2012-04-17 | SGDB N° 016/2012

Added · Updated

SGDB No. 016/2012: Minimum Operational Security Requirements for Electronic Payment Instruments

The Central Bank of Bolivia establishes mandatory minimum operational security standards for electronic fund transfer orders, mobile wallets, and payment cards. Financial entities must implement encrypted communication channels, robust two-factor authentication, and specific data retention and integrity protocols. For payment cards, the regulation mandates migration to the EMV chip standard, assigning liability for magnetic stripe transactions to acquirers or issuers based on terminal capabilities, and requires dynamic data authentication for offline operations.

Banco Central de Bolivia logo

Bolivia

Banco Central de Bolivia

Click to view thumbnail

EXTERNAL CIRCULAR OF THE CENTRAL BANK OF BOLIVIA

La Paz, April 17, 2012 SGDB No. 016/2012

FROM: GENERAL MANAGEMENT FINANCIAL ENTITIES MANAGEMENT

TO: FINANCIAL ENTITIES, ACCL S.A., EDV S.A., ATC S.A., LINKSER S.A., SERVired S.A., PAYMENT SERVICE PROVIDER COMPANIES

SUBJECT: MINIMUM OPERATIONAL SECURITY REQUIREMENTS FOR ELECTRONIC PAYMENT INSTRUMENTS

Ladies and Gentlemen:

In the framework of its regulatory powers over the national payments system and in accordance with Article 15 of the Regulation on Electronic Payment Instruments, approved through R.D. No. 126/2011 of October 4, 2011, and modified by R.D. 025/2012 of February 23, 2012, the Central Bank of Bolivia transmits for application and compliance the minimum operational security requirements for payment cards, electronic fund transfer orders, and mobile wallets.

The minimum operational security requirements for the aforementioned electronic payment instruments constitute the normative reference framework for the application of standards and best practices in payment systems operating with these instruments.

Sincerely,

//Attached: The above CRO/MMV/MAAM/PMS/AGA

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia


Minimum Operational Security Requirements for Electronic Fund Transfer Orders

The following requirements mark the minimum operational security conditions that operations carried out through Electronic Fund Transfer Orders (OETF) must meet and must be applied within the national territory.

  1. Transactional services must function using encrypted communication channels on a secure server under the SSL or TLS protocol.

  2. The secure site (web page) must indicate the name of the entity issuing the certificate and a link to the certification authority that allows access to the following information to verify its validity: certifying entity, web page name, name of the entity owning the site, and certificate validity.

  3. The digital certificate will be valid until the expiration date indicated therein. Under no circumstances shall the validity of the digital certificate exceed that defined in the Digital Signature Regulation for the Payments System issued by the BCB.

  4. Financial entities must implement robust authentication mechanisms in their operations, through internet portals or mobile banking. That is, establish at least a double factor for user authentication.

  5. Fund transfers must be credited to customers' accounts on the same day of their processing and with duly justified reason no later than the next business day.

  6. OETF must comply with the following characteristics:

  • Authenticity. They must have mechanisms that allow verifying the identity of the holder of the electronic payment instrument.

  • Integrity. They must have the quality of being protected against accidental or fraudulent alterations during their processing, transport, and storage.

  • Confidentiality. They must have encryption mechanisms that prevent the unauthorized dissemination or disclosure of the information contained in the operation.

  • Non-repudiation. They must guarantee that none of the parties involved in the transaction can deny their participation in it.

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia


  • Availability. The issuer, within its control, must guarantee that the processing system is available to users as contractually established.
  1. The exchange of information between financial entities and external technology service provider companies must comply with the security characteristics described in point 6.

  2. The exchange of information for the processing of OETF between financial entities and the ACH must comply with what is defined in the Digital Signature Regulation for the Payments System issued by the BCB.

Abbreviations

  • ACH = Electronic Clearing House for Electronic Fund Transfers
  • OETF = Electronic Fund Transfer Orders
  • SSL = Secure Sockets Layer, secure connection layer
  • TLS = Transport Layer Security, transport layer security

Glossary

Two-factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of a combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia


Minimum Operational Security Requirements for Mobile Wallets

The following requirements mark the minimum operational security conditions that operations carried out through mobile wallets must meet and must be applied within the national territory.

  1. The issuer must link the payment account number to the holder's full name, identity document, mobile device number, and maintain a record of processed operations for a period of at least ten (10) years.

  2. Payment orders must be processed through means that guarantee compliance with the following security characteristics:

  • Authenticity. They must have mechanisms that allow verifying the identity of the holder of the electronic payment instrument in each transaction.

  • Integrity. They must have the quality of being protected against accidental or fraudulent alterations during their processing, transport, and storage.

  • Confidentiality. They must have encryption mechanisms that prevent the unauthorized dissemination or disclosure of the information contained in the operation throughout the transaction.

  • Non-repudiation. They must guarantee that none of the parties involved in the transaction can deny their participation in it.

  • Availability. The issuer must guarantee that the processing system is available to users as contractually established.

  1. The user must have a password to authenticate to the service. The issuer must generate mechanisms to remind the user to change their password periodically, at least every ninety (90) days. At no time shall this key be stored in the mobile wallet.

  2. Financial entities and PSPs must implement robust authentication mechanisms. That is, establish at least a double factor for user authentication.

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia


  1. The issuer must ensure that the maximum inactivity time in a session does not exceed twenty (20) seconds.

  2. Financial entities and PSPs must carry out information campaigns regarding the security of the use of the instrument directed at mobile wallet users, which must additionally include:

a) Description of operations b) Use of the service c) Changes in operations d) Customer complaint and inquiry handling system

Abbreviations

  • PSP = Payment Service Provider Companies

Glossary

Two-factor authentication or robust authentication mechanism: It is a way of verifying user identity based on the use of a combination of two of the following three authentication factors:

  • Something the user knows
  • Something the user has
  • Something the user is

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia


Minimum Operational Security Requirements for Payment Cards

The following requirements mark the minimum operational security conditions that operations carried out through payment cards must meet and must be applied within the national territory.

  1. Payment cards must contain printed, engraved, or embossed, as appropriate, the following data: issuer name, card number, card verification value, and when applicable, name, logo, and hologram of the international brand. The credit card must include the expiration date.

  2. The last four embossed, engraved, or printed digits on the card must match the digits appearing on the receipt generated by the terminal at the time of making withdrawals or in-person purchases.

  3. When dealing with debit or prepaid cards, upon completion of the migration process to the EMV standard, the issuer must offer the holder the option of printing the cardholder's name on the plastic, explaining the advantages and disadvantages of the selection. In case the client does not wish to include this data, the issuer must record and save the selection made with the holder's signature.

  4. The magnetic stripe of payment cards must contain the following information: Primary Account Number (PAN), expiration date, PIN verification value, card verification value (CVV), and service code. This information must be validated by the issuer when processing transactions.

  5. The card validation code (CAV2, CID, CVC2, CVV2) or PIN validation data cannot be stored in systems or databases.

  6. Messages exchanged between terminals must be generated under the ISO 8583 standard, which may be adapted to particular needs to facilitate the interoperability of the platforms involved.

  7. Clearing and Settlement Service Entities for payment card transactions must communicate to their participants, the BCB, and the ASFI, thirty (30) calendar days in advance, any updates made to the ISO 8583 standard.

  8. As an authentication factor, for cards with magnetic stripe only, the holder or user of the instrument at the time of making an in-person purchase at a merchant must:

For the case of debit or prepaid cards:

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia


  • enter the PIN and sign the transaction receipts.

For the case of credit cards:

  • present their identification document and sign the transaction receipts.
  1. Once the migration process to the EMV standard is completed, acquirers must instruct merchants to process transactions always using chip reading.

  2. Once the deadline for migration to the EMV standard is met, which will be established between the BCB and the ASFI, disputes or claims regarding the processing of transactions will fall on the issuing or acquiring entities that do not operate with EMV standard chip cards in the following manner:

  • Responsibility for transactions processed with magnetic stripe on terminals that do not have the capacity to process chip cards will lie with the acquirer.

  • Responsibility for transactions processed with magnetic stripe-only cards on a terminal that has chip reading enabled will lie with the issuer that does not operate under the EMV standard.

  1. Encryption algorithms must be applied to authenticate the chip card and the operation data.

  2. As a robust authentication mechanism for chip cards, the holder or user of the instrument, to make in-person purchases at merchants with payment cards, must enter the PIN and sign the transaction receipts. In this sense, issuers must foresee in the design of the instrument that the service code requires the entry of the PIN to perform transactions.

  3. To verify the identity of the cardholder, biometric authentication systems can also be used.

  4. In case the issuer authorizes the execution of offline operations, payment cards must use a dynamic Card Authentication Method (CAM) of type DDA or CDA that allows recalculating the digital signature value in each transaction, for which they must be equipped with a cryptoprocessor.

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia


  1. The operating system of the cards may be of native or open platform but must have the capacity to handle DDA or CDA, in case the issuer accepts the processing of offline transactions.

Abbreviations

  • CAM = Card Authentication Method
  • CVV = Card Verification Value
  • CDA = Combined Data Authentication
  • DDA = Dynamic Data Authentication
  • EMV = Europay, MasterCard and Visa
  • PAN = Primary Account Number
  • CAV2 = Card Security Code, card validation code for Japan Credit Bureau
  • CID = Card Security Code, card validation code for American Express
  • CVC2 = Card Security Code, card validation code for MasterCard
  • CVV2 = Card Security Code, card validation code for VISA
  • PIN = Personal Identification Number

Ayacucho and Mercado • Tel: (591-2) 2409090 • P.O. Box: 3118 bcb@bcb.gob.bo • La Paz - Bolivia