that may be carried out and provided through said Instruction Channels.
b) The mechanisms and procedures for Client Authentication, as well as the responsibilities of the Client and the electronic payment fund institution regarding the execution of Operations and the provision of services through the respective Instruction Channel.
c) The mechanisms and procedures for notifying the Client of the Operations carried out and services provided by the electronic payment fund institutions through the Instruction Channels.
d) The mechanisms and procedures for cancelling the contracting of services, which must be similar to those of the contracting itself, considering the Client service channels, Client Identification Mechanisms, and procedures for their Authentication.
e) The operational restrictions applicable according to the Instruction Channel in question, in accordance with what is provided in this Chapter.
II. Inform their Clients, prior to contracting, of the terms and conditions for the use of the Instruction Channels, keeping such information available for consultation at all times.
III. Inform their Clients of the risks inherent to the use of the respective Instruction Channels, as well as make known to them suggestions to prevent the carrying out of unauthorized acts by them or any other irregular or illegal acts, through which Operations referred to the Accounts of which they are holders could be carried out.
Article 3.- Electronic payment fund institutions, regarding Instruction Channels, may:
I. Allow their Clients to contract additional Operations and services to those originally agreed upon.
II. Modify the terms and conditions for the provision of previously agreed services that may have a financial impact on their Clients, with their prior express consent, which may be obtained by said institutions through the Authentication process referred to in Article 7 of these Provisions, from the Instruction Channel in question.
III. Allow Clients to contract the use of another Instruction Channel, provided that the electronic payment fund institution requires, at least, one Authentication Factor for this purpose.
Article 4.- Electronic payment fund institutions must notify their respective Clients, through the means agreed upon with them and within a period not exceeding five seconds, when through Instruction Channels, any of the following Operations are executed or any of the following services are requested from the electronic payment fund institutions:
I. Transfers and delivery of money amounts resulting from the charge to the Client's Account in question, starting from when the accumulated daily amount of Operations carried out exceeds the equivalent in national currency to 60 UDI's, or when each individually exceeds the equivalent in national currency to 25 UDI's.
II. Registration or modification of the notification method to the Client, in which case the respective electronic payment fund institution must send the notification referred to in this article through the means previously agreed with the Client, as well as through the new means.
III. Contracting of another service provided through Instruction Channels.
IV. Deactivation, blocking, reactivation, and modification of Authentication Factors.
Electronic payment fund institutions must ensure that the notification sent pursuant to this article does not contain Personal Information or Sensitive Information of the Client. Notwithstanding, electronic payment fund institutions must enable mechanisms so that their Clients can, at their choice, receive information about the Account balance resulting from services provided through the Instruction Channels.
For the purposes of the notification referred to in this article, electronic payment fund institutions that issue disposition instruments must carry out said notification, both to their Clients and to the holders of the issued disposition instruments.
Electronic payment fund institutions may disable notifications when any of the Operations or services provided in Sections I to IV of this article are executed, upon express request of their Clients, which must be obtained by said institutions through the Authentication process referred to in Article 7 of these Provisions, and having previously informed their Clients of the risks associated with such disabling.
Section B On Authentication in Instruction Channels
Article 5.- For the purposes of these Provisions, the Authentication Factors that electronic payment fund institutions must use may only include information belonging to any of the following categories:
I. Information that the electronic payment fund institution provides to the Client or allows said Client to generate, under the understanding that only such person knows it, so that it can be entered into the system authorized by the electronic payment fund institution, in order to initiate a Session and execute the Operation in question. The Authentication Factors referred to in this section must comply with any of the following schemes:
a) Passwords that meet, at least, the following:
It must be composed of at least six consecutive characters and include alphanumeric characters.
Under no circumstances may the following information be used as passwords:
i) The Client Identifier.
ii) The name or commercial brand of the electronic payment fund institution.
iii) More than three identical characters in consecutive form.
iv) More than three numerical or alphabetic characters in sequential form.
b) Questionnaires carried out through electronic messaging channels, call centers, or automated agents, provided they observe the following:
Data that the Client knows and that electronic payment fund institutions can validate are required, maintaining due confidentiality of such information.
A set of open questions in questionnaires of at least three questions is defined, and in the event that the answer to one of them is incorrect, an additional question may be formulated. This set of questions must be unique per medium through which the questionnaire is presented, allowing the repetition of only one question among all mediums. Likewise, randomness mechanisms must be implemented in the presentation of questions to the Client.
Under no circumstances can the answers to these questions be data displayed on the Instruction Channel. Likewise, the information or data of the answer to two or more questions cannot be sent by electronic payment fund institutions to their Clients through the same communication channel, whether by printed or electronic means.
The answers provided by their Clients are validated through computer tools, without the operator or automated system being able to consult or access the Clients' Authentication data.
Electronic payment fund institutions will allow their Clients to change the Authentication Factors of this category, when the latter so require, under the terms provided in these Provisions.
Electronic payment fund institutions may use questionnaires to unlock Authentication Factors that have been previously blocked, provided they do so in combination with a second Authentication Factor different from the questionnaire.
II. Information contained, received, or generated by electronic means or devices that only the Client possesses, including that obtained by devices or applications generating dynamic passwords that the electronic payment fund institution provides to the Client, as well as that which allows associating electronic means or devices to a Client through secure mechanisms of credential or cryptographic key exchange. The foregoing shall be subject to the information being contained, received, or generated in said electronic devices that only the Client possesses and meeting the following characteristics:
a) Possess properties that prevent duplication or alteration.
b) Be dynamic information that cannot be used more than once with a validity that cannot exceed two minutes, or be dynamic information generated for the carrying out of an operation, as well as subsequent operations without any modification, in which case it will be considered, for the purposes of this subsection, as an independent element to authenticate the operations as authorized by the Client only for the first operation in which it is used.
c) Not be known prior to its generation and use by officials, employees, representatives of the electronic payment fund institution, or third parties.
Electronic payment fund institutions may provide their Clients with means or devices that generate one-time dynamic passwords using information from the Operation, by capturing data, so that such Password can only be used for the requested Operation. In this case, the validity set forth in subsection b) of this section shall not apply.
III. Information derived from the Client's own characteristics, such as those of a biometric nature, fingerprints, hand or face geometry, iris or retina patterns, and voice recognition, among others. For the use of this information, electronic payment fund institutions must have prior authorization from the CNBV and the Bank of Mexico.
In all cases, two or more Authentication Factors will be considered independent if the compromise of one of the Authentication Factors does not compromise the reliability of the others.
Article 6.- Electronic payment fund institutions may request authorization from the CNBV and the Bank of Mexico to use Authentication Factors referred to in Sections I and II of Article 5 of these Provisions with characteristics different from those indicated in said article, as well as the use of the information indicated in Section III of the mentioned article, provided they prove that the technology used, in the judgment of both Financial Authorities, is reliable for authenticating their Clients.
The request to obtain the authorization indicated in the preceding paragraph must contain the following:
I. The detailed description of the process, which must be approved by the Administrative Body, as well as the technology employed in each part of it.
II. The description of the means necessary for the transmission and safeguarding of the information that guarantee its integrity, correct reading of the data, impossibility of manipulation, as well as its adequate conservation and availability.
For the case prescribed in Section III of Article 5 of these Provisions, the electronic payment fund institution that formulates the authorization request referred to in this article must additionally present evidence collected from controlled tests demonstrating that the technological solution and methods used are effective for authenticating their Clients. Such evidence may be obtained by the electronic payment fund institution itself or by a company specialized in Authentication Factor certification with the capacity to present reports.
Electronic payment fund institutions must have mechanisms and procedures to ensure that, in the use of the Authentication Factors referred to in Section III of Article 5 of these Provisions, the information transmitted for the Authentication process is different each time it is generated, by incorporating additional information, such as timestamps, random numbers, and counters, among others, in the message encryption process, so that in no case can it be used again or duplicated.
Electronic payment fund institutions must present the authorization requests and other information referred to in this article to the Bank of Mexico and the CNBV, in accordance with what is established in Article 59 of these Provisions.
Article 7.- Electronic payment fund institutions, in order to allow access to Instruction Channels, must carry out Client Authentication. To carry out such Authentication, electronic payment fund institutions must collect and validate, at least, the following:
I. The Client Identifier
II. An Authentication Factor.
The Client Identifier must be unique for each Client and must be associated with all Operations carried out by the latter.
Likewise, electronic payment fund institutions must keep evidence of the Authentication, in accordance with what is established in Article 29, Section IV of these Provisions.
Article 8.- Electronic payment fund institutions must request, at least, two independent Authentication Factors on each occasion when the following is intended to be carried out:
I. Registration, cancellation, or any other modification related to the beneficiaries of the Account referred to in the seventh paragraph of Article 29 of the Law for Regulating Financial Technology Institutions.
II. Changes regarding Authentication Factors.
III. Request for account statements.
IV. Registration and modification of the notification method to the Client.
Electronic payment fund institutions shall be subject to what is established in Circular 12/2018 issued by the Bank of Mexico, in the case where they receive complaints from their Clients for unrecognized charges from Operations resulting from any of the operations described in Sections I, II, and IV of this article.
For the purposes of what is provided in this article, electronic payment fund institutions may take into account the Authentication Factor used for initiating a Session in the Instruction Channels in question.
Article 9.- Electronic payment fund institutions must have policies and procedures to ensure that, in the generation, delivery, storage, unlocking, and restoration of Authentication Factors, only the Client receives, activates, knows, unlocks, and restores them.
Regarding passwords defined or generated by electronic payment fund institutions during the restoration of Authentication Factors referred to in subsection a) of Section I of Article 5 of these Provisions, the institutions themselves must provide mechanisms and procedures through which the Client must modify them immediately after initiating the corresponding Session, when so required according to the type of Instruction Channel and prior to carrying out any Operation, validating that the Authentication Factors referred to in this paragraph are different from the passwords defined by the electronic payment fund institutions themselves.
Section C On information security requirements in Instruction Channels
Article 10.- Electronic payment fund institutions must establish mechanisms and procedures so that their Clients, upon accessing Instruction Channels, can recognize the institutions themselves, for which they must adhere to the following:
I. Provide personalized and sufficient information so that Clients can verify, before carrying out the Authentication procedure, that it is indeed the electronic payment fund institution of which they are a Client. For this purpose, electronic payment fund institutions may use the following information:
a) That which the respective Client knows or has provided to the electronic payment fund institution, or that which has been agreed with the electronic payment fund institution for this purpose, such as name, alias, and images, among others.
b) That which the respective Client can verify through a means agreed upon for this purpose with the electronic payment fund institution.
II. Once the Client accesses the Instruction Channel in question, the electronic payment fund institution must make available to them, at least, the following information:
a) Date and time of the last access to the Instruction Channel in question, and
b) Client's first and last name.
The foregoing shall not apply when the Client uses Instruction Channels that do not require prior interaction for the instruction of Operations, such as point-of-sale terminals.
Article 11.- Electronic payment fund institutions must provide for what is necessary so that, once the Client is authenticated in the Instruction Channel, the Session cannot be used by a third party. For the purposes of the foregoing, electronic payment fund institutions will establish, at least, the following mechanisms:
I. Terminate the Session immediately and automatically and inform the Client of the reason in any of the following cases:
a) When there is inactivity for more than 5 minutes.
b) When during a Session, the electronic payment fund institution identifies relevant changes in the communication parameters of said Session, such as identification of the Instruction Channel, range of communication protocol addresses, and geographic location, among others, that allow the institution itself to infer that it might be a Session theft.
II. Prevent simultaneous access in the same Instruction Channel, by using the same Client Identifier and making it known to the Client. Likewise, electronic payment fund institutions must detect attempts to access the Instruction Channel with incorrect Authentication Factors, and in case of exceeding three consecutive failed access attempts, access to the Instruction Channel in question must be temporarily restricted, blocking the Client's Authentication Factor for a period of ten minutes, notifying the Client about said blocking through the means previously agreed upon with them.
After the ten minutes indicated in the preceding paragraph have elapsed, the Client may have one more attempt to access the Instruction Channel, and in case an incorrect Authentication Factor is entered, said Authentication Factor will be blocked permanently until the Client carries out the unlocking process referred to in Article 9 of these Provisions.
The electronic payment fund institution must notify the Client of this permanent blocking, through the means agreed upon between the parties.
III. In the event that electronic payment fund institutions offer third-party services through links, they must communicate to their Clients that, upon entering said services, they will enter another link whose security does not depend on nor is the responsibility of said institution.
In the case where the electronic payment fund institution intends to establish parameters different from those established in this article, it must obtain prior authorization from the Bank of Mexico and the CNBV. Requests for such authorizations must be presented in accordance with Article 59 of these Provisions.
Article 12.- Electronic payment fund institutions, in the use of the Client Identifier and Authentication Factors, must comply with the following requirements:
I. Have the necessary mechanisms to prevent the reading or presentation on the Channel
Instructions, the information provided by the Client and used in the Identification and Authentication Mechanisms.
II. Ensure that, when at least two Authentication Factors are used, they are independent.
III. Have procedures to restore Authentication Factors, so that the Client's Personal Information or Sensitive Information is not compromised.
IV. Have procedures to invalidate Authentication Factors, in order to prevent their use in a service provided by the electronic payment fund institution, when a Client or the electronic payment fund institution itself cancels the use of said service or when the respective Client ceases to be a Client of said institution.
Article 13.- Electronic payment fund institutions may only store information related to the Authentication Factors used by their Clients in the Instruction Channels, when such storage is carried out under cryptographically secure protocols and it is not possible that:
I. The original information of the Authentication Factors is obtained from the stored information.
II. Different sets of data generate the same stored information.
Article 14.- Electronic payment fund institutions must establish procedures and mechanisms so that their Clients, who carry out Operations or request the services of these through Instruction Channels, can at all times temporarily deactivate the carrying out of said Operations or the provision of those services, as well as establish procedures to reactivate the use when the Clients request it.
Electronic payment fund institutions must allow Clients to temporarily deactivate the carrying out of the Operations and the provision of the services mentioned in the previous paragraph, through the Instruction Channels agreed upon for this purpose, requesting, at least, one Authentication Factor.
For the reactivation of the carrying out of Operations and the provision of services that electronic payment fund institutions provide through Instruction Channels, said institutions must allow Clients to use the Instruction Channels agreed upon for this purpose, for which they must require, at least, one Authentication Factor. Electronic payment fund institutions must observe what is stated in Article 7 of these Provisions, in order to allow access to the Instruction Channel in question once the service has been reactivated.
Second Section On Technological Infrastructure in Internal Processes
Article 15.- Electronic payment fund institutions, regarding components of communications and computing, must establish the following security aspects:
I. Logical, or logical and physical, segregation of different networks into different domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter and network security components that ensure that only authorized traffic is permitted. In particular, in those segments with links to the outside, such as the Internet, providers, authorities, other networks of the electronic payment fund institution or headquarters, and other third parties, all of this referring to those services defined as critical by the institution itself, related, at least with payment systems, Encryption equipment, or Operation authorizers, among others, they must consider safe zones, including those known as demilitarized zones (referred to as DMZ, by its initials in English).
II. Secure configuration according to the type of component considering, at least, ports and services, incoming and outgoing connections to other networks, including the Internet, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters. The principle of least privilege shall be understood as the enabling of access only to the information and resources necessary for the development of the functions proper to each User of the Technological Infrastructure.
III. Security mechanisms in applications that ensure that, during their execution, they are protected from attacks or intrusions, such as code injection, session manipulation, information leakage, and alteration of access privileges, among others. Such mechanisms must be implemented, both for applications provided by third parties, as well as for applications developed, implemented, and maintained by the electronic payment fund institution itself.
Article 16.- Electronic payment fund institutions must encrypt Personal Information and Sensitive Information received, generated, stored, or transmitted in the own or contracted third-party Technological Infrastructure, as well as images of identification documents issued by official authorities and biometric information of Clients, and any other that they determine according to their policies. In the case of Sensitive Information, encryption is exempted for information related to Operations, provided that such information is stored in tables or repositories distinct from those used to store the rest of the Personal Information and Sensitive Information, and there are security mechanisms that allow its dissociation and prevent access to said information, if not authorized to do so.
The mechanisms and procedures to decrypt the information referred to in this article, as well as the cryptographic keys required for such purpose, must be under the exclusive control of the Chief Information Security Officer of the respective electronic payment fund institution.
Article 17.- Electronic payment fund institutions must have procedures and mechanisms that allow structuring the Personal Information and Sensitive Information stored in the Technological Infrastructure, in such a way that the personal data of Clients cannot be related to the information related to their Operations, including, among others, the amounts, as well as the names or designations of the recipients or senders of payments made by Clients. This relationship can only be generated through computer procedures or applications for consultation, designed by the electronic payment fund institution, which must be executed on demand whenever it is necessary to build this relationship, either through manual mechanisms or computer systems.
Article 18.- Electronic payment fund institutions, regarding information related to Authentication Factors, must comply with the following requirements:
I. Maintain information security procedures for the custody, distribution, and assignment of their Clients' Authentication Factors.
II. Establish procedures and mechanisms so that information related to Authentication Factors is not known by any of their officials, employees, or representatives, or by any third party.
III. Establish procedures and mechanisms that prevent requesting from their Clients, through their officials, employees, representatives, or third parties, partial or complete information related to Authentication Factors.
Article 19.- Electronic payment fund institutions must establish procedures and mechanisms that ensure that, when discarding or decommissioning storage components or physical devices, known as hardware, of the Technological Infrastructure, the Client information contained in said components or devices is unrecoverable.
Article 20.- Electronic payment fund institutions are obliged to use tools that allow detecting computer viruses and malicious codes in the Technological Infrastructure, as well as procedures that allow their periodic update.
Article 21.- Electronic payment fund institutions must perform, prior to the start of their operation and at least every two months, vulnerability scanning tests of all components of the own Technological Infrastructure, or of third parties and commissioned agents contracted, in which they store, process, or transmit information of the electronic payment fund institutions and their Clients. Additionally, in case of modifications or updates in the Technological Infrastructure, electronic payment fund institutions must perform vulnerability scanning tests on the updated or modified components, before putting the mentioned modifications or updates into the production environment, having to take the necessary actions to remediate, at least, vulnerabilities classified as critical and high. The general manager or, in its case, the sole administrator, will be responsible for monitoring that such tests are carried out, either through the institution itself or a third party contracted for this purpose.
Electronic payment fund institutions must generate a documented remediation plan to address the vulnerabilities detected in the tests mentioned in the previous paragraph, in which their attention must be prioritized according to the criticality of said vulnerabilities, according to the classification made by the institution itself.
The remediation plans referred to in the previous paragraph must be validated by the Chief Information Security Officer. Likewise, said plans must contain, at least, the indication of the personnel responsible for their implementation and execution, detail of the defined activities, start and end dates of these, as well as the technical, material, and human resources required. The aforementioned remediation plans must be prepared within ten business days following the identification of the vulnerabilities and be available to the CNBV and the Bank of Mexico, when said authorities require them.
Article 22.- Electronic payment fund institutions must have procedures and mechanisms to prevent the installation of any service, application, or software, except those that:
I. Are necessary for the operation of the electronic payment fund institution.
II. Are authorized by the Chief Information Security Officer of the electronic payment fund institution, in each of the elements of its Technological Infrastructure.
Article 23.- Electronic payment fund institutions that have their own infrastructure for their operation and the safeguarding of information, must establish procedures and mechanisms to restrict access, both to physical connection ports and peripheral devices, as well as to computing or telecommunications infrastructure.
Likewise, when electronic payment fund institutions contract with a third party the infrastructure necessary for their operation and the safeguarding of information, they must ensure that said third party has the procedures and mechanisms referred to in the previous paragraph.
Article 24.- Electronic payment fund institutions must have access control procedures and mechanisms for the Technological Infrastructure that are robust and secure, for which they must comply, at least, with the following requirements:
I. Logical access controls to computing and telecommunications infrastructure, as well as their Technological Infrastructure and software infrastructure such as databases, operating systems, and software containers.
II. Controls for the management of Technological Infrastructure Users and passwords.
III. Controls that ensure the tracking and monitoring of access to the systems used for storing Client information, including automatic audits that allow the review of individual access to Client information, the actions performed after accessing such information, invalid access attempts, changes in Client Identification and Authentication for accessing Client data, as well as all changes made to the storage system.
In the case that the electronic payment fund institution intends to use any practice or standard different from those mentioned above, it must previously obtain authorization from the Bank of Mexico and the CNBV, for which it must present the respective request in accordance with what is established in Article 59 of these Provisions. The CNBV and the Bank of Mexico may publish on their Internet pages the standards that meet the aforementioned requirements.
Article 25.- Electronic payment fund institutions must establish information security policies that their personnel are obliged to observe, which include the correct use of resources used for storing Client data, the prior review of personnel profiles that the electronic payment fund institution intends to hire, as well as the risk assessment processes that are carried out at least once a year.
Third Section General Provisions for Technological Infrastructure
Article 26.- Electronic payment fund institutions must establish and document policies and mechanisms so that Instruction Channels only use those communication protocols that guarantee the confidentiality of information in point-to-point communication, based on the best practices and international standards of computer security in this matter that, prior agreement between the CNBV and the Bank of Mexico, are published, on their respective Internet sites. The encryption mechanisms implemented for said communication protocols must be valid, not have known vulnerabilities, and contemplate that the length of encryption keys is robust.
In case any electronic payment fund institution intends to use any practice or standard different from those mentioned above, it must previously obtain authorization from the Bank of Mexico and the CNBV. For these purposes, electronic payment fund institutions must present the requests referred to in this article, in accordance with what is established in Article 59 of these Provisions.
Article 27.- Electronic payment fund institutions must have validation measures to guarantee the authenticity of the processes executed by the different components of the Technological Infrastructure, including the Operations carried out by Clients, considering, at least, the following:
I. The verification of the truthfulness and integrity of the information regardless of whether it is static or in transit.
II. The Authentication between components of the Technological Infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.
III. The messaging, communication, and Encryption protocols, which must ensure the integrity and confidentiality of the information.
IV. The identification of atypical processes, anticipating that there are monitoring tools or automatic alert measures for their attention, by the corresponding operational areas.
V. The update and maintenance of digital certificates and components provided by service providers that are integrated into the execution processes.
The measures referred to in this article must be established in accordance with the degree of risk that electronic payment fund institutions define for each type of process.
Article 28.- Electronic payment fund institutions, for the implementation and development of their computer systems, whether by the institution itself or through a third party specialized in computer program development contracted by it, must comply with the following:
I. Document their processes, functionalities, and configurations, including their development or acquisition methodology, as well as the record of their changes, updates, and the detailed inventory of each component of the Technological Infrastructure. The development process must implement information security aspects, at least, in the following stages:
a) Elaboration of requirements.
b) Design of the computer system.
c) Development or acquisition of the computer system according to the design referred to in the previous letter b).
d) Validation of functionalities, purpose, capacity, and quality of the computer system.
e) Vulnerability tests and code analysis prior to their release.
f) Release or installation of the computer system.
g) Change control in the computer system.
h) Secure destruction of information at the end of the useful life of components or systems.
i) In case the software is developed by an external specialized company, the electronic payment fund institution must request that the delivered software contain mechanisms to validate its integrity and authenticity at the time of installing it in its Technological Infrastructure.
II. Computer systems must consider the following functionalities throughout their entire operation process:
a) Authentication mechanisms between the different components used for the operation of the electronic payment fund institution.
b) Use of electronic signatures to guarantee the integrity and non-repudiation of the operational information of the electronic payment fund institution, regardless of whether it is static information or in transit.
c) Management of Technological Infrastructure Users and their privileges.
d) Use of encrypted communications for the communication of the different computer systems and their components.
III. Review statically, at least through automated tools, the security of the computer system every time an update is performed on it.
Article 29.- Electronic payment fund institutions must maintain the robustness of their Technological Infrastructure, for which they must have:
I. Controls that allow reviewing, at least once a year, that the components that provide security to their Technological Infrastructure are valid and, in their case, update the components that are no longer so.
II. Procedures and tools for the detection of the alteration or falsification of the information contained in the Technological Infrastructure.
III. Records that allow monitoring, auditing, and tracking the accesses and activities performed by the different Users of the Technological Infrastructure of the computer systems, regardless of the level of privileges established for their access and the medium or protocol of access. These records must include, at least, the following information:
a) Date, hour, minute, and second of the activities performed by Technological Infrastructure Users.
b) Elements that allow identifying the Technological Infrastructure User who performs said activities.
c) Identification data of the access point used by the Technological Infrastructure User to perform the operation in question.
d) Internet protocol addresses or similar, according to the electronic medium used by the Technological Infrastructure User. The generated information must be stored securely for a minimum period of one hundred eighty natural days and contemplate mechanisms to prevent its alteration, as well as maintain internal control procedures for its access and availability.
IV. Records that allow monitoring, auditing, and tracking the accesses and activities performed by the different Clients. These records must include, at least, the following information:
a) Date, hour, minute, and second of the activities performed by Clients.
b) Account numbers involved in the Operation, including that Account belonging to the orderer of the Operation and, in its case, that of the recipients, and other information that allows identifying the Operations performed by Clients or those who have used the respective disposal medium.
c) Identification data of the Instruction Channel used by the Client or by whoever has used the respective disposal medium to perform the Operation in question, as well as the Authentication Factors used for its instruction.
d) Internet protocol addresses or similar, the telephone line number or other data, according to the Instruction Channel used by the Client or user of the disposal medium. The generated information must be stored securely for a minimum period of one hundred eighty natural days from its generation, through mechanisms previously determined to prevent its alteration, as well as maintain internal control procedures for its access and availability.
Such information must be provided to Clients or users of the disposal medium who expressly request it from the electronic payment fund institution through their Customer service channels, within a period that does not exceed ten business days, provided that it concerns Operations carried out in the Clients' own Accounts or users of the disposal medium during the one hundred eighty natural days prior to the request for the information in question.
V. Records that allow monitoring, auditing, and tracking all operations performed by computer systems, as well as blocking transmissions that do not meet the established security criteria. These records must include the following:
a) Date, hour, minute, and second of the activities performed by computer systems.
b) Identification data of the access point used by the computer system to perform the operation in question.
c) Internet protocol addresses or similar, according to the electronic medium used by the computer system. The generated information, including that of other media, must be stored securely for a minimum period of one hundred eighty natural days and contemplate mechanisms to prevent its alteration, as well as maintain internal control procedures for its access and availability.
Article 30.- Electronic payment fund institutions must have a Strategic Policy
of Business Continuity and Information Security, which must be approved by its Governing Body.
Article 31.- Electronic payment fund institutions must have a Master Security Plan, which must be approved by the General Manager or, in their absence, by the sole administrator.
The Master Security Plan must be aligned with the business strategy of the electronic payment fund institution and with what is established in the Strategic Policy on Business Continuity and Information Security, as well as define and prioritize projects in the matter of information security, with the objective of reducing exposure to technological risks and the materialization of Information Security Incidents to acceptable levels as defined by the Governing Body, based on an analysis of the current situation.
For the approval of the Master Security Plan, the General Manager or, where applicable, the sole administrator must verify that it contains initiatives aimed at improving existing work methods and contemplates the required controls in accordance with applicable provisions. Modifications to the Master Security Plan must be approved by the General Manager or, where applicable, by the sole administrator.
In the case of electronic payment fund institutions that have a General Manager and a Board of Directors, the former must inform the Board of the content and modifications to the Master Security Plan, and must have evidence of its approval and implementation.
Article 32.- Electronic payment fund institutions must implement procedures and mechanisms that must be followed for the handling of Information Security Incidents in their Technological Infrastructure, which must include the identification, containment, and adequate collection and safeguarding of evidence of such incidents.
Article 33.- Electronic payment fund institutions must evaluate or audit, at least once a year, the computer security of the Technological Infrastructure. Additionally, among the work of said evaluation or audit, electronic payment fund institutions must present to the Governing Body, within the referred period, the following documents:
I.
Report specifying the computer risk level for the Technological Infrastructure.
II.
Remediation Plan to address observations classified with high and very high criticality, found in said evaluation or audit.
III.
Evidence of the implementation of remediation measures in accordance with the plan indicated in fraction II of this article.
IV.
Evidence of the mitigation of the referred observations in accordance with the plan mentioned in fraction II of this article.
Electronic payment fund institutions, prior to the start of operations, must carry out the evaluation or audit referred to in the previous paragraph, on those elements or components of the Technological Infrastructure, whether own or of contracted third parties, used to carry out the issuance, administration, redemption, or transmission of electronic payment funds, including the services they provide to their Clients to carry out said activities, as well as the storage of Personal Information and Sensitive Information.
For the purposes of what is established in the first and second paragraphs of this article, electronic payment fund institutions that use Technological Infrastructure of third parties must have, from these, the following documents:
I.
Results of the evaluation or audit carried out at least once a year and prior to the start of operations to said third parties.
II.
Remediation Plan to address observations classified with high and very high criticality, found in the evaluation or audit referred to in the previous fraction I.
III.
Evidence of the implementation of the remediation plan and of the mitigation of the observations mentioned in the preceding fraction II.
Electronic payment fund institutions must present to the Governing Body what is referred to in the previous fractions.
The documents referred to in this article must be available for consultation by the Bank of Mexico and the CNBV, when said Financial Authorities so require and, in this case, must be sent in accordance with what is established in Article 59 of these Provisions.
Article 34.- Electronic payment fund institutions must hire a legal entity, with personnel who have verifiable technical capacity through industry certifications in the matter, so that, at least, every two years, penetration tests are carried out in the different systems and applications of the Technological Infrastructure, with the purpose of detecting errors, vulnerabilities, unauthorized functionality, or any code that puts or may put at risk the information and assets of the Clients and of the electronic payment fund institution itself.
The electronic payment fund institution must send to the Bank of Mexico and to the CNBV, within twenty business days, counted from the date on which the corresponding tests have ended, a report with the conclusions of said tests, in accordance with what is established in Article 59 of these Provisions. The report must be digitally signed by the General Manager or, where applicable, by the sole administrator, and must be encrypted in accordance with what is provided in Article 59 of these Provisions.
In the event that, from the penetration tests carried out, observations of high or very high criticality arise, the electronic payment fund institution in question must present a documented remediation plan to correct said observations, to the Bank of Mexico and to the CNBV, within a period not greater than 20 business days after the end of the penetration tests. The remediation plan must be digitally signed by the General Manager or, where applicable, by the sole administrator, and encrypted in accordance with what is provided in Article 59 of these Provisions. The CNBV and the Bank of Mexico may make observations to said remediation plan, at any time.
Once the remediation activities of the observations of high or very high criticality referred to in the previous paragraph are concluded, the electronic payment fund institution must carry out again, within a period not greater than two months after the date of conclusion of said activities, penetration tests to verify that the respective vulnerabilities have been mitigated.
Electronic payment fund institutions must document in manuals the methodologies used to classify the criticality and risk of the findings of the information security tests, including those of penetration and vulnerabilities.
Article 35.- Electronic payment fund institutions must have a person who, among their functions, serves as Chief Information Security Officer, known as CISO by its English acronym for Chief Information Security Officer. Said functions may be performed by a third party, provided that it complies with what is stated in this article.
The Chief Information Security Officer must be designated by the General Manager or, where applicable, by the sole administrator, and must not have conflicts of interest with respect to the person responsible for the functions of audit and information technologies of the electronic payment fund institution. Likewise, they cannot perform functions related to the operation of the information security of the electronic payment fund institution itself.
The Chief Information Security Officer may support, in the exercise of their functions, representatives from the different business units.
Electronic payment fund institutions may designate the General Manager or, where applicable, the sole administrator as Chief Information Security Officer, for a maximum period of twelve months counted from the date on which they obtain authorization to act as electronic payment fund institutions.
Article 36.- The Chief Information Security Officer of the electronic payment fund institution must, at least:
I.
Participate in the definition and verify the implementation and continuous compliance of the information security policies and procedures indicated in these Provisions.
II.
Prepare the Master Security Plan, which must contain, for each project defined, the name of the project, objective, scope, start and end dates, involved areas, and projected investment. The plan referred to in this fraction must be reviewed and updated, at least annually.
III.
Verify, at least annually, the definition of access profiles to the Technological Infrastructure of the electronic payment fund institution, whether own or provided by third parties, in accordance with job profiles, known as functional segregation, including those with high privileges, such as administration of operating systems, databases, and applications.
IV.
Ensure, at least annually or earlier in case an Information Security Incident occurs, the correct assignment of access profiles to Users of the Technological Infrastructure. The function referred to in this fraction may be carried out through representative and random samples.
Likewise, the Chief Information Security Officer will be responsible for the temporary authorization of accesses by exception, such as those of Users of the Technological Infrastructure of development environments with access to production environments, accesses due to contingency events, or any other privileged access that does not correspond with the policy determined by the electronic payment fund institution. Likewise, they must have a record containing the name of the Technological Infrastructure User, associated application, environment, reason for the exception, and start and end date of the assignment.
V.
Approve and verify compliance with the measures that have been adopted to correct deficiencies detected as a result of the functions referred to in fractions III and IV of this article, as well as the findings, both of internal and external audit related to the Technological Infrastructure and information security.
VI.
Manage information security alerts communicated by the CNBV or other means, as well as Information Security Incidents, considering the stages of identification, protection, detection, response, and recovery.
VII.
Preside over the team that is formed for the detection and response to Information Security Incidents in the electronic payment fund institution.
VIII.
Inform the Governing Body, or the audit committee and the risk committee in case they exist, in the immediate next session, as applicable, after the verification of the Information Security Incident, regarding the actions taken and the follow-up to measures to prevent or avoid the recurrence of said incidents.
IX.
Verify that annual training programs directed to all personnel are implemented, as well as awareness programs in the matter of information security towards Clients, including, where applicable, third parties that provide them with services, in which aspects such as the roles and responsibilities that Technological Infrastructure Users have in this regard are contemplated.
X.
Present monthly to the General Manager or, where applicable, to the sole administrator, the management report in the matter of information security. This report must be made to the audit committee and the risk committee or, in the absence of these, to the Board of Directors of the electronic payment fund institution, in its immediate next session.
XI.
Consider, at least, the risk indicators in the matter of information security established in Annex 1 of these Provisions, and inform the result of the evaluation of said indicators to the Governing Body, and where applicable, to the audit committee or risk committee.
XII.
Respond to the requirements formulated by the Bank of Mexico and the CNBV and within the electronic payment fund institution, in the matter of information security.
Electronic payment fund institutions must ensure that the Chief Information Security Officer has at their disposal the records of persons who have access to information related to the operations in which the electronic payment fund institution itself intervenes, including those located abroad, as well as of the Technological Infrastructure Users who have high privileges, such as administration of operating systems, databases, and applications, as well as of their service providers.
Electronic payment fund institutions that belong to a financial group subject to the supervision of the CNBV, or that are part of Consortia or Business Groups that have a financial entity subject to the supervision of the CNBV itself, may assign the functions of the Chief Information Security Officer to the person who performs said activities in the financial entity supervised by the CNBV, provided that said person complies with what is established in Article 35 of these Provisions.
CHAPTER III
ON OPERATIONAL CONTINUITY
Article 37.- Electronic payment fund institutions must have a Business Continuity Plan that they are obliged to comply with and include the minimum requirements established in Annex 2 of these Provisions, which must be aligned with the Strategic Policy on Business Continuity and Information Security.
The Business Continuity Plan must be approved by the General Manager or, where applicable, by the sole administrator, verifying that it contains initiatives aimed at improving existing work methods, in accordance with these Provisions. Modifications to the Business Continuity Plan must be approved by the General Manager or, where applicable, by the sole administrator, with the General Manager being responsible for adhering to the principles established by the Board of Directors in the business continuity and information security manual.
In the case of electronic payment fund institutions that have a General Manager and a Board of Directors, the former must inform the Board of the content of the Business Continuity Plan, or its modifications, and have evidence of its approval and implementation.
Article 38.- Each electronic payment fund institution must have the necessary mechanisms for operational continuity and the administration of Operational Contingencies of the institution itself, which include their identification, evaluation, monitoring, and mitigation.
Article 39.- Electronic payment fund institutions must have methodologies to estimate the quantitative and qualitative impacts of possible Operational Contingencies that, in terms of these Provisions, the person responsible for the administration of Operational Contingencies determines for their use in the analysis referred to in Annex 2 of these Provisions. The Governing Body of each electronic payment fund institution must approve said methodologies, without prejudice to the powers of the General Manager to make modifications to the Business Continuity Plan, in accordance with the principles established by the respective Governing Body in the Strategic Policy on Business Continuity and Information Security.
Article 40.- The Governing Body of the electronic payment fund institution must designate a person responsible for the administration of Operational Contingencies, who has knowledge in the matter and who may be the same person who is designated as integral risk administrator in accordance with the general provisions issued by the CNBV. The person responsible for the administration of Operational Contingencies may be assisted by other areas of the electronic payment fund institution itself or by contracted third parties for this purpose, who are specialists in the matter. This person must have, at a minimum, the following functions:
I.
Prepare, review, and, where applicable, update the Business Continuity Plan.
II.
Evaluate, at least once a year, the scope and effectiveness, as well as the compliance with the minimum requirements established in Annex 2 of these Provisions, as well as of the established Business Continuity Plan, and inform the results of said evaluation to the Governing Body and to the areas responsible for critical operational processes, identifying, where applicable, the necessary adjustments for its update, strengthening, and compliance. In the event that the electronic payment fund institution has an audit committee, the functions provided for in this fraction will be carried out by said committee.
III.
Coordinate and verify the execution of tests of the functioning and sufficiency of the Business Continuity Plan and inform the Governing Body, at least once a year, about the results of said tests.
IV.
Define and present to the Governing Body, the methodology for the administration of Operational Contingencies, in the terms established in the provisions corresponding to the administration of operational events. For the purposes of the foregoing, the person responsible for the administration of operational events may be assisted by other areas of the electronic payment fund institution itself or by contracted third parties for this purpose, who are specialists in the matter.
V.
Define and present for approval by the Governing Body, the methodologies to estimate the quantitative and qualitative impacts of Operational Contingencies. For the purposes of the foregoing, the person responsible for the administration of Operational Contingencies may be assisted by other areas of the electronic payment fund institution itself or by contracted third parties for this purpose who are specialists in the matter.
VI.
Verify the effectiveness of the methodology to estimate the quantitative and qualitative impacts of possible Operational Contingencies, at least once a year and, where applicable, correct said methodology within the same period. Likewise, compare its estimates against the Operational Contingencies effectively observed and, if applicable, carry out the necessary corrections.
In the event that electronic payment fund institutions contract with third parties the services necessary to support their operation, in substitution of what is provided in fractions II and III of this article, and solely with respect to the services provided by said third parties, the institutions must have documentation that accredits that such third parties have a valid certification issued in accordance with international standards regarding their capacity to maintain the continuity of their services. The foregoing must be observed without prejudice to compliance with what is provided in Chapter V of these Provisions.
CHAPTER IV
COMMON PROVISIONS ON INFORMATION SECURITY AND OPERATIONAL CONTINUITY
Article 41.- Electronic payment fund institutions must keep a record in databases of Information Security Events classified as relevant, Information Security Incidents, Operational Contingencies, as well as failures or vulnerabilities detected in the Technological Infrastructure, which includes, as appropriate, information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out, as well as loss, extraction, alteration, loss, or misuse of information of the Technological Infrastructure Users or of the Clients, where the date of the event and a brief description of it, its duration, service or the element of the Technological Infrastructure affected, affected Clients and amounts, as well as the corrective measures implemented are contemplated.
The information of Information Security Events classified as relevant and Information Security Incidents, as well as Operational Contingencies, must be backed up in the media that electronic payment fund institutions determine and be preserved for, at least, ten years.
Article 42.- In the event that an Information Security Incident occurs, or an Information Security Event in the components of the Technological Infrastructure of the electronic payment fund institution; in the Instruction Channels, or in the technological infrastructure of any third party that affects the operation or the Technological Infrastructure of the electronic payment fund institution, the General Manager or, where applicable, the sole administrator must carry out the following:
I.
Provide for what is necessary to make known to the Bank of Mexico and to the CNBV, in an immediate manner, the Information Security Incidents, by email sent to the accounts ifpe@banxico.org.mx and Ciberseguridad-CNBV@cnbv.gob.mx, or through other means that the Bank of Mexico or the CNBV itself indicate. In said notification, at least the date and time of start of the Information Security Incident in question must be indicated, and, where applicable, the indication of whether it continues or has concluded and its duration; a description of said event or incident, as well as an initial evaluation of the impact or gravity.
Additionally, electronic payment fund institutions must send to the accounts ifpe@banxico.org.mx and Ciberseguridad-CNBV@cnbv.gob.mx, or through other means that the Bank of Mexico or the CNBV itself indicate, within five business days following the identification of the Information Security Incident in question, the information determined in Annexes 3 and 4 of these Provisions.
In the case of Information Security Events, they must be reported through the means indicated in the first paragraph of this fraction only those that, according to the policies and procedures established by the electronic payment fund institution itself, are classified
as relevant due to their potential impact on the electronic payment fund institution, its Clients, counterparties, suppliers, or other entities in the financial system, as well as those related to Personal Information or Sensitive Information, images of official identification documents, and information regarding the Authentication Factors referred to in Section III of Article 5 of these Provisions. This report shall only contain the date and time of commencement, as well as a description of the event in question.
II.
Conduct an immediate investigation into the causes that generated the Information Security Incident and establish a work plan that describes the actions to be implemented to eliminate or mitigate the vulnerabilities that facilitated the aforementioned incident. Such plan shall indicate, at least, the personnel responsible for its design, implementation, execution, and monitoring; deadlines for its execution, as well as the technical, material, and human resources; and shall be sent to the Bank of Mexico and to the CNBV within a period not exceeding fifteen business days following the conclusion of the Information Security Incident.
III.
When the Information Security Incident consists of Personal Information or Sensitive Information under the custody of the electronic payment fund institution or third parties providing services to it, being extracted, lost, deleted, altered, or if the electronic payment fund institutions suspect the occurrence of any act involving unauthorized access to such information, the General Manager or, where applicable, the sole administrator or the person designated by either of them, shall notify the Clients of the possible loss, extraction, alteration, loss, or unauthorized access to their information, within the following twenty-four hours after the Information Security Incident occurred or after knowledge thereof was obtained, through the notification means designated by the Client for such purpose, in order to prevent them from the risks derived from the misuse of information that has been extracted, lost, deleted, or altered. Likewise, the Client shall be informed of the measures they must take and, where applicable, the replacement of the corresponding disposal instruments or the substitution of necessary Authentication Factors shall be effected.
The notification referred to in this section shall include, at least, the nature of the event, its date and time of commencement, duration, and, if applicable, delimit and indicate the individual impacts on each Client. The evidence of this notification shall be included in the result of the investigation referred to in Section II of this Article.
Article 43.- Electronic payment fund institutions shall inform the Bank of Mexico and the CNBV of Operational Contingencies that occur in any of the public service channels or within the electronic payment fund institution itself, via email sent to the accounts ifpe@banxico.org.mx, contingencias@cnbv.gob.mx, and supervisionfintech@cnbv.gob.mx, or through other means made available by the Bank of Mexico or the CNBV, and an electronic receipt must be generated. This applies provided that these interruptions last at least thirty minutes.
The notification referred to in the preceding paragraph shall be made within sixty minutes following the occurrence of the Operational Contingency in question, and must include the date and time of commencement of the Operational Contingency; an indication of whether it continues or has concluded and its duration; the processes, systems, and channels affected; a description of the event that has been registered; and an initial assessment of the impact or severity.
Likewise, in the event that an Operational Contingency occurs, the electronic payment fund institution in question shall conduct an immediate investigation into the causes that generated the event, and send the results of said investigation to the Bank of Mexico and to the CNBV, within a period not exceeding five business days in accordance with the specifications of Annex 5 of these Provisions.
On the other hand, in the event that, as a result of an Operational Contingency, one or more Instruction Channels are affected, the electronic payment fund institution in question shall inform its Clients or users regarding the disposal instrument being affected by this, within a period not exceeding five seconds counted from the occurrence of the Operational Contingency and in accordance with the information available at that time, regarding the intermittency or impossibility of using the Instruction Channels, through the notification means agreed upon with the respective Clients or users, and shall maintain evidence thereof.
In addition to what is provided in the preceding paragraph, the electronic payment fund institution shall make available to the general public, on the Internet site previously made known to its Clients, the information related to the Operational Contingency in question, including, at least, the nature of the event, its date and time of commencement and duration, as well as a general description of the impacts its Clients had, within a maximum period of sixty minutes counted from the occurrence of the event, and, if applicable, shall delimit and indicate the individual impacts on each Client or user of the disposal instrument, which it shall make known to its Clients through the means previously agreed upon for this purpose, within a maximum period of twenty-four hours, counted from the occurrence of the event.
Where applicable, the General Manager or sole administrator shall be responsible for carrying out what is provided in this Article.
CHAPTER V
ON THE CONTRACTING OF SERVICES WITH THIRD PARTIES AND COMMISSION AGENTS
Article 44.- Electronic payment fund institutions require authorization from the Bank of Mexico and the CNBV to contract the provision of services with any third party that meets any of the following characteristics:
I.
Provides services that imply the transmission, storage, processing, safeguarding, or custody of Personal Information or Sensitive Information, images of identification documents issued by official authorities, or biometric information of Clients, provided that the third party in question has access privileges to know such information or security configuration information, or to access control administration.
II.
Carries out processes abroad related to accounting or treasury.
III.
Acts as the primary provider of those services whose partial or permanent interruption would prevent the electronic payment fund institution from issuing, administering, redeeming, or transmitting electronic payment funds, in accordance with the acts referred to in Sections II, III, IV, and V of Article 22 of the Law for Regulating Financial Technology Institutions.
Electronic payment fund institutions may only contract the services referred to in the preceding sections, as well as any others, when the persons providing the respective services are obligated to maintain the due confidentiality of information regarding Operations conducted with their Clients, as well as regarding the Clients themselves, in case of having access to it, at least under the same terms and conditions in which the electronic payment fund institutions are obligated to maintain such confidentiality. In all cases, electronic payment fund institutions shall be responsible for violations of the confidentiality of information under their safeguard or in custody of the referred third parties.
The General Manager or, where applicable, the sole administrator of the electronic payment fund institution shall be responsible for approving the contracting of service providers referred to in this Chapter.
Electronic payment fund institutions shall maintain the data of those who provide them services, in the registry referred to in Article 52 of these Provisions.
The authorization referred to in this Article shall not be necessary when electronic payment fund institutions contract other financial entities subject to general provisions substantially similar to these Provisions.
Article 45.- Electronic payment fund institutions shall present to the Bank of Mexico and the CNBV a notice twenty business days in advance of contracting third parties, when such third party:
I.
Acts as a secondary or backup provider to complement the operation of a primary provider or to guarantee business continuity in the event that the primary provider is not in a position to provide the service, as well as for those services whose partial or permanent interruption would prevent the electronic payment fund institution from issuing, administering, redeeming, or transmitting electronic payment funds, in accordance with the acts referred to in Sections II, III, IV, and V of Article 22 of the Law, in which case the referred notice shall comply with the requirements referred to in Article 49 of these Provisions.
II.
Corresponds to a legally authorized financial entity subject to regulation substantially similar to that provided in these Provisions, in the federal sphere, in financial matters.
The Bank of Mexico and the CNBV, during the aforementioned twenty-business-day period, may require the electronic payment fund institution in question that the provision of said service not be carried out through the third party indicated in the notice referred to in this Article, when either of the two authorities considers that, due to the terms and conditions of service contracting, internal control policies and procedures, or due to the technological or communications infrastructure subject to the service used by said third party, it will not be in a position to comply with the provisions applicable to the electronic payment fund institution and, where applicable, the financial stability or operational continuity of the institution itself may be affected, at the discretion of the Bank of Mexico or the CNBV.
Article 46.- Electronic payment fund institutions may enter into commercial commission contracts with third parties who act in front of the general public in the name and on behalf of the respective electronic payment fund institutions, solely for the performance of the following Operations:
I.
Cash withdrawals made by the respective Client, holder of the account.
II.
Receipt of cash for credit to own accounts or third-party accounts.
III.
Balance and account movement inquiries.
IV.
Circulation of instruments for the disposal of electronic payment funds.
V.
Opening of electronic payment fund accounts, observing at all times what is established in the general provisions referred to in Article 58 of the Law for Regulating Financial Technology Institutions, issued by the Secretariat, or those that replace them.
VI.
Transfers charged to electronic payment fund accounts, including service payments.
For the purposes of this Article, electronic payment fund institutions shall request authorization from the CNBV, in accordance with what is established in Article 59 of these Provisions.
The operations provided for in the preceding sections shall be carried out in national currency and in the name and on behalf of the electronic payment fund institution. In the event that the electronic payment fund institution intends to carry out operations other than those indicated through commission agents, it shall request authorization from the CNBV prior to their execution, in accordance with what is established in Article 59 of these Provisions.
Regarding those electronic payment fund institutions that carry out the operations indicated in Sections I and II of this Article, through a credit institution, they are exempt from presenting the authorization request referred to in the preceding paragraph. Additionally, electronic payment fund institutions shall observe, at all times, the limits established in Article 9 of the General Provisions applicable to Financial Technology Institutions issued by the CNBV or those that replace them, and establish in the compliance manual provided for in the General Provisions referred to in Article 58 of the Law for Regulating Financial Technology Institutions issued by the Secretariat, or those that replace them, monitoring mechanisms to comply with the aforementioned limits.
Electronic payment fund institutions, in the celebration of the contracts referred to in this Article, shall ensure at all times that the third parties providing them services maintain the due confidentiality of information regarding Operations conducted with their Clients, as well as regarding the Clients themselves, in case of having access to it.
The General Manager or, where applicable, the sole administrator of the electronic payment fund institution shall be responsible for approving the contracting of commission agents.
Article 47.- Electronic payment fund institutions that intend to enter into the commercial commission contracts referred to in the previous Article shall present in the authorization request the following:
I.
General functioning plan containing the following:
a)
Detailed description and flowchart of the processes of each of the operations to be contracted, considering, where applicable, the reconciliation and settlement process of each of them, the third parties involved, and the Technological Infrastructure to be used in the Operation in question.
b)
Mechanisms that include the automated controls that the electronic payment fund institution will use to prevent commission agents or the Commission Agent Administrator from exceeding the operation limits established in Article 48 of these Provisions.
c)
Monitoring mechanisms for the performance of the commission agent or the Commission Agent Administrator, which shall consider, at least, the compliance with their contractual obligations.
For the purposes of the foregoing, the electronic payment fund institution shall have plans to evaluate and report to the Administrative Body or, where applicable, to the audit committee, the performance of the contracted commission agents or the Commission Agent Administrator and the compliance with the applicable regulation related to such contracting.
d)
Technical requirements to carry out operations through commission agents, adhering to what is indicated in Annex 7 of these Provisions.
Electronic payment fund institutions, for the execution of operations additional to those manifested in the general functioning plan referred to in this section, shall request authorization from the CNBV, within a period not exceeding twenty business days prior to the start of the execution of said operations. Likewise, when they carry out reforms to said plan that imply substantial changes in the terms under which they would carry out Operations with Clients or users of the disposal instrument, they shall request authorization from the CNBV, at least twenty business days in advance of the date on which they intend to take effect.
II.
Draft contract in which the probable date of its celebration and the rights and obligations of the electronic payment fund institution and the commission agent or the Commission Agent Administrator shall be indicated. Likewise, within the contract, the following shall be provided:
a)
Operations that the commission agent or the Commission Agent Administrator will carry out in the name and on behalf of the electronic payment fund institution.
Regarding Operations carried out through Commission Agent Administrators, electronic payment fund institutions shall provide in the contract the Operations that the Commission Agent Administrator will contract in the name and on behalf of the electronic payment fund institution with the Commission Agents that it will administer, as well as, where applicable, the Operations and services that the Commission Agent Administrator itself will carry out.
b)
Limits that will apply to each of the Operations, in accordance with applicable provisions.
c)
Rights and obligations that will have, both the electronic payment fund institution, as well as the commission agent or the Commission Agent Administrator, as well as the respective legal consequences and sanctions applicable in case of non-compliance with the terms of the contract.
d)
Authority of the electronic payment fund institution to suspend the execution of operations or to terminate the respective contract, both without liability, in case the commission agent or the Commission Agent Administrator fails to comply with applicable regulations or the contract, or presents changes in their operation that affect the conditions of the contracted service.
e)
Corrective measures that the electronic payment fund institution would implement due to the non-compliance of the commission agent or the Commission Agent Administrator with applicable provisions.
f)
Prohibition for the commission agent or Commission Agent Administrator of:
Conditioning the execution of the operation to the acquisition of a product or service.
Advertising or promoting themselves in any form through stationery or on the front of receipts provided to Clients in the name of the electronic payment fund institution in question.
Carrying out the Operations subject to the commission on terms different from those agreed with the corresponding electronic payment fund institution.
Subcontracting the commercial commission. What is provided in this section shall not be applicable to the Commission Agent Administrator in the contracting in the name and on behalf of the electronic payment fund institution of the commission agents that it will administer, except for what refers to those operations and services that the Commission Agent Administrator itself will carry out.
Charging commissions, for their own account, to Clients for the provision of services subject to the commercial commission, or receiving price or rate differentials regarding the operations in which they intervene.
Carrying out Operations with Clients in their own name.
Exclusively agreeing with the electronic payment fund institution, the execution of Operations and activities consisting of the receipt of service payments charged to electronic payment fund accounts.
g)
Record, within the contract, of the express acceptance by the commission agent or Commission Agent Administrator of the following obligations:
Adherence to what is provided in Article 54 of the Law for Regulating Financial Technology Institutions.
Deliver, during the development of the audit and at the request of the electronic payment fund institution, to the independent external auditor of the electronic payment fund institution itself and to the CNBV, the books, systems, records, manuals, and documents in general, related to the provision of the service in question, as well as allowing the independent external auditor or CNBV personnel access to their offices and facilities in general, related to the provision of the service in question.
Inform the electronic payment fund institution regarding any modification to its corporate object or any other change that could affect the operations subject to the contracting, at least thirty days in advance of when such modification or change occurs.
Maintain confidentiality regarding information that has been received, transmitted, processed, or stored during the execution of the operations. Likewise, accept that such information may only be used and exploited for the purposes agreed upon in the contract.
Manifest acceptance of direct responsibility for the improper use of the electronic payment fund institution's information and, where applicable, pay indemnifications for damages and losses caused by any non-compliance with the aforementioned numeral.
Comply with the terms, conditions, and processes to guarantee the electronic payment fund institution the transfer, return, and secure deletion of information subject to the contracted commission when the contract is terminated.
Prevent the improper use of the Authentication Factors of Clients and employees who operate the contracted service.
Observe the measures that the electronic payment fund institution must implement to adhere to the general provisions referred to in Article 58 of the Law for Regulating Financial Technology Institutions, issued by the Secretariat, or those that replace them.
Train personnel regarding the process to carry out Operations, the use of the commission agent's technological infrastructure, and information security.
Electronic payment fund institutions shall present to the CNBV the authorization request referred to in this Article, in accordance with Article 59 of these Provisions, with an advance of at least twenty business days from the date on which they intend to carry out the contracting.
Electronic payment fund institutions may authorize third parties, through a mandate or commission, to contract on their behalf with other persons in the name and on behalf of the institution itself, the commissions or services referred to in this Article, such representatives being designated, for the purposes of these provisions, as Commission Agent Administrators.
In this case, electronic payment fund institutions shall establish that it shall be the responsibility of the Commission Agent Administrators to ensure that the commission agents they contract comply with what is established in this Article and in Annex 7 of these Provisions.
What is provided in this Article shall be observed without prejudice to the authorization that the electronic payment fund institution may obtain for its own Commission Agent Administrator to also be a commission agent.
Article 48.- Electronic payment fund institutions, in the execution of the Operations through commission agents referred to in Sections I and II of Article 46 of these Provisions, shall
subject to the following limits:
I.
With respect to the Operations referred to in fraction I of article 46, the limit per commissionaire shall not exceed a daily amount equivalent in national currency to 1,500 UDIs, per Client Account.
II.
With respect to the Operations referred to in fraction II of article 46, the limit per commissionaire shall not exceed a daily amount equivalent in national currency to 4,000 UDIs, per Client Account.
Article 49.- Electronic payment fund institutions must accompany the authorization request referred to in article 44 or, as applicable, the notice referred to in fraction I of article 45 of these Provisions, with the following:
I.
Detailed description and flowcharts of the processes for the services to be contracted, considering the activities to be carried out by the electronic payment fund institution, as well as by the service provider; the areas of the electronic payment fund institution and the third party that participate in the service flow; name, description, and functionality of the systems that, as applicable, will be contracted for the provision of the service, or the systems of the electronic payment fund institution that will be used by the respective provider.
II.
Draft service provision contract, in which the contemplated date of its celebration, the rights and obligations of the electronic payment fund institution and the third party must be stated, including the determination regarding intellectual property rights concerning the designs, developments, or processes used for the provision of the service. Such draft contract must be presented in the Spanish language.
Likewise, the contract must record the express acceptance by the third party of the following obligations:
a)
To adhere to what is provided in article 54 of the Law for Regulating Financial Technology Institutions.
b)
To deliver, during the development of the audit and at the request of the electronic payment fund institution, to the Independent Third Party of the electronic payment fund institution, as well as to Bank of Mexico and the CNBV, the books, systems, records, manuals, and documents in general, related to the provision of the service in question. Likewise, to allow the Independent Third Party or the personnel of Bank of Mexico or the CNBV access to their offices and facilities in general, related to the provision of the service in question.
c)
To inform the electronic payment fund institution regarding any modification to its corporate purpose or any other change that could affect the provision of the service subject to the contract, at least thirty days in advance of when such modification or change occurs.
d)
To maintain confidentiality regarding the information that has been received, transmitted, processed, or stored during the provision of the services. Likewise, to accept that such information may only be used for the purposes agreed upon in the provision of the service.
e)
In the event that the third party carries out subcontracting for the partial or total provision of any of the services provided to the electronic payment fund institutions, it must notify the institution regarding such subcontracting; likewise, it will establish mechanisms so that the subcontractor complies with the agreed obligations and provides the information for the purposes of article 52 of these Provisions.
f)
To comply with the terms, conditions, and processes so that the third party guarantees to the electronic payment fund institution the transfer, return, and secure deletion of the information subject to the contracted service when it ceases to provide it.
g)
To maintain complete audit records that include detailed information of accesses or access attempts and the operation or activity carried out by the Users of the Technological Infrastructure. Such records must be available to the authorized personnel of the electronic payment fund institution.
h)
To have access controls to information according to the access levels and profiles determined by the electronic payment fund institution.
i)
To allow the electronic payment fund institution to carry out the security reviews indicated in articles 21, 33, and 34 of these Provisions on the contracted services, or to provide evidence of the carrying out of these reviews.
III.
Documentation regarding the Technological Infrastructure indicated below:
a)
Description of the communication links used by the electronic payment fund institution to connect with the service provider, including the name of the provider, bandwidth, and type of service provided, among others.
b)
Telecommunications diagram showing the existing connection between each of the participants in the provision of the service, such as providers, data centers, and the electronic payment fund institution, among others, including redundancy schemes.
c)
Full address of the place where each of the services will be carried out, as well as of the primary and secondary data centers where the information will be stored and processed. In the event that the indicated place is located in national territory, it must include at least, street, exterior and interior number, neighborhood, borough or municipality, postal code, and federal entity. With respect to a site located abroad, similar data must be included that allows locating the indicated place with certainty. With respect to Cloud Computing services, only what is indicated in article 50 of these Provisions must be provided.
d)
As applicable, the scheme of interrelation of applications or systems subject to the contract, including the systems of the electronic payment fund institution.
e)
Mechanisms for continuity of the contracted service.
IV.
Mechanisms that will allow the electronic payment fund institution to keep under its custody, either in its own Technological Infrastructure or that of third parties in national territory, the detailed records of all Operations carried out, as well as its accounting records, in such a way as to ensure operational continuity at all times. Such records must be maintained in a format that allows their consultation, operation, and use, regardless of whether the service contracted with the third party is not available.
V.
Evidence of the controls that the third party will maintain to guarantee the confidentiality, integrity, and availability of this information, when it has access privileges to images of official identifications or biometric information of the Clients.
VI.
Description of the mechanisms to monitor the performance of the contracted third party and the compliance with its contractual obligations including, at least, those provided in these Provisions.
VII.
Plans to evaluate and report to the Governing Body or, as applicable, to the audit committee of the electronic payment fund institution, according to the importance of the contracted service, the performance of the third party, and the compliance with the applicable regulation related to said service.
VIII.
Evidence that allows verifying that the third parties have and implement personal data protection and information confidentiality policies that allow the electronic payment fund institution to comply with the legal provisions governing it in this matter.
With respect to services that are processed, provided, or executed wholly or partially outside national territory, electronic payment fund institutions must accompany the documentation that accredits that the third parties reside in countries whose internal law provides protection for the data of persons, safeguarding their proper confidentiality, or that such countries maintain international agreements with Mexico in this matter, or of exchange of information between supervisory bodies, with respect to Financial Entities.
Additionally, electronic payment fund institutions must:
a)
Have the approval of the Governing Body regarding that there will be no impact on the continuity of the operation of the electronic payment fund institution, due to the geographical distance and, as applicable, the language that will be used in the provision of the service.
b)
Have technical support schemes that allow solving problems and incidents, regardless of the differences that, as applicable, exist in time zones and business days. Likewise, in the event that any authority of the country of origin of the third party referred to in this fraction requires information related to the services it provides to the electronic payment fund institution, the third party must, as soon as it is legally possible, inform the institution of this, as well as provide it with a copy of the information it has delivered to said authority.
In this case, the electronic payment fund institution must inform Bank of Mexico and the CNBV of such situation in accordance with what is established in article 59 of these Provisions, immediately after it becomes aware of it, as well as provide them with a copy of the referred information.
Bank of Mexico and the CNBV will have a period of twenty-five business days to resolve regarding the authorization request referred to in this article; after this period has elapsed without any pronouncement, the resolution will be understood as positive. Any request for additional information made by Bank of Mexico or the CNBV will interrupt the period indicated in this paragraph.
Article 50.- Electronic payment fund institutions that fall under any of the cases provided for in letters a) and b) of this article must observe the measures established below for prudential reasons.
The institutions that will be obliged to adopt the measures referred to in this article will be those that hire a third party as the primary provider of the services corresponding to Cloud Computing to carry out any of the acts of issuance, administration, redemption, or transmission of electronic payment funds as indicated in fractions II, III, IV, and V of article 22 of the Law for Regulating Financial Technology Institutions, when the services provided by said third party, regardless of the nationality of the latter or of the persons who exercise Control over it, are susceptible of being interrupted, temporarily or permanently, due to some provision, order, instruction, mandate, or equivalent act of a foreign authority that is directed directly to prevent, limit, prohibit, or block the provision of Cloud Computing services by the primary provider, either by the place where it or the persons who exercise Control over it are located or have been constituted, or in that they maintain assets or carry out their operations, as well as by the relationship that said third party has with the respective electronic payment fund institution, and that this makes it impossible for said institution to carry out the aforementioned acts of issuance, administration, redemption, or transmission of electronic payment funds.
Electronic payment fund institutions that fall under the case referred to in the previous paragraph must include in their respective Business Continuity Plans any of the mechanisms indicated below, with the purpose of guaranteeing that they will maintain the computing and processing capacity necessary so that, from a period not greater than two hours, the referred mechanisms are implemented and the respective processes can be carried out, at least, to perform all the acts of issuance, administration, redemption, or transmission of electronic payment funds referred to above, during the period that the interruption of the primary Cloud Computing lasts:
I.
A mechanism that, in addition to the primary Cloud Computing referred to in this article, allows electronic payment fund institutions to have the availability of Cloud Computing services provided by a secondary provider, provided that this other additional provider is not subject to the same risk to which the primary Cloud Computing is subject, as contemplated in the second paragraph of this article, by being subject to a jurisdiction different from that in which the risk that gives rise to the interruption of the services provided by the primary provider may occur, as well as by being under the Control of a person different from the primary provider or any other person who belongs to the same Business Group of said primary provider or of a Group of Persons in which said primary provider or person of the same Business Group participates.
The foregoing shall not be understood in the sense that the services corresponding to the secondary Cloud Computing must be carried out simultaneously with those of the primary Cloud Computing referred to used by the institution in its normal operation, while the referred interruption has not occurred.
II.
A mechanism that, in addition to the primary Cloud Computing used by the institution in question and located in the case described in the second paragraph of this article, allows the institution in question to have its own infrastructure that allows it to carry out, in a territory different from that of the foreign jurisdiction in which the risk referred to in the second paragraph of this article may occur, the processes referred to in said paragraph, provided that the execution of said processes is not carried out by the primary Cloud Computing provider or depends on it or on the persons who exercise Control over it or well, depends on any other person that both it and those who exercise Control over it are subject to the same jurisdiction in which the indicated risk may occur.
The implementation of the mechanism indicated in this fraction will not imply the operation simultaneously with the Cloud Computing of the primary provider used by the institution in its normal operation, while the referred interruption has not occurred.
III.
Any other mechanism different from those contemplated in fractions I and II above that, at the request of the electronic payment fund institution, are authorized by Bank of Mexico and the CNBV, independent of that other authorization that, in accordance with fraction III of article 44 of these Provisions, said authorities grant for the hiring of the primary provider of the Cloud Computing referred to in the second paragraph of this article, provided that the electronic payment fund institution demonstrates that said mechanism can ensure the continuity in the carrying out of the acts indicated in the second paragraph cited, in the event that the interruption provided for in said paragraph occurs for the causes indicated therein.
The authorization request referred to in this fraction must be presented in the terms established in article 59 of these Provisions.
Electronic payment fund institutions that fall under the cases of this article will be obliged to comply with what is prescribed in this same article, without prejudice to their faculty to celebrate, in the terms and under the conditions established in these and other applicable provisions, the contracts that allow them to obtain and conserve the services related to Cloud Computing provided by third parties from the country or abroad, with computer installations located inside or outside national territory, in order to carry out the processes corresponding to their Operations that they are authorized to carry out.
What is established in this article will only be applicable to those electronic payment fund institutions that, as a result of the evaluation that is carried out with information at the close of each quarter, fall under any of the following cases:
a)
During a twelve-calendar-month period, carry out any of the following activities:
Carry out more than three million five hundred thousand Transfer Operations.
Send or receive Transfers for a total amount greater than the equivalent in national currency to six billion UDI's.
b)
At any time have had more than one million Accounts that, during a twelve-calendar-month consecutive period, have registered, at any time, a positive balance or with respect to which at least one Transfer has been sent in said period, or have had a total balance in the Accounts greater than the equivalent in national currency to four hundred million UDI's.
Electronic payment fund institutions to which this article is applicable will have a period of one hundred eighty natural days counted from the first day of the calendar month immediately following that in which the case contemplated in letters a) or b) above that corresponds is updated, to comply with what is established in this article.
Article 51.- Electronic payment fund institutions, for the contracting of services with third parties that are subject to authorization in terms of article 44 of these Provisions, as well as those related to operational processes and with administration of databases and computer systems, must comply with the following:
I.
With respect to third parties that provide services related to operational processes and with administration of databases and computer systems, provide for what is indicated in fraction II, letter g), numerals 1 to 6 of article 47 of these Provisions and conserve the respective contract.
II.
Carry out, at least annually, internal or external audits on the contracted service or have evidence that the contracted third party carries them out.
III.
Keep in their offices where the administration functions of the electronic payment fund institution are carried out, at least, the documentation and information relative to the evaluations, audit results, and, as applicable, the work plans that correspond, as well as the performance reports of the contracted third parties, including documentation regarding the compliance with what is indicated in fraction I of this article.
IV.
Update the description or respective documentation when there are modifications that are considered to have a relevant impact on the service provided or that are related to the systems, equipment, and applications subject to the contract or with their technical characteristics.
V.
With respect to Technological Infrastructure and information security, in addition to the information determined in article 49, fraction III, letters b) and d) of these Provisions, have the following documentation:
a)
Description of the technical characteristics of the systems, equipment, and applications subject to the contract.
b)
That in which the mechanisms to ensure the transmission and storage of Personal Information or Sensitive Information in Encrypted form, as applicable, are detailed, including the version of the Encryption protocols and security components in the Technological Infrastructure.
In the case of Sensitive Information, the information related to the Operations is exempt from Encryption, provided that such information is stored in tables or repositories different from those used to store the rest of the Personal Information and Sensitive Information and there are security mechanisms that prevent the integration of said separate repositories if not authorized to do so.
c)
That which contains the detail of the type of information of the electronic payment fund institution and Clients specifying, as applicable, the type of Personal Information or Sensitive Information that will be stored by the third party in its equipment or facilities, or to which it may have access.
d)
The description of the control and monitoring mechanisms of access to computer systems and to the Personal Information or Sensitive Information transmitted, stored, processed, safeguarded, or custodied in said systems, as well as of the logs, databases, and security configurations that are established for this purpose.
e)
The evidence of the controls and of the control mechanisms referred to in fraction V of article 49 of these Provisions.
VI.
Have the evidence referred to in fraction VIII of article 49 of these Provisions.
Article 52.- Electronic payment fund institutions must have a registry of all service providers, including those subcontracted by them, as well as of the Administrators of Commissionaires and commissioned agents hired, which must contain at least the following information:
I.
Service Providers:
a)
Name, denomination, or corporate name of the service provider.
b)
Name of the legal representative of the service provider.
c)
Description of the service contracted with the third party, including the data or information that, as applicable, are stored, processed, or transmitted by it.
d)
As applicable, information of the systems that support the service contracted with the third party that includes, at least, the name, version, and function or purpose.
e)
As applicable, interfaces with other systems and the purpose of these, including the detail of the information that is exchanged.
f)
Location where the service is carried out and where the personnel responsible for carrying it out is located.
g)
As applicable, location or jurisdiction of the main data center where the processing equipment of the contracted system is located.
h)
As applicable, location or jurisdiction of the alternate data center where the processing equipment is located, with respect to the recovery of the contracted service.
i)
As applicable, number and date of the letter with which Bank of Mexico and the CNBV granted the authorization to act as a service provider.
II.
Administrator of Commissionaires or commissionaires:
a)
Name, denomination, or corporate name of the commissionaire or of the Administrator of Commissionaires.
b)
Name of the legal representative of the commissionaire or of the Administrator of Commissionaires.
c)
Trade name of the commissionaire or of the Administrator of Commissionaires, as well as detail of the commercial modality under which it operates, whether it is a commercial chain or franchise.
d)
Number of establishments of the commissionaire in which commercial commissions are carried out,
and the complete address of each, including the geo-statistical area key
according to the Unique Catalog of State, Municipal, and Local Geo-statistical Area Keys of the National Institute of Statistics and Geography, or its successor.
e)
Type of Operation performed by the commission agent on behalf of and for the account of the electronic payment fund institution.
f)
Limits of the Operations agreed upon with the commission agent or with the Commission Agent Administrator.
g)
Access devices used to offer services to Clients, such as mobile phones, electronic tablets, and point-of-sale terminals, among others.
h)
If applicable, the number of the official document and the date on which authorization was granted for the hiring of the commission agent or Commission Agent Administrator.
Electronic payment fund institutions must disseminate through their website or application the list of modules or establishments that the commission agents or the Commission Agent Administrator have enabled to perform the Operations referred to in Article 47 of these Provisions, specifying the Operations that can be carried out in each of them and the maximum amounts authorized per Operation.
Electronic payment fund institutions must keep the registry referred to in this article updated.
Article 53.- The electronic payment fund institution must perform, at least annually, on its own or through a third party, audits aimed at verifying the degree of compliance with these Provisions. In the event that the commission agent or Commission Agent Administrator has audit results with the same object previously performed, with a maximum validity of one year, they may present them to the electronic payment fund institution. Without prejudice to the foregoing, the CNBV may order the performance of audits when, in its judgment, there are risk conditions regarding operation and information security.
Article 54.- Electronic payment fund institutions must, at all times, fully identify the Operations they perform through the commission agent or the Commission Agent Administrator, independently of those they perform through their platforms.
Likewise, electronic payment fund institutions must verify that the commission agents or Commission Agent Administrator inform Clients by any means of the electronic payment fund institutions themselves, that they act on behalf of and for the account of the respective electronic payment fund institution.
Article 55.- Electronic payment fund institutions will be liable at all times, both for the service provided by their commission agents or Commission Agent Administrator to Clients, even when the performance of the corresponding Operations is carried out under terms different from those agreed upon, as well as for the non-compliance with the provisions incurred by said commission agents.
In the event of non-compliance by the commission agents or Commission Agent Administrator with the applicable provisions, electronic payment fund institutions must implement the necessary corrective measures.
The provisions in the two preceding paragraphs will be without prejudice to the civil, administrative, or criminal liabilities in which the commission agents or Commission Agent Administrator or their employees may incur due to violations of applicable legal provisions.
The aforementioned must be established in the contract entered into between the electronic payment fund institution and the commission agent or the Commission Agent Administrator.
CHAPTER VI
ON EVALUATION THROUGH INDEPENDENT THIRD PARTIES
Article 56.- Electronic payment fund institutions must hire the services of an Independent Third Party or of the legal entity through which said Independent Third Party provides its services, to perform the evaluation of the level of compliance with the information security requirements, the use of Instruction Channels, and operational continuity that these institutions must observe in accordance with what is provided in Chapters II, III, IV, and V of these Provisions.
Article 57.- The evaluation of the level of compliance performed by the Independent Third Party referred to in the previous article must be carried out every two years.
The compliance evaluation report must be delivered by the Independent Third Party to the Administrative Body of the electronic payment fund institution and presented to the audit committee of said institution, if it has one.
Electronic payment fund institutions may not hire the services of an Independent Third Party, nor of the legal entities through which they provide the respective services, to obtain the compliance evaluation referred to in this article for more than two consecutive evaluation periods. Without prejudice to the foregoing, the electronic payment fund institution may designate the same Independent Third Party or legal entity referred to again, after a minimum interruption of five years counted from the last compliance evaluation granted with respect to said institution.
In the event that observations arise from the evaluation performed that, in the judgment of the Independent Third Party, represent serious violations, the respective electronic payment fund institution must present the compliance evaluation report to its Board of Directors within twenty business days following the end of the evaluation by the Independent Third Party, or within five business days if it is a Sole Administrator.
The report indicated in the preceding paragraph must be delivered to the Bank of Mexico and to the CNBV, in accordance with what is established in Article 59 of these Provisions, within a period of five business days counted from the day following the presentation of said report to its Administrative Body. The report must be digitally signed by the general director or, if applicable, the sole administrator, and encrypted in accordance with what is provided in the cited Article 59.
Additionally, the electronic payment fund institution must present, in accordance with what is established in Article 59 of these Provisions, and within a period of twenty business days following the completion of the evaluation performed by the Independent Third Party, a remediation plan to rectify said observations. The remediation plan must be digitally signed by the general director or, if applicable, the sole administrator, and encrypted in accordance with what is provided in the aforementioned Article 59. The CNBV and the Bank of Mexico may make observations to said remediation plan at any time.
Article 58.- Independent Third Parties that evaluate the level of compliance of electronic payment fund institutions with the norms contained in these Provisions, as well as the legal entities through which they provide the respective services, must be independent at the date of celebration of the service provision contract, during the development of the compliance evaluation, and until the issuance of the compliance evaluation report in question, and must comply with what is stated in Annex 6 of these Provisions.
CHAPTER VII
COMPLEMENTARY PROVISIONS
Article 59.- Regarding documents containing requests, reports, and plans of work or remediation that electronic payment fund institutions must present through the website that the CNBV and the Bank of Mexico make available to the aforementioned institutions at the moment they obtain authorization to organize themselves as such, for the purposes established in Articles 6, 11, 24, 26, 33, 34, 43, 44, 45, 46, and 57 of these Provisions, they must be presented with the respective electronic signatures of the corresponding representatives and, in the cases indicated, encrypted as follows:
I.
Use of cryptographic keys, known as public and private asymmetric keys, for each electronic signature, in order to guarantee confidentiality and non-repudiation, avoiding sharing the private key.
II.
Use of a digital certificate validated by a recognized certification agency or by a certification service provider accredited before the Ministry of Economy.
III.
Incorporation of electronic signature that guarantees the integrity of the information provided.
The information of the public cryptographic keys that must be used to encrypt the data message constituting the respective document will be published on the website that the Financial Authorities referred to in the first paragraph of this article will make available to the electronic payment fund institutions. To perform the encryption, said institutions may use the Bank of Mexico's information system called "WebSec" or any other developed by a third party that complies with what is provided in Annex 8 of these Provisions.
In cases where the website referred to in the first paragraph of this article is not available or if electronic payment fund institutions do not have the necessary elements to be able to use electronic signatures in the documents referred to in this article, said institutions must present said documents through the Electronic Attention Module, known as MAE, of the Bank of Mexico, in terms of the applicable provisions issued by the Bank of Mexico itself for such purposes, or in the absence of said module, by the means it makes available.
Resolutions issued regarding the documentation entered into the website of the aforementioned Financial Authorities, in accordance with what is established in this article, will be delivered jointly by said authorities, through the aforementioned website.
TRANSITORY PROVISIONS
FIRST.- These Provisions will enter into force ninety natural days after their publication in the Official Journal of the Federation.
SECOND.- Electronic payment fund institutions will have a maximum period of six months, counted from the entry into force of these Provisions, to comply with what is established in Article 15 of this instrument.
THIRD.- Electronic payment fund institutions will have a period of nine months, counted from the entry into force of these Provisions, to comply with what is established in Articles 16 and 17 of this instrument.
FOURTH.- The persons referred to in the OCTAVO Transitory Provision of the Law to Regulate Financial Technology Institutions published in the Official Journal on March 9, 2018, will have a period of six months counted from the obtaining of their authorization to act as an electronic payment fund institution, to comply with what is established in Articles 44, 45, 46, and 47 of these Provisions.
Mexico City, January 15, 2021. - BANK OF MEXICO: The General Director of Payment Systems and Market Infrastructures, Manuel Miguel Ángel Díaz Díaz. - Initials. - The General Legal Director, Luis Urrutia Corral. - Initials. - NATIONAL BANK AND SECURITIES COMMISSION: The President, Juan Pablo Graf Noriega. - Initials.
ANNEX 1
Information Security Indicators
The Chief Information Security Officer of the electronic payment fund institution, in relation to the risk indicators in information security referred to in fraction XI of Article 36 of these Provisions, must:
Evaluate said indicators, which must adjust to the thresholds contained in this annex for each indicator. In the event of defining different thresholds, the reason must be documented.
Define remediation plans for those risks where the evaluation results yield values that are within the medium and high risk thresholds established in this annex or, if applicable, those defined by the electronic payment fund institution, provided that these are in a high threshold for at least two consecutive periods.
Provide continuous maintenance, whether to add, eliminate, or update existing key risk and information security performance indicators, which must always be aligned with the strategy of the electronic payment fund institution and the Information Security Master Plan of this.
Measure and evaluate their evolution with the periodicity indicated in the following tables, or earlier in the event of unusual events.
In the event that not all scenarios apply, indicate that they are not applicable and explain the reason.
Type
Definition
Sub Type
Sub Class of Events
Examples
I. Internal Fraud
Losses derived from
any type of action
aimed at defrauding,
improperly appropriating goods
or, well, bypassing regulations,
laws or corporate policies
(excluding diversity
/ discrimination events)
in which at least one
internal party to the
Electronic Payment Fund
Institution is involved.
1.1 Unauthorized Activities.
1.1.1 Misuse of powers and authorities
1.1.2 Undisclosed operations (intentional).
1.1.3 Unauthorized operations (with financial losses).
1.1.4 Erroneous valuation of positions
(intentional).
Operations not communicated; unauthorized operations
(with financial losses); erroneous valuation of
positions, and intentional
omission of regulations.
1.2 Internal Theft and Fraud.
1.2.1 Fraud / credit fraud / worthless deposits.
1.2.2 Theft / Extortion / Misappropriation / Robbery.
1.2.3 Improper appropriation of assets.
1.2.4 Destructive destruction of assets.
1.2.5 Internal Forgery.
1.2.6 Smuggling
1.2.7 Appropriation of accounts, identity, among others.
1.2.8 Non-compliance / tax evasion (intentional)
1.2.9 Bribery / Corruption.
1.2.10 Abuse of insider information (not in favor of the company).
Theft; misappropriation; improper appropriation; destruction of
assets; forgeries; identity theft; and
bribes; account manipulation.
1.3. Vulnerability to the security of
systems.
1.3.1 Breach of security systems.
1.3.2 Damage from cyber attacks.
1.3.3 Information theft (with financial losses).
1.3.4 Inadequate use of access keys and/or authorization levels.
Abuse and use of privileged or confidential information;
alteration of computer applications; theft of passwords,
and prohibited computer access.
1.4 Identity Theft
1.4.1 Internal forgery / impersonation
Internal forgery and impersonation
II. External Fraud
Losses derived from
any type of action
aimed at defrauding, improperly appropriating goods or bypassing
the legislation, by
a third party.
2.1 External Fraud.
2.1.1 Use and/or disclosure of insider information.
2.1.2 Industrial espionage.
2.1.3 Smuggling.
Improper use of stolen, forged, stolen or
blacklisted cards.
2.2 System Security.
2.2.1 Breach of security systems.
2.2.2 Damage from cyber attacks.
2.2.3 Information theft (with financial losses).
2.2.4 Inadequate use of access keys and/or authorization levels.
Unauthorized computer access; manipulation of
corporate applications; damage from cyber attacks, and
information theft.
2.4 Identity Theft
2.4. 1 External forgery / impersonation
Forged or manipulated documentation (
transfers, etc.); identity theft.
VI. Business Incidents and System
Failures
Losses derived from
business incidents
and system failures.
6.1 Systems
6.1.1 Hardware.
6.1.2 Software.
6.1.3 Telecommunications.
6.1.4 Interruption / supply incidents.
Interruption / supply and communication line incidents; errors in
computer programs; hardware and software
failures;
sabotage; business interruptions; computer failures and
virus programming.
ID
Name
Description
Domain
Type
Sub Type
Sub Class of Events
Indicator Type
Period
Unit of
Measurement
Calculation
Variable X
Variable Y
High Risk
Medium Risk
Low Risk
KRI0001
Incidents via
direct attacks
against internal
systems.
Number of incidents
that have been
originated by attacks
towards the internal
systems of the Electronic Payment Fund
Institution, in the period
established.
Logical attacks.
II. External
Fraud.
2.2 System
Security.
2.2.1 Breach of
security systems.
Reactive.
Quarterly.
Quantity.
Variable X
Number of cases
of identified
incidents.
More than 1.
Equal to 1.
Equal to 0.
KRI0002
Fraud cases on
the platform.
Percentage of cases
where fraud is identified,
that has been
originated by attacks
towards the Platform.
Logical attacks.
II. External
Fraud
2.2 System
Security.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100
Number of fraud cases
on the
Platform.
Number of
Clients who
use the
Platform.
More than 0.01%.
Between 0.005% and
0.01%.
KRI0003
Infrastructure
Equipment whose
security configuration
is managed.
Percentage of Infrastructure
Equipment within the
Platform and/or process
of review of secure
configuration standards,
with respect to the total
of the IFPE equipment
during the period
established.
Compliance.
II. External
Fraud.
2.2 System
Security.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Percentage.
(X/Y)*100
Number of equipment
within the
platform or
process of review
of secure
configuration
standards.
Total
number of
equipment.
Less than 85%.
Between 85% and 95%.
More than 95%.
KRI0004
Level of
compliance of
secure configuration
of servers whose
configuration is
managed.
Average percentage of
server compliance level
contemplated within the
tool and/or process
of review of secure
configuration standards.
Compliance.
II. External
Fraud.
2.2 System
Security.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Average
percentage.
Average(X)
% of compliance
of the secure
configuration
standard of each one
of the Servers.
Less than 90%.
Between 90% and 95%.
More than 95%.
KRI0005
Users with
inadequate roles
and profiles.
Percentage of users
with inadequate profiles
within the
applications of the IFPE,
with respect to the total
of users in all
applications of the
Electronic Payment Fund
Institution.
Compliance.
I. Internal
Fraud
1.3. Security of
systems.
1.3.3 Information theft
(with financial losses).
1.3.4 Inadequate use
of access keys and/or
authorization levels.
Corrective.
Semi-annual.
Percentage.
(X/Y)*100
Number of
users with
incorrect profiles,
considering all
applications.
Total
number of
users
considering all
applications.
More than 3%.
Between 1% and 3%.
Less than 1%.
KRI0006
Applications without
roles and profiles.
Percentage of
applications which
do not possess the capacity
nor the profiling of roles
and permissions, or that said
profiles are not
implemented, this with
respect to the total
of applications.
Compliance.
I. Internal
Fraud.
1.3. Security of
systems.
1.3.3 Information theft
(with financial losses).
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
applications without
capacity for
profiling, or
profiling not
implemented.
Total
number of
applications.
More than 5%.
Between 2% and 5%.
Less than 2%.
1.3.4 Inadequate use
of access keys and/or
authorization levels
KRI0007
Information security
incidents in general
Total number of
incidents reported
during the period
established regarding
information security.
Information.
Applies to:
I. Internal
Fraud
II. External
Fraud VI.
Business
Incidents
and
System
Failures.
Apply to:
1.3. Security of
systems
2.2 Security of
Systems.
6.1 Systems.
Apply to:
1.3.1 Breach of
security systems
1.3.2 Damage from cyber
attacks.
1.3.3 Information theft
(with financial losses).
1.3.4 Inadequate use
of access keys and/or
authorization levels.
Reactive.
Monthly.
Quantity.
Variable X.
Number of
security incidents.
of information
More than 5.
From 2 to 5.
Less than 2.
2.2.1 Breach of
security systems.
2.2.2 Damage from cyber
attacks.
2.2.3 Information theft
(with financial losses).
2.2.4 Inadequate use
of access keys and/or
authorization levels.
6.1.1 Hardware.
6.1.2 Software.
6.1.3 Telecommunications.
6.1.4 Interruption /
incidents in the
Supply
KRI0008
Obsolete and/or
outdated technology
platforms
Percentage of
technology platforms
that are on
obsolete versions and/or
without support from the
manufacturer
Infrastructure.
II. External
Fraud.
2.2 System
Security.
2.2.1 Breach of
security systems.
Corrective.
Semi-annual
Percentage.
(X/Y)*10.
Number of
obsolete technology
platforms.
Total of
technology platforms.
More than 5%.
Between 2% and 5%.
Less than 2%
KRI0009
System
crashes
Number of system crashes
related to
services
provided to their
Clients
greater than 10 minutes.
Infrastructure.
VI.
Business
Incidents
and
system
failures
6.1 Systems.
6.1.4 Interruption /
supply incidents.
Reactive.
Monthly.
Quantity.
Variable X.
Number of
system crashes.
More than 1.
Equal to 1.
Equal to 0.
KRI0010
Security incidents due
to system vulnerabilities
provided by
providers (third parties).
Percentage of security
incidents caused
by vulnerabilities in
systems and
technological infrastructure
provided by
providers (third parties)
that do not belong to the
Infrastructure.
II. External
Fraud.
2.2 System
Security.
2.2.1 Breach of
security systems.
2.2.2 Damage from cyber
attacks.
2.2.3 Information theft
(with financial losses).
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
security incidents
attributed to
vulnerabilities in
systems provided
by
providers.
Total
number of
incidents.
security.
More than 5%.
Between 0.1% and 5%.
Less than 0.1%.
payroll of the EPFI,
reported during the
established period, with
respect to the total of
security incidents.
2.2.4 Improper use
of access keys and/or
authorization levels.
providers
(third parties).
KRI0011
Pending critical
vulnerabilities to be corrected detected in ethical
hacking tests.
Number of
vulnerabilities in the
information systems
that, according to the
ethical hacking tests,
are classified as critical, which have
more than one month
of age from their detection date.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Quantity.
Variable X.
Number of
critical vulnerabilities
pending correction with
an age of more
than one month.
More than 2.
Between 1 and 2.
Equal to 0.
KRI0012
Unavailability of
IT systems.
Average percentage of
time of
unavailability of the
systems against the total time of the established
period.
Infrastructure.
VI.
Incidents
in the
Business and
Failures in the
Systems.
6.1 Systems.
6.1.4 Interruption /
incidents in the
Supply.
Reactive.
Monthly.
Average
Percentage.
Average(X).
Average of
time of
unavailability of
IT systems.
More than 0.5%.
Between 0.25%
and 0.5%.
Less than
0.25%.
KRI0013
Critical and
high-priority incidents
in production
environments.
Percentage of incidents
qualified as critical
and high priority in
production environments
with respect to the total
of incidents in production.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
incidents in
production
qualified as critical.
Number
total of
incidents
in
production.
Greater than or equal to
0.5%.
Greater than 0%
and less than 0.5%.
Equal to 0%.
KRI0014
Components of the
technological
infrastructure
exposed to the internet
without ethical
hacking tests and/or
vulnerability
analysis.
Percentage of the
components of the
technological
infrastructure of the
organization exposed to the internet to which
ethical hacking or
vulnerability analysis
has not been performed,
with respect to the total
of equipment for more
than 3 months.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of assets
exposed to
the internet that have
not performed
ethical hacking tests
or vulnerability
analysis.
Number of
assets
exposed to
the internet.
More than 3%.
Between 1% and 3%
.
Less than 1%.
KRI0015
Pending critical
vulnerabilities to be corrected detected in the
vulnerability
analysis.
Number of
vulnerabilities in the
information systems
that, according to the
vulnerability
analyses,
are classified as critical,
which have more than
one month of age from
their detection date.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Quantity.
Variable X.
Total number of
critical
vulnerabilities.
More than 2
Between 1 and 2
Equal to 0
KRI0016
Obsolete and/or
unsupported
Technological
Infrastructure.
Number of equipment and
Technological
Infrastructure, which
are in obsolete versions
or without support,
compared to all
active IT infrastructure
in the established
period.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of obsolete
equipment and
infrastructure.
Number
total of
equipment
active.
More than 5%.
Between 2% and 5%.
Less than 2%.
KRI0017
Servers without
antimalware
solution.
Percentage of servers
without antimalware with
respect to the total
of servers.
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of servers
without antimalware.
Number
total of
servers.
More than 6%.
Between 3% and 6%.
Less than 3%.
KRI0018
Servers with
antimalware
signatures
outdated.
Percentage of servers
with antimalware (malware
signatures)
outdated with respect
to the total of servers
with antimalware in each
EPFI
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of servers
with outdated
antimalware
signatures.
Number
total of
servers
with
antimalware.
More than 6%
Between 3% and 6%
Less than 3%
KRI0019
Workstations without
antimalware
solution
Percentage of
workstations without
antimalware with respect
to the total of
equipment
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of workstations
without antimalware.
Number
total of
workstations.
More than 8%.
Between 4% and 8%.
Less than 4%.
KRI0020
Workstations with
antimalware
signatures
outdated.
Percentage of the
workstations that have
antimalware (malware
signatures)
outdated with respect
to the total of
computing equipment with
antimalware installed.
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of workstations
with outdated
antimalware
signatures.
Number of
workstations with
antimalware.
More than 8%.
Between 4% and 8%.
Less than 4%.
KRI0021
Security incidents
attributed to
personnel of
providers
(third parties).
Percentage of security
incidents
related to personnel
of providers (third parties)
that do not belong to the
payroll of the EPFI,
reported during the
established period, with
respect to the total of
security incidents.
Incidents.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of security
incidents
related to
personnel of
providers (third parties).
Number of
incidents
of
security total of
personnel of
providers
(third parties).
More than 5%.
Greater than 0%
and less than 5%.
Equal to 0%.
KRI0022
Servers with
obsolete operating
system versions.
Total percentage of
servers with obsolete
operating system
versions compared
to the total number of
servers.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of servers
with obsolete
operating system
versions.
Number
total of
servers.
More than 10%.
Between 5% and 10%.
Less than 5%.
KRI0023
Applications in
production with
partial or deficient
compliance with security
controls.
Percentage of the
applications in
production with
partial or deficient
compliance, with
respect to the security
policies
established,
in matters of security,
with respect to the total
of applications.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of deficient
security controls
in applications in
production.
Number
total of
security
controls.
More than 5%.
Between 2% and 5%.
Less than 2%.
KRI0024
Database managers
(DBM) with
obsolete or
unsupported technology versions.
Percentage of database managers (DBM),
which are obsolete versions
or unsupported by the
manufacturer,
compared to the total
of database managers
(DBM) active in the
established period.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of database
managers (DBM)
obsolete or not
supported.
Number
total of database
managers
(DBM).
More than 10%.
Between 5% and 10%.
Less than 5%.
KRI0025
Obsolete or
unsupported
applications.
Percentage of
applications within the
EPFI, which are
obsolete or
without support by the
manufacturer, in relation to
all applications
active during the established
period.
Software.
II. External
Fraud.
VI.
Incidents
in the
Business and
Failures in the
Systems.
2.2 Security of
the Systems.
6.1 Systems.
2.2.1 Breach of
security systems.
6.1.2 Software.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of obsolete or
unsupported
applications.
Total of
active
applications.
More than 5%.
Between 2% and 5%.
Less than 2%.
KRI0026
Servers without
security patch
coverage.
Percentage of servers
without the most recent
security patches,
with respect to the total
of active servers
during the established
period.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of servers
without the most recent
security patches
installed.
Total of
servers.
More than 5%.
Between 2% and 5%.
Less than 2%.
KRI0027
Workstations without
security patch
coverage.
Percentage of
workstations without the
most recent security
patches regardless of
the operating system,
with respect to
the total of workstations
of the EPFI.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of workstations
without the most recent
security patches
installed.
Number of
workstations total.
More than 3%.
Between 1% and 3%.
Less than 1%.
KRI0028
Database managers
(DBM) without
security patch
coverage.
Percentage of database
managers (DBM) without
coverage of the most recent
security patches, with respect to the total of database
managers (DBM) during
the established period.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Preventive.
Quarterly.
Percentage.
(X/Y)*100.
Number of database
managers (DBM) without
security patch
coverage.
Number
total of database
managers
(DBM).
More than 5%.
Between 2% and 5%.
Less than 2%.
ANNEX 2
Minimum requirements to develop the Business Continuity Plan
Electronic payment fund institutions, prior to the development of the Business Continuity Plan,
must carry out the following:
I.
A risk analysis that:
a)
Considers risks associated with the following factors: human (includes fraud, integrity,
training), process, technological and external (including external providers) in accordance
with the methodology referred to in article 39 of these Provisions.
b)
Identifies, evaluates, monitors and mitigates risks related to operational processes and
data processing and transmission services contracted with providers, as well as those
related to custody and safeguarding of information of the electronic payment fund
institution and its Clients.
c)
Determines the risks derived from the geographic location of the main data processing
centers and operation of the processes identified as critical in accordance with the
business impact analysis, to avoid that the alternative data processing and operation
centers are exposed at the same time to the same risks as the main ones.
d)
Evaluates the need to establish alternative information processing sites or services,
as well as operations which, if applicable, must allow operation at the time it is
required, and not be subject at the same time to the same risks as the primary site.
II.
A business impact analysis that:
a)
Contains all services and processes, identifying those that are critical and that
are considered indispensable for the continuity of operations, including services
contracted with their service providers.
b)
Determines the minimum human, logistical, material, Technological Infrastructure and
of any other nature resources necessary to maintain and restore the services and
processes of the electronic payment fund institution in the event of an Operational
Contingency, as well as at the end of this.
c)
Relevant scenarios related to possible Operational Contingencies, considering,
among others, the following:
Natural and environmental disasters.
Infectious diseases.
Cyberattacks or computer activity attacks.
Sabotage.
Terrorism.
Interruptions in energy supply.
Failures or unavailability in Technological Infrastructure.
Unavailability of human, material or technical resources.
Interruptions occurred in services provided by third parties.
d)
Estimates the quantitative and qualitative impacts of Operational Contingencies, based on the
scenarios defined for each process and through the methodologies referred to in the
article 39 of these Provisions.
e)
Defines the recovery priority for each of the processes.
f)
Determines the recovery time objective (known as RTO, from its English acronym),
for each of the services and processes. In the case of processes considered as
critical, the recovery period must not exceed two hours.
g)
Establishes the recovery point objective (known as RPO, from its English acronym),
understood as the maximum tolerable data loss for each of the services and processes,
considering that the information of those operations already carried out cannot be lost in
any scenario and that the status of each operation
celebrated at the moment when the Operational Contingency occurred is known in a timely manner.
h)
Identifies and evaluates risks related to operational processes and data processing and
transmission services contracted with providers, as well as risks
related to custody and safeguarding of information of the electronic payment fund
institution.
III.
The Business Continuity Plan must indicate the processes that will have priority in the
recovery when an Operational Contingency occurs, in accordance with the impact analysis to which
section II of this annex refers.
IV.
In the development of the Business Continuity Plan, at least the following
actions must be incorporated:
a)
Preventive, which will include, at least, the determination of activities and
procedures related to:
The reduction of vulnerabilities in the processes and services of the electronic payment fund
institution in the face of Operational Contingencies.
The availability of human, financial, material, technical and
Technological Infrastructure resources necessary to act in a timely manner in the face of an
Operational Contingency.
The establishment of an annual testing program, or sooner if a significant
change occurs in the Technological Infrastructure, processes, products and services, or
internal organization of the institution, regarding the functioning and sufficiency of the Business Continuity Plan that evaluates all its stages and components.
Policies and procedures for training personnel involved, both in the
processes, as well as in the development of the plan itself.
Procedures for recording, attending, following up and disseminating to personnel whose functions are
affected by the Operational Contingency or are related to the execution of the
Business Continuity Plan, the findings, incidents or observations resulting
from the tests on the functioning and sufficiency of said plan, or from the execution
of the same in case an Operational Contingency has occurred.
b)
Contingency, which will include the definition of authorized response actions and procedures for:
Timely identification of the nature of Operational Contingencies that affect the
critical processes of the electronic payment fund institution.
Contain the effects of Operational Contingencies on critical processes and favor
the restoration of operations to the required levels of functioning.
Inform the Bank of Mexico and the CNBV of the Operational Contingencies,
in accordance with what is stated in article 43 of these Provisions.
c)
Recovery, which will include the definition of actions and procedures to be followed so that
the services and processes of electronic payment fund institutions, in the event of
materialization of Operational Contingencies, can continue their operation at a minimum
acceptable level, including mechanisms for updating and reconciliation of information, as well as
the mechanisms for recovery in case of updating what is provided in section VII of article
49 of these Provisions.
d)
Restoration, which will include the definition of actions and procedures so that
the services and processes of electronic payment fund institutions return to their normal operation
after the execution of recovery actions due to the occurrence of any
Operational Contingency.
e)
Evaluation, which will include the collection and analysis of relevant information
on the development of the Operational Contingency, and of the actions and procedures
followed for its prevention, containment, recovery and restoration in order to, if applicable,
make the necessary adjustments to the Business Continuity Plan.
Electronic payment fund institutions, when defining the different actions and procedures referred to
in this section, must, at all times, precisely determine the responsible personnel, as well as provide for
their replacement or substitution in case the holders are not present or available to carry out what the Business Continuity Plan establishes.
ANNEX 3
Incidents in matters of information security
I.
Information of the electronic payment fund institution
a)
Name of the electronic payment fund institution.
b)
Full name of the chief information security officer, as well as their phone number and email address.
II.
Detailed Information of the Information Security Incident
Description of the Information Security Incident
a)
Date and time it occurred
b)
Date and time it was detected
c)
Duration of the incident
d)
Is the information involved in the incident managed by third parties?
Yes ( )
No ( )
e)
If the answer to item d) is affirmative, detail provider data (name,
address and contact data, email, phone, among others)
Impact caused by the Information Security Incident
f)
Can the incident cause a monetary loss for Clients or for the
EPFI itself?
Yes ( )
No ( )
g)
Is it viable to recover the possible monetary loss directly (own management) or indirectly (through
insurance)?
Yes ( )
No ( )
h)
Have other incidents related to the one reported been identified, whether by
origin, mode of operation or impact?
Yes ( )
No ( )
i)
Indicate, if applicable, the type of information compromised with the Information Security
Incident, in accordance with the following tables:
Compromised Client Personal Information
Names
Yes ( )
No ( )
Addresses
Yes ( )
No ( )
Phone numbers
Yes ( )
No ( )
Email addresses
Yes ( )
No ( )
Biometric data (fingerprints, iris or retina patterns or facial recognition,
among others)
Yes ( )
No ( )
Other(s):
Account or Balance Information
Card numbers, or others
Yes ( )
No ( )
Account Numbers
Yes ( )
No ( )
Passwords or Customer Identifier numbers
Yes ( )
No ( )
Customer Identifiers
Yes ( )
No ( )
Limits
Yes ( )
No ( )
Balances
Yes ( )
No ( )
Other(s)
Information of the electronic payment fund institution
Access Keys
Yes ( )
No ( )
Security configurations
Yes ( )
No ( )
Port or service identification
Yes ( )
No ( )
IP addresses of components or services
Yes ( )
No ( )
IP addresses of internal components
Yes ( )
No ( )
Access to internal network segments
Yes ( )
No ( )
Software, operating systems or database versions
Yes ( )
No ( )
Vulnerability identification
Yes ( )
No ( )
Other(s)
III.
Classify the reported Information Security Incident based on the following
definitions:
a)
Unintentional or accidental damage, loss of information or loss of assets
Improperly shared information
Yes ( )
No ( )
Errors or omissions in systems or devices
Yes ( )
No ( )
Errors in procedures or controls
Yes ( )
No ( )
Unauthorized changes to data
Yes ( )
No ( )
Loss of information or devices
Yes ( )
No ( )
Other(s):
b)
Incidents due to failures or malfunctions
Devices
Yes ( )
No ( )
Systems
Yes ( )
No ( )
Communications
Yes ( )
No ( )
Services
Yes ( )
No ( )
Third-party equipment
Yes ( )
No ( )
Supply chain
Yes ( )
No ( )
Other(s):
c)
Incidents due to interruption or lack of supplies
Absence of personnel
Yes ( )
No ( )
Strikes
Yes ( )
No ( )
Energy
Yes ( )
No ( )
Water
Yes ( )
No ( )
Telecommunications
Yes ( )
No ( )
Other(s):
d)
Incidents due to data interception
Espionage
Yes ( )
No ( )
Messages
Yes ( )
No ( )
Wardriving
Yes ( )
No ( )
Man-in-the-middle attacks
Yes ( )
No ( )
Session hijacking
Yes ( )
No ( )
Sniffers
Yes ( )
No ( )
Message theft
Yes ( )
No ( )
Other(s):
e)
Incidents due to malicious activity with the aim of taking control, destabilizing
or damaging a computer system
Identity theft
Yes ( )
No ( )
Phishing
Yes ( )
No ( )
Denial of service (DOS, DDOS)
Yes ( )
No ( )
Malicious code (malware, trojans, worms, code injection, virus,
ransomware)
Yes ( )
No ( )
Social engineering
Yes ( )
No ( )
Certificate breach (site spoofing, false certificates)
Yes ( )
No ( )
Hardware manipulation (anonymous proxies, skimmers, sniffers)
Yes ( )
No ( )
Information alteration (address spoofing and routing tables, DNS
poisoning, configuration alteration)
Yes ( )
No ( )
Abuse of audit applications
Yes ( )
No ( )
Brute force attacks
Yes ( )
No ( )
Abuse of authorizations
Yes ( )
No ( )
Organized crime
Yes ( )
No ( )
Hacktivists
Yes ( )
No ( )
Government or affiliated groups
Yes ( )
No ( )
Terrorists
Yes ( )
No ( )
Insiders
Yes ( )
No ( )
Other(s):
f)
Incidents originating from legal aspects
Violation of contractual clauses
Yes ( )
No ( )
Violation of confidentiality agreements
Yes ( )
No ( )
Adverse decisions (judicial resolutions in the same jurisdiction or others)
Yes ( )
No ( )
Other(s):
g)
Others (specify)
IV.
Classification of the Information Security Incident
Indicate in the following table the classification in which the incident falls using the concepts from the catalog listed below:
Type
Sub Type
Event Sub-Class
I. Internal Fraud
1.1 Unauthorized activities.
1.1.1
Undisclosed operations (intentional).
1.1.2
Unauthorized operations (with financial losses).
1.1.3
Erroneous valuation of positions (intentional).
( )
( )
( )
1.2 Internal Theft and Fraud.
1.2.1
Fraud / valueless deposits.
1.2.2
Extortion / embezzlement / theft.
1.2.3
Misappropriation of assets.
1.2.4
Destructive damage to assets.
1.2.5
Internal forgery.
1.2.6
Smuggling.
1.2.7
Account/identity appropriation, among others.
1.2.8
Non-compliance/tax evasion (intentional).
1.2.9
Bribery.
1.2.10
Abuse of insider information (not for the benefit of the company).
( )
( )
( )
( )
( )
( )
( )
( )
( )
( )
1.3. System security.
1.3.1
Breach of security systems.
1.3.2
Damage from cyberattacks.
1.3.3
Theft of information (with financial losses).
1.3.4
Inadequate use of access keys and/or authorization levels.
( )
( )
( )
( )
( )
II. External Fraud
2.1 External Theft and Fraud.
2.1.1
Theft / fraud / extortion / bribery.
2.1.2
External forgery / Impersonation.
2.1.3
Use and/or disclosure of insider information.
2.1.4
Industrial espionage.
2.1.5
Smuggling.
( )
( )
( )
( )
( )
2.2 System Security.
2.2.1
Breach of security systems.
2.2.2
Damage from cyberattacks.
2.2.3
Theft of information (with financial losses).
2.2.4
Inadequate use of access keys and/or authorization levels.
( )
( )
( )
( )
VI. Business Incidents and System Failures
6.1 Systems
6.1.1
Hardware.
6.1.2
Software.
6.1.3
Telecommunications.
6.1.4
Interruption / supply incidents.
( )
( )
( )
( )
Name and signature of the Chief Information Security Officer
ANNEX 4
Information Security Incident Report
I.
Information of the electronic payment fund institution
a)
Name of the electronic payment fund institution.
b)
Full name of the information security officer, as well as their phone number and email address.
II.
Detailed information of the Information Security Incident
a)
Attach, in encrypted digital media, the following information:
Description of the Information Security Incident.
Affected Account numbers.
Status of the Affected Accounts (blocked, suspended, active).
Affected network zone (internet, internal network, administration network, among others).
Type of affected system (file server, web server, email service, database, workstations, whether desktop or mobile, among others).
Operating system (specify version).
Protocols or services of the impacted components.
Number of components of the electronic payment fund institution's systems affected.
Applications involved (specify version).
Information of the compromised device, if applicable (brand, software version, firmware, among others).
Impact on the service (considering any disruption) caused by the Information Security Incident.
Amount of loss in pesos, if applicable.
Amount recovered in pesos, if applicable.
Status of the Information Security Incident (Resolved or Unresolved).
Indicate whether the Information Security Incident has been disclosed to any authority. If affirmative, indicate the authority and the date.
Public IP addresses, email addresses, or domains from where the attack originates.
The communication protocol used, if applicable.
The URL in case of websites involved.
The malware or signature detected.
Detail the actions taken to mitigate the Information Security Incident, mentioning the persons responsible for implementing said mitigation actions.
Description of the results of the mitigation actions.
Incident recovery times.
Actions to minimize damage in similar subsequent situations.
Other information that you consider should be known to the CNBV.
Communication actions with Clients to inform them of the incident.
Name and signature of the Chief Information Security Officer
ANNEX 5
Operational Contingencies Report
I.
Information of the electronic payment fund institution
a)
Name of the electronic payment fund institution.
b)
Author of the report.
c)
Position/Area
d)
e)
Phone
II.
Detailed information of the Operational Contingency
Description of the Operational Contingency
a)
Date and time it occurred
b)
Date and time it was detected
c)
Duration of the operational contingency
d)
Location(s) of the affected installation(s) (data center, offices)
e)
Failures or malfunctions in the Technological Infrastructure that supports the services
Yes ( )
No ( )
g)
Impact on the critical components of the Technological Infrastructure that has resulted in the total or partial activation of the Business Continuity Plan.
Yes ( )
No ( )
h)
Indicate if the event originated from a cybersecurity incident.
Yes ( )
No ( )
i)
Indicate the Impact of the events (according to the "Impact Scale" ):
Very High [ ]
High [ ]
Medium [ ]
Low [ ]
j)
Is the Technological Infrastructure involved in the operational contingency administered by third parties?
Yes ( )
No ( )
k)
If the answer to item j) is affirmative, detail the provider's data and services provided
II.
Classify the reported operational contingency based on the following causes that provoked the operational contingencies:
Failures in the Technological Infrastructure that supports the services or Impact on the critical components of the Technological Infrastructure that has resulted in the total or partial activation of the Business Continuity Plan
Failures or malfunctions
Devices
Yes ( )
No ( )
Systems
Yes ( )
No ( )
Telecommunications
Yes ( )
No ( )
Services
Yes ( )
No ( )
Databases
Yes ( )
No ( )
Third-party equipment
Yes ( )
No ( )
Others (specify)
Unintentional or accidental damage
Errors in procedures or controls
Yes ( )
No ( )
Mention the procedures or controls
Improper changes to data
Yes ( )
No ( )
Other(s):
Cybersecurity incident
Devices
Yes ( )
No ( )
Systems
Yes ( )
No ( )
Telecommunications
Yes ( )
No ( )
Services
Yes ( )
No ( )
Databases
Yes ( )
No ( )
Third-party equipment
Yes ( )
No ( )
Others (specify)
Impact from scenarios other than impacts on Technological Infrastructure
Interruption or lack of supplies
Protests
Yes ( )
No ( )
Strikes
Yes ( )
No ( )
Energy
Yes ( )
No ( )
Water
Yes ( )
No ( )
Others (specify)
Natural or environmental disasters
Earthquakes
Yes ( )
No ( )
Floods
Yes ( )
No ( )
Hurricanes
Yes ( )
No ( )
Fires
Yes ( )
No ( )
Others (specify)
Quantification caused by the operational contingency
Did the operational contingency cause a monetary loss for Clients or for the institution itself?
Yes ( )
No ( )
Monetary loss
$
Number of Affected Clients
IV.
Report on the description of the reported operational contingency
a)
Detailed description of the causes and diagnosis of the operational contingency (Indicate root cause and how it was determined)
b)
Actions implemented to resolve the presented problems (corrective actions) (Indicate chronology and description of what was done)
c)
Indicate the controls that failed
d)
What preventive and corrective actions will be carried out to mitigate the risk of a similar situation occurring?
e)
Work plan for the attention of corrective actions that was elaborated for this purpose, which must contain at least the personnel responsible for its design, implementation, execution, and monitoring, deadlines for its execution, detail of activities performed and to be performed, as well as the technical, material, and human resources employed
f)
Additional Information (Indicate anything you consider useful to complement this report)
Name and signature of the representative of the Administrative Body
In section III of this Annex, the reasons that motivated the classification of the incident must be described, based on the following "Impact Scale":
ANNEX 6
Characteristics of Independent Third Parties
A.
Independence requirements
Independence shall be considered non-existent when the Independent Third Party or the legal entity through which it provides its services falls under any of the following circumstances:
I.
The Independent Third Party or the legal entity through which it provides its services exercises Control over the electronic payment fund institution, or is its subsidiary, its associate, an entity with which it enters into agreements with joint control, or a legal entity that belongs to the same Business Group or Consortium as the electronic payment fund institution.
The income received by the Independent Third Party or the legal entity through which it provides its services, derived from the electronic payment fund institution or, as applicable, from its parent company, subsidiaries, associates, entities with which it enters into agreements with joint control, or legal entities that belong to the same Business Group or Consortium, resulting from the provision of its services, represent in total 10% or more of the total income of said legal entity or Independent Third Party during the year immediately preceding that in which it intends to provide the service.
II.
The Independent Third Party or the legal entity through which it provides its services, has been an important Client or supplier of the electronic payment fund institution or, as applicable, of its parent company, subsidiaries, associates, entities with which it enters into agreements with joint control, or legal entities that belong to the same Business Group or Consortium, during the year immediately preceding that in which it intends to provide the service.
A Client or supplier is considered important when its sales or purchases to the electronic payment fund institution or, as applicable, to its parent company, subsidiaries, associates, entities with which it enters into agreements with joint control, or legal entities that belong to the same Business Group or Consortium, represent in total 10% or more of its total sales or, as applicable, total purchases.
III.
The Independent Third Party or any partner of the legal entity through which it provides its services, are or have been during the year immediately preceding their hiring, a board member, general manager, or employee holding a position within the two levels immediately below the latter in the electronic payment fund institution, in its parent company, subsidiaries, associates, entities with which it enters into agreements with joint control, or legal entities that belong to the same Business Group or Consortium.
IV.
In the event that the Independent Third Party or any partner of the legal entity through which the services are provided, the spouse, concubine, concubinario, or economic dependent of the aforementioned natural persons, have investments in shares or debt securities issued by the electronic payment fund institution or, as applicable, by its parent company, subsidiaries, associates, entities with which it enters into agreements with joint control, or legal entities that belong to the same Business Group or Consortium, have credit instruments that represent said values or derivatives that have them as underlying, except when it comes to fixed-term deposits, including withdrawable certificates of deposit on predetermined days, bank acceptances, or promissory notes with yield payable at maturity, provided that these are contracted under market conditions.
The provisions of this section shall not apply to:
a)
The holding of shares representing the share capital of variable income investment funds and debt instruments.
b)
The holding of shares representing the share capital of a joint-stock company, registered in the National Securities Registry under the responsibility of the CNBV, through trusts constituted for that sole purpose in which they do not intervene in investment decisions or in titles referred to indices or baskets of shares or in credit instruments that represent shares of the share capital of two or more joint-stock companies issued under the auspices of trusts.
V.
The Independent Third Party or any partner of the legal entity through which the services are provided, the spouse, concubine, concubinario, or economic dependent of the aforementioned natural persons, maintain with the electronic payment fund institution or, as applicable, with its parent company, subsidiaries, associates, entities with which it enters into agreements with joint control, or legal entities that belong to the same Business Group or Consortium, debts for loans or credits of any nature, except when it comes to credit card debts, for financing intended for the purchase of durable consumer goods, for mortgage credits for the acquisition of real estate, and for personal and payroll credits, provided that they are granted under market conditions.
VI.
In the event that the parent company, subsidiaries, associates, entities with which it enters into agreements with joint control, or legal entities that belong to the same Business Group or Consortium as the electronic payment fund institution, have investments in the legal entity in which the Independent Third Party provides its services or is a partner who performs the audit.
VII.
In the event that the Independent Third Party or the legal entity through which the services are provided provides to the electronic payment fund institution, in addition to the compliance evaluation, any of the following services:
a)
Consulting on the elaboration of processes, procedures, policies, and criteria, as well as the systems that the electronic payment fund institution must have to comply with the requirements referred to in these Provisions.
b)
Direct or indirect operation of financial information systems, or administration of its local network.
c)
Supervision, design, or implementation of the computer systems (hardware and software) of the electronic payment fund institution, which carry out activities for the operations that the said institution performs.
d)
Supervision, design, or implementation of policies and procedures for information security, use of Instruction Channels, or operational continuity.
e)
Provision of services related to information security, use of electronic media, or operational continuity.
f)
Administration of the electronic payment fund institution, temporary or permanent, participating in decisions.
g)
Internal audit related to the evaluation of the level of compliance with requirements related to information security, use of Instruction Channels, and operational continuity.
h)
Recruitment and selection of personnel of the electronic payment fund institution to occupy positions of general manager or of the two levels immediately below the latter.
i)
Any other service that implies or could imply conflicts of interest regarding the compliance evaluation work to be carried out.
VIII.
The income that the Independent Third Party or the legal entity through which the service is provided receives or will receive for carrying out the compliance evaluation of the electronic payment fund institution depends on the result of the evaluation itself or on the success of any operation performed by said electronic payment fund institution that has the compliance evaluation as its basis.
IX.
The Independent Third Party or the legal entity through which the service is provided, have overdue accounts receivable with the electronic payment fund institution for fees resulting from a service that has already been provided to the electronic payment fund institution, at the date of issuance of the evaluation report.
B.
Selection of the legal entity through which compliance evaluation services will be provided
The electronic payment fund institution shall select a legal entity through which the Independent Third Party may provide compliance evaluation services to the standards contained in these Provisions, which must meet the characteristics defined in this annex.
If deemed appropriate, the electronic payment fund institution may select different legal entities to evaluate compliance with the requirements related to information security, use of Instruction Channels, and operational continuity.
In the event that, as a result of the evaluation of information security and operational continuity requirements, it is identified that one or more points are partially met or not met, any future evaluation and until the observations are fully resolved, must be carried out by the same legal entity that performed the first evaluation.
Only when due to force majeure it is not possible for the electronic payment fund institution to select the same legal entity, it may select a different legal entity, for which it must fully justify its reasons in writing to the Bank of Mexico and the CNBV.
C.
Service provision contract signed between the electronic payment fund institution and the legal entity through which compliance evaluation services will be provided
The electronic payment fund institution must establish a service provision contract with the legal entity in which they define the terms under which the latter will perform the evaluation, as well as the period that the activities will cover. Said contract must establish the following aspects:
I.
That the Independent Third Parties assigned to the project meet the characteristics indicated in this Annex, as well as the provisions of these Provisions.
II.
That the delivery of information between the electronic payment fund institution and the legal entity will be carried out in the terms specified in this Annex.
III.
That the information provided by the electronic payment fund institution, as well as the results of the compliance evaluation, may be requested directly from the legal entity by the Bank of Mexico or the CNBV.
IV.
That the legal entity and the Independent Third Parties commit to:
a)
Maintain confidentiality regarding the evidence collected and the results obtained from the evaluation of the electronic payment fund institution on the compliance of information security and operational continuity requirements.
b)
Maintain confidentiality regarding information security and operational continuity requirements.
c)
Safeguard the information produced as part of the evaluation in restricted access media, ensuring its integrity and confidentiality.
D.
Evaluation of compliance with requirements related to information security, Instruction Channels, and operational continuity
The compliance evaluation comprises two types of reviews:
I.
Extra-situ.- Dictation of documentary evidence provided by electronic payment fund institutions.
II.
In-situ.- Verification of compliance with requirements through visits to the facilities of the electronic payment fund institution, based on the evidence provided by it.
E.
Characteristics of the legal entity and Independent Third Party through which compliance evaluation services will be provided
Independent Third Parties must meet the following characteristics:
I.
In matters of information security:
a)
Hold at least one of the following certifications: CISSP (Certified Information System Security Professional), CISA (Certified Information Systems Auditor), or CISM (Certified Information Security Manager) or their equivalents or those that replace them. The Bank of Mexico and the CNBV may disclose on their website the certifications that are equivalent or replace those mentioned in this item.
b)
Demonstrate experience in information security consulting in the financial sector for at least two years.
c)
Have participated in activities or projects related to information security in the last twenty-four months.
II.
In matters of operational continuity:
a)
Hold at least two of the following certifications: ISO 31000, ISO 22301, Basel II, and COSO II or their equivalents or those that replace them. The Bank of Mexico and the CNBV may disclose on their website the certifications that are equivalent or replace those mentioned in this item.
b)
Demonstrate experience in business continuity management auditing in the financial sector for at least two years.
The legal entity through which the Independent Third Party may provide compliance evaluation services to the standards contained in these Provisions, must meet the following characteristics:
I.
It must not be disqualified from entering into any contract with the Federal Public Administration, regarding professional services related to information technologies, operational risk, operational continuity, and anti-money laundering prevention.
II.
In matters of information security, it must comply with the following:
a)
Experience in information security consulting in the financial sector for at least five years when it comes to electronic payment fund institutions considered relevant in accordance with article 49 of these Provisions.
Regarding electronic payment fund institutions that are not considered within the
In the aforementioned case, the independent third party must have at least two years of experience in information security in the financial sector, or at least three years in said matter, but not specifically in the financial sector.
b)
Profile oriented towards information security auditing.
III.
In terms of operational continuity, it must comply with the following:
a)
Experience in risk management consulting in the financial sector of at least five years when dealing with electronic payment fund institutions considered relevant in accordance with Article 49 of these Provisions.
In the case of electronic payment fund institutions that do not fall under the aforementioned scenario, the independent third party must have at least two years of experience in information security in the financial sector or at least three years in said matter but not specifically in the financial sector.
b)
Profile oriented towards business continuity auditing.
IV.
Independent Third Parties that provide their services through the aforementioned legal entity must not be subcontracted.
ANNEX 7
Technical Requirements to Carry Out Operations through Commission Agents
Commission agents or the Commission Agent Administrator, to guarantee the correct execution of Operations and the security of Client information, must have the following:
I.
Definitions.
For the purposes of this annex, the following shall be understood:
Individual Identifier: the string of characters assigned to each operator individually.
II.
Description of the technical characteristics of the systems, equipment, and applications that the commission agent or the Commission Agent Administrator will use to carry out Operations, from their initiation until the impact on the respective accounts of the electronic payment fund institution, considering all involved participants.
The aforementioned description must contain, at least, the following:
a)
Description of the communication links used by the electronic payment fund institution to connect with the commission agent, including, at least, the name of the commission agent, the bandwidth, and the type of Operation performed.
b)
Telecommunications diagram showing the connection existing between each of the participants in the commission agent's operation (service providers, data centers, electronic payment fund institution, among others), including redundancy schemes.
c)
If applicable, scheme of interrelation of applications or systems of the commission agent or the Commission Agent Administrator, including the own systems of the electronic payment fund institution.
d)
Documentation exposing the mechanisms to ensure the transmission of information in encrypted point-to-point form, including the version of Encryption protocols and security components of the Technological Infrastructure implemented in each of the nodes involved in the sending and receiving of data.
e)
Detail of the type of information of the electronic payment fund institution, its Clients, or users of disposition instruments, specifying, if applicable, the type of Sensitive Information that will be stored by the commission agent or the Commission Agent Administrator in their equipment or facilities, or to which they may have access. In the case of Sensitive Information, the commission agent or Commission Agent Administrator must implement encryption mechanisms.
f)
Procedure for validation and testing of the commission agent's technological infrastructure installation.
f)
Criteria regarding the composition of passwords or access keys for operators and authentication factors for Clients or users of the disposition instrument, including Personal Identification Numbers (PINs).
III.
Requirements of the commission agent's or Commission Agent Administrator's technological infrastructure.
a)
Mechanisms necessary to carry out online transactions.
The commission agent's technological infrastructure must have the necessary mechanisms to carry out online transactions in the case of Receipt or Cash Withdrawal Operations, that is, at the very moment the Operation is carried out, updating the Client's balance online in compliance with the operational rules of the respective electronic payment fund institutions.
b)
Validation of the commission agent's technological infrastructure.
Only the technological infrastructure of commission agents authorized by the electronic payment fund institution will have access to the Technological Infrastructure provided by it (use of dedicated lines, identification of physical or logical addresses, VPNs, digital signatures, among others).
Likewise, the electronic payment fund institution must obtain evidence that the technological infrastructure used by the commission agents maintains control mechanisms that prevent the reading and extraction of Client information by unauthorized third parties.
c)
Policies and procedures for the administration of access and configuration of the commission agent's technological infrastructure.
It is the responsibility of the electronic payment fund institution to have policies and procedures for the commission agent or Commission Agent Administrator for:
The configuration of the technological infrastructure that connects to the electronic payment fund institution's computer systems.
The administration of cryptographic keys used between the commission agents and the electronic payment fund institution's systems.
d)
Generation of electronic records of Operations.
All Operations carried out through commission agents must generate electronic records that cannot be modified or deleted, and in which must be included, at least, the date, hour, and minute in which they were performed, the type and amount of the instruction; if applicable, the Client's account number, the medium through which the instruction was executed, as well as sufficient information allowing the identification of the personnel who performed the instruction.
The custody of said records must be under the responsibility of the electronic payment fund institution.
IV.
Requirements for operator identification and Client authentication.
a)
Mechanisms necessary for the full identification of commission agents.
Electronic payment fund institutions, in the realization of Operations through the commission agent, must have mechanisms that allow them to identify the operators, in order to have the necessary information for the resolution of clarifications or disputes. Such mechanisms must be indicated in the general functioning plan referred to in fraction I of Article 47 of these Provisions.
b)
Generation and delivery of passwords or access keys for operators.
Electronic payment fund institutions must establish mechanisms for the process of generating and delivering the authentication factors that ensure that only the commission agent or, if applicable, its operators, can know them.
c)
Composition of passwords or access keys for operators.
Criteria must be established for the characteristics of the length of passwords or access keys for operators.
d)
Protection of passwords or access keys for operators and Personal Identification Numbers (PINs) of Clients.
Electronic payment fund institutions must foresee what is necessary to prevent the reading of the characters that make up the passwords or access keys for operators, as well as the Personal Identification Numbers (PINs) entered by Clients, respectively, in the commission agent's technological infrastructure, both in their capture and in their display through screens.
The passwords or access keys for operators and the Personal Identification Numbers (PINs) of Clients must be validated and stored through encryption mechanisms.
Under no circumstances may commission agents have access to data related to said Personal Identification Numbers (PINs) of Clients.
e)
Two-factor authentication for Clients.
For the realization through commission agents of consultations and Operations that represent a charge to the Client's account, the latter must authenticate themselves through the commission agent's technological infrastructure with which the aforementioned Operations are carried out, using an authentication factor referred to in fractions II and III of Article 5 of these provisions.
For the purposes of the foregoing, electronic payment fund institutions may opt for the combination of at least two of the following authentication factors and adjust to what is provided in Article 5 of these Provisions.
f)
For the receipt and operation of transactions requested by Clients through the commission agent's technological infrastructure, operators must initiate a session and authenticate themselves through said infrastructure.
The authentication processes must be validated by the electronic payment fund institution, through the mechanisms and controls it deems appropriate. It is the responsibility of the electronic payment fund institution to ensure that commission agents have said operator authentication mechanisms, for the realization of operations.
V.
Operation of the commission agent's technological infrastructure.
a)
Generation of Operation receipts.
The commission agent's technological infrastructure must automatically generate the Operation receipts issued by the electronic payment fund institutions for each Operation, without any intervention by the commission agent's personnel. Said Operation receipts will be different from those used by commission agents to record their own commercial operations.
When the operation limits referred to in Article 48 of these Provisions are reached, as applicable, the requested Operations cannot be carried out, so the commission agent's technological infrastructure must generate receipts indicating this situation to the Client. For such purposes, a receipt must be provided that includes the following legend:
" Transaction not performed due to exceeding your allowed limit. Please contact your electronic payment fund institution. "
Electronic payment fund institutions must attach the design of the receipt for each of the Operations to be contracted.
Under no circumstances must the Client's address be shown on the operation receipt.
b)
Monitoring of Operations.
The electronic payment fund institution must establish mechanisms that allow it to monitor the activities carried out by operators through the commission agent's technological infrastructure, in order to detect transactions that deviate from the usual parameters of Operation.
c)
Storage of Client information in the commission agent's technological infrastructure.
Commission agents may not store, conserve, or copy in their technological infrastructure, information of the Client of the electronic payment fund institution. In cases where, for operational and technical reasons, it is required to store partially or totally said information in their technological infrastructure, it must have encryption mechanisms.
It is the responsibility of the electronic payment fund institutions to verify compliance with this subsection.
Annex 8
Specifications of the information system developed by a third party for the encryption of information shared with the National Banking and Securities Commission and the Bank of Mexico
For the purposes of this annex, the terms with initial capital letters used in this, in singular or plural, will have the same meanings as those established for said terms in the Commercial Code and the Rules of the Extended Security Infrastructure (IES), as well as the following:
Qualified Digital Certificate:
a Qualified Digital Certificate issued, in accordance with the IES Rules, by the Tax Administration Service, in its capacity as Certifying Agency, also referred to in the provisions of this as " e.firma ", which is stored in a digital file with extension ".cer" when obtained before said authority in accordance with the provisions it establishes for such effect, as well as any other Digital Certificate that, in accordance with the IES Rules, is issued by an authorized third party, if applicable, by the Bank of Mexico, subject to the determination of the latter that said Digital Certificate meets the same security and identity accreditation requirements observed by the Tax Administration Service for its issuance.
Encryption:
the process of applying Qualified Electronic Signature Verification Data to a Data Message to generate a new one that is unintelligible to any person, except for the Holder of the Qualified Digital Certificate of which the Qualified Electronic Signature Verification Data are part, who, in turn, acts as the Recipient of said Data Message.
Creation of an Electronic Signature:
the process of applying Qualified Electronic Signature Creation Data to a Data Message and generating the Electronic Signature that is added to said Data Message.
Qualified Electronic Signature Creation Data:
those Creation Data for Electronic Signatures provided for in the IES Rules that the Holder generates as part of the process of issuing their respective Digital Certificate, which are stored in a digital file with extension ".key".
Qualified Electronic Signature Verification Data:
those Verification Data for Electronic Signatures referred to in the IES Rules that are part of the information included in the Digital Certificate.
Decryption:
the process of applying Qualified Electronic Signature Creation Data to a Data Message that has been Encrypted, so that the Holder of the respective Digital Certificate can view the content of the original Data Message.
Electronic Signature:
the set of data that is added to a Data Message, which is logically associated with it and is attributable to the Holder once the Qualified Information System is used, and which meets the requirements of Advanced or Reliable Electronic Signature referred to in Article 89 of the Commercial Code, as modified or substituted subsequently.
Extended Security Infrastructure (IES):
that referred to in the IES Rules.
IES Rules:
the Rules to Operate as a Registrar Agency and/or Certifying Agency in the Extended Security Infrastructure, issued by the Bank of Mexico through Circular-Telefax 6/2005, as modified or substituted subsequently.
Qualified Information System:
that information system that allows, on the one hand, the Creation of Electronic Signatures, as an Electronic Signature Creation Device in terms of the IES Rules, and, on the other hand, the Verification of Electronic Signatures, as an Electronic Signature Verification Device in terms of said Rules, as well as carrying out the Encryption and Decryption of Data Messages.
Holder:
that referred to in the IES Rules, who intervenes in its capacity as Signer in terms of Article 89 of the Commercial Code.
Verification of an Electronic Signature:
the process of applying Verification Data for Electronic Signatures to the Electronic Signature of a Data Message and verifying, both the reliability of said Electronic Signature by verifying that it was created for that same Data Message using the Creation Data of the Electronic Signature corresponding to the Verification Data for Electronic Signatures, as well as the integrity of the Data Message by not suffering alteration after its Electronic Signature was generated.
The computer program developed by a third party to carry out the Encryption of information shared with the CNBV and the Bank of Mexico must comply with the following specifications:
I.
Have as its main function the application of cryptographic algorithms that meet the specifications of Electronic Signature provided for in the IES Rules.
II.
Maintain communication with a Registrar Agency of the Extended Security Infrastructure to be able to request and verify the validity of Qualified Digital Certificates of the Signers involved in the processes of Creation and Verification of Electronic Signatures and to encrypt and decrypt Data Messages. For this purpose, the computer program must comply with the Communication Protocol with the Extended Security Infrastructure that the General Directorate of Payment Systems and Market Infrastructures will keep available to interested parties on the page that the Bank of Mexico has on its internet site identified with the domain www.banxico.org.mx
III.
Implement the RFC 3852 standard " Cryptographic Message Syntax (CMS) " for the Creation of an Electronic Signature and encrypt Data Messages. Within the aforementioned standard, the specification of the resulting file of the Creation of an Electronic Signature that is generated through the so-called Signed-data Content Type on the information that conforms to the type of data files whose specification in its ASN.1 notation is described below. Likewise, within the aforementioned standard, the specification of the resulting file when encrypting a Data Message is generated through the so-called Enveloped-data Content Type on the information that conforms to the type of data files whose specification in its ASN.1 notation is described below.
The information used within the RFC 3852 standard is that which is available according to the following description in ASN.1 notation:
Files ::= SEQUENCE of Archive
File ::= SEQUENCE {
name OCTET STRING,
content OCTET STRING }
where name is the name of the file containing the information of interest. On the other hand, content is the information contained in said file interpreted as a sequence of bytes.
In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Su
Mo
Tu
We
Th
Fr
Sa
INDICATORS
Exchange Rate and Rates as of 08/28/2026
DOLLAR
16.9712 UDIS
8.808812 TIIE 28 DAYS
6.7559% TIIE 91 DAYS
6.7931% TIIE 182 DAYS
6.844% TIIE OVERNIGHT
6.50%
See more
SURVEYS
Did you like the new look of the Official Gazette website?
No
Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.