EBA欧洲银行-RTS-on-SCA-and-CSC-amended-by-EBA-June-2017_30页_548kb
报告摘要
COMMISSION DELEGATED REGULATION (EU) Summary
Core Content
This document is the Commission Delegated Regulation (EU) that supplements Directive 2015/2366 (PSD2). It establishes Regulatory Technical Standards (RTS) for Strong Customer Authentication (SCA) and Common and Secure Open Standards of Communication (CSC). The regulation aims to enhance the security of electronic payments, ensure technology and business-model neutrality, and facilitate innovation and competition in the EU payment market.
Main Objectives
- Enhance Security: Ensure that payment transactions are secure through SCA.
- Promote Competition: Allow for the development of new payment services and business models.
- Ensure Technology Neutrality: Avoid favoring any specific technology for SCA implementation.
- Facilitate Innovation: Enable the use of new authentication methods while maintaining security.
- Protect Consumers: Provide clear exemptions and oversight mechanisms to reduce fraud risk.
Key Provisions
1. Strong Customer Authentication (SCA)
- SCA must be applied to online payments, remote transactions, and any action through a remote channel that may imply a risk of fraud or abuse.
- SCA requires two or more authentication elements from the categories: knowledge, possession, and inheritance.
- An authentication code must be generated, and it must be resistant to forgery and not derivable from any of its elements.
- The code can only be used once for accessing the payment account, initiating a payment, or performing a remote action.
2. Exemptions from SCA
- Exemptions are allowed based on risk level, transaction amount, recurrence, and payment channel.
- Remote payments may be exempt under two conditions:
- Transaction Risk Analysis (TRA): If the payment is deemed low-risk based on pre-set fraud rates.
- Low-value payments (under EUR 30).
- Proximity payments (e.g., contactless payments at points of sale) are also exempt.
- Unattended terminals (e.g., toll gates) may be exempt if SCA is not feasible due to operational constraints.
- E-commerce transactions with low value are exempt, but thresholds are set more conservatively due to the lack of physical presence.
3. Security Requirements for SCA Elements
- Knowledge elements (e.g., PIN, password): Must have sufficient length and complexity.
- Possession elements (e.g., mobile apps, tokens): Must include algorithm specifications, key length, and information entropy.
- Inheritance elements (e.g., biometric data): Must have secure storage, encryption, and anti-tampering features.
- All elements must be independent to prevent a breach in one from compromising the others, especially when used on multi-purpose devices like smartphones.
4. Common and Secure Open Standards of Communication (CSC)
- Communication interfaces must be available for ASPSPs, PISPs, and AISPs to access payment account data.
- Screen scraping is prohibited after the transition period under PSD2.
- Interfaces must be secure, interoperable, and accessible using international or European standards.
- Availability and performance of interfaces must be at least as good as those used by end-users.
- Key performance indicators (KPIs) and service level targets must be transparent and published quarterly.
5. Audit and Monitoring Requirements
- Payment service providers must document, test, evaluate, and audit their SCA and CSC measures.
- Audits must be conducted by IT security and payment experts who are operationally independent.
- For exempt transactions, audits must be performed at least annually, and external audits are required during the first year and every three years thereafter.
- Fraud levels must be monitored and reported to both competent authorities and the EBA, enabling a review of fraud rates within 18 months of the RTS entering into force.
Key Information
- Scope: Applies to payment accounts only, not other types of accounts.
- Effective Date: Same as the application date of security measures under PSD2.
- Consultation Process: The EBA conducted public consultations and impact assessments before finalizing the standards.
- Oversight: The EBA will review and update the fraud rate thresholds every 18 months.
- Implementation Support: Payment service providers must test technical solutions at least three months before the RTS apply.
Conclusion
This delegated regulation provides detailed technical standards to implement Strong Customer Authentication and secure communication protocols in the EU payment services market. It ensures a balanced approach between security and user convenience, while promoting innovation and technological neutrality. The regulation also includes comprehensive audit and reporting requirements to ensure compliance and transparency.
试读结束,高清完整版pdf/doc/ppt,请点下载