2016-02-22 | SGDB N°005/2016

Added · Updated

SGDB N°005/2016: Minimum Operational Security Requirements for Electronic Payment Instruments

The Central Bank of Bolivia mandates updated minimum operational security requirements for electronic payment instruments, including payment orders, mobile wallets, and electronic cards, which supersede Circular Externa SGDB N° 016/2012. Financial entities, payment service companies, and related issuers must implement robust authentication mechanisms such as two-factor authentication, enforce SSL/TLS encryption, and adhere to specific data protection and transaction processing standards. The regulation establishes detailed obligations for identity verification, data retention, and liability allocation for disputes involving magnetic stripe versus chip-based transactions.

Banco Central de Bolivia logo

Bolivia

Banco Central de Bolivia

Click to view thumbnail

[Logo: BANCO CENTRAL DE BOLIVIA]

BCB-DGD-VUC BANCO CENTRAL DE BOLIVIA ESTADO PLURINACIONAL DE BOLIVIA

EXTERNAL CIRCULAR

La Paz, February 12, 2016 SGDB No. 005/2016

FROM: GENERAL MANAGEMENT FINANCIAL ENTITIES MANAGEMENT TO: FINANCIAL ENTITIES, PAYMENT SERVICE COMPANIES, ACCL S.A., EDV S.A. SUBJECT: MINIMUM OPERATIONAL SECURITY REQUIREMENTS FOR ELECTRONIC PAYMENT INSTRUMENTS

Ladies and Gentlemen:

In the framework of its regulatory powers over the national payments system and in accordance with Article 27 of the Regulation of Payment Services, Electronic Payment Instruments, Compensation and Settlement, approved by Supreme Decree No. 134/2015 of July 28, 2015, the Central Bank of Bolivia transmits for application and compliance the update to the minimum operational security requirements for electronic cards, payment orders, and mobile wallets, which renders Circular Externa SGDB No. 016/2012 of April 17, 2012, null and void.

The minimum operational security requirements for the aforementioned electronic payment instruments constitute the normative reference framework for the application of standards and best practices in the payment systems operating with these instruments.

Sincerely,

[Signature] RONALD O. PINTO RIBERA MANAGER OF FINANCIAL ENTITIES a.i. BANCO CENTRAL DE BOLIVIA

[Signature] CARLOS COLO-DRO LÓPEZ GENERAL MANAGER a.i. BANCO CENTRAL DE BOLIVIA

CCL/RPR/APM/AQA/RAT Adj.: The aforementioned

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA]

Minimum Operational Security Requirements for Payment Orders processed through Internet portals and mobile banking

The following requirements mark the minimum operational conditions for Payment Orders for application within the national territory.

  1. Transactional services must function using encrypted communication channels on a secure server under the SSL or TLS protocol.
  2. The secure site (web page) must indicate the name of the entity issuing the certificate and a link to the certification entity that allows access to the following information to verify its validity: certifying entity, web page name, name of the entity owning the site, and certificate validity.
  3. The digital certificate will be valid until the expiration date indicated therein. In no case shall the validity of the digital certificate exceed that defined in the Digital Signature Regulation for the Payments System issued by the BCB.
  4. Financial entities must implement in their operations, through Internet portals and mobile banking, robust authentication mechanisms. That is, establish at least double factor for user authentication.
  5. Fund transfers must be credited to customer accounts once the validation processes required by the processing system are completed, and at the latest by the end of the cycle in case the processing involves compensation and settlement processes.
  6. Payment Orders must comply with the following characteristics:
    • Authenticity. They must have mechanisms that allow verifying the identity of the holder of the electronic payment instrument.
    • Integrity. They must have the quality of being protected against accidental or fraudulent alterations during their processing, transport, and storage.
    • Confidentiality. They must have encryption mechanisms that prevent the unauthorized dissemination or disclosure of the information contained in the operation.
    • Non-repudiation. They must guarantee that none of the parties involved in the transaction can deny their participation in it.

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA]

- Availability. The issuer, within its control, must guarantee that the processing system is available to users as contractually established.

7. The exchange of information between financial entities and external technology service provider companies must comply with the security characteristics described in point 6. 8. The exchange of information for the processing of Payment Orders between financial entities and compensation and settlement systems must comply with what is defined in the Digital Signature Regulation for the Payments System issued by the BCB.

Abbreviations

SSL = Secure Sockets Layer, secure connection layer TLS = Transport Layer Security, transport layer security

Glossary

Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA]

Minimum Operational Security Requirements for Mobile Wallets

The following requirements mark the minimum operational conditions for mobile wallets for application within the national territory.

  1. The issuer must link the mobile wallet account number to the full name of the holder, identity document, mobile device number, and maintain a record of processed operations for a period of at least ten (10) years.
  2. Payment orders must be processed through means that guarantee compliance with the following security characteristics:
    • Authenticity. They must have mechanisms that allow verifying the identity of the holder of the electronic payment instrument in each transaction.
    • Integrity. They must have the quality of being protected against accidental or fraudulent alterations during their processing, transport, and storage.
    • Confidentiality. They must have encryption mechanisms that prevent the unauthorized dissemination or disclosure of the information contained in the operation throughout the transaction.
    • Non-repudiation. They must guarantee that none of the parties involved in the transaction can deny their participation in it.
    • Availability. The issuer must guarantee that the processing system is available to users as contractually established.
  3. The user must have a password to authenticate to the service. The issuer must generate mechanisms to remind the user to change their password periodically, at least every ninety (90) days. At no time shall this key be stored in the mobile wallet.
  4. Financial entities and PSPs must implement robust authentication mechanisms. That is, establish at least double factor for user authentication.
  5. The issuer must ensure that the maximum inactivity time in a session does not exceed twenty (20) seconds.

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA]

  1. Financial entities and PSPs must carry out information campaigns regarding the security of the use of the instrument directed at mobile wallet users, which must also include:

    a) Description of operations b) Use of the service c) Changes in operations d) Customer complaint and inquiry handling system

Abbreviations

PSP = Payment Service Company

Glossary

Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA]

Minimum Operational Security Requirements for Electronic Cards

The following requirements mark the minimum operational conditions for electronic cards for application within the national territory.

  1. Electronic cards must contain printed, engraved, or embossed, as appropriate, the following data: name of the issuer, card number, card verification value, and when applicable, name, logo, and hologram of the international brand. The credit card must include the expiration date.
  2. The last four digits embossed, engraved, or printed on the card must match the digits appearing on the receipt generated by the terminal at the time of making withdrawals or in-person purchases.
  3. When dealing with debit or prepaid cards, the issuer must offer the holder the option of printing the cardholder's name on the plastic, explaining the advantages and disadvantages of the selection. In case the client does not wish to include this data, the issuer must register and save the selection made with the holder's signature.
  4. The magnetic stripe of payment cards must contain the following information: primary account number (PAN), expiration date, PIN verification value, card verification value (CVV), and service code. This information must be validated by the issuer at the time of processing transactions.
  5. The card validation code (CAV2, CID, CVC2, CVV2) or PIN validation data must not be stored in systems or databases.
  6. Messages exchanged between terminals must be generated under the ISO 8583 standard, which may be adapted to particular needs to facilitate the interoperability of the platforms involved.
  7. Payment Service Companies that process transactions with electronic cards must communicate, with a thirty (30) calendar day advance notice to their participants, to the BCB, and to the ASFI, any updates made to the ISO 8583 standard.
  8. As a robust authentication mechanism for chip cards, the holder or user of the instrument, to make in-person purchases at merchants with electronic cards, must enter the PIN and sign the transaction receipts. In this sense, issuers must ensure in the design

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA]

of the instrument that the service code requires the entry of the PIN to perform transactions.

  1. For the case of electronic cards from foreign issuers that have exclusively a magnetic stripe for processing in Bolivian merchants, the holder or user of the instrument at the time of making an in-person purchase must enter their PIN or present their identification document and sign the transaction receipts.
  2. Acquirers must instruct merchants to process transactions always using chip reading.
  3. Disputes or claims regarding the processing of transactions will fall on the issuing or acquiring entities that do not operate with chip cards under the EMV standard as follows:
    • Responsibility for transactions processed with magnetic stripe on terminals that do not have the capacity to process chip cards will be that of the acquirer.
    • Responsibility for transactions processed with magnetic stripe-only cards on a terminal that has chip reading enabled will be that of the issuer that does not operate under the EMV standard.
  4. Encryption algorithms must be applied to authenticate the chip card and the operation data.
  5. To verify the identity of the cardholder, biometric authentication systems can also be used.
  6. In case the issuer authorizes the performance of offline operations, payment cards must use a dynamic Card Authentication Method (CAM) of the DDA or CDA type that allows recalculating the digital signature value in each transaction, for which they must be equipped with a cryptoprocessor.
  7. The operating system of the cards may be of native or open platform but must have the capacity to handle DDA or CDA, in case the issuer accepts the processing of offline transactions.

Abbreviations

CAM = Card Authentication Method CVV = Card Verification Value CDA = Combined Data Authentication DDA = Dynamic Data Authentication

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia


[Logo: BANCO CENTRAL DE BOLIVIA]

EMV = Europay, MasterCard and Visa PAN = Primary Account Number CAV2 = Card Security Code, card validation code for JCB CID = Card Security Code, card validation code for American Express CVC2 = Card Security Code, card validation code for MasterCard CVV2 = Card Security Code, card validation code for VISA PIN = Personal Identification Number

Glossary

Double factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of the combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Ayacucho Street corner Mercado · Telephone: (591-2) 2409090 · Fax: (591-2) 2661590 www.bcb.gob.bo · bancocentraldebolivia@bcb.gob.bo · La Paz Bolivia