2014年-ECB欧洲央行_Assessment_guide_for_the_security_of_internet_payments_60页_1mb
报告摘要
ASSESSMENT GUIDE FOR THE SECURITY OF INTERNET PAYMENTS - SUMMARY
I. INTRODUCTION
This document is an assessment guide for the security of internet payments, developed by the European Forum on the Security of Retail Payments (SecuRe Pay) based on the Recommendations for the security of internet payments published by the European Central Bank (ECB) in January 2013. It is intended for supervisory and oversight authority staff in EU/EEA Member States to ensure harmonised and efficient assessments of compliance with the recommendations.
Key Objectives
- To enhance consumer trust in internet payments by reducing fraud.
- To provide a common minimum standard for internet payment services, regardless of the access device.
- To allow for flexibility in implementation, acknowledging technological innovation and evolving threats.
Scope
- Applies to Payment Service Providers (PSPs) and Governance Authorities (GAs) of payment schemes.
- Excludes other internet services (e.g., e-brokerage, online contracts), non-browser-based mobile payments, payments via SMS, third-party access to payment accounts, and clearing and settlement.
Core Definitions
- Strong customer authentication is defined as a procedure using two or more elements from the categories of knowledge, ownership, and inheritance (e.g., passwords, tokens, biometrics).
- Sensitive payment data includes:
- Data enabling payment initiation (e.g., IBAN, PAN).
- Data used for authentication (e.g., passwords, phone numbers).
- Data used for ordering payment instruments (e.g., postal address, email).
- Parameters and software that affect the ability to verify transactions or control accounts (e.g., black/white lists, customer-defined limits).
II. RECOMMENDATIONS
1. General Control and Security Environment
Recommendation 1: Governance
- KC 1.1: Security policies must be formally documented, regularly reviewed, and approved by senior management. They should define security objectives and risk appetite.
- KC 1.2: The policy must define roles and responsibilities, including a risk management function with a direct reporting line to the board.
- BP 1.1: Security policy could be in a dedicated document for clarity.
Recommendation 2: Risk Assessment
- KC 2.1: PSPs and payment schemes must conduct detailed risk assessments, considering:
- Technology solutions used.
- Outsourced services.
- Customers' technical environments.
- KC 2.2: Risk assessments should lead to formal implementation plans, including interim measures, milestones, and contingency plans.
- KC 2.3: Risk assessments should address protection of sensitive payment data, including identification processes and access policies.
- KC 2.4: Periodic reviews of risk scenarios and security measures are required after major incidents, infrastructure changes, or new threats. A general annual review is also mandated.
2. Specific Control and Security Measures for Internet Payments
Recommendation 6: Initial Customer Identification and Information
- Ensures proper customer identification and information provision to prevent fraud.
Recommendation 7: Strong Customer Authentication
- Requires two or more authentication factors.
- Authentication elements must be mutually independent and include at least one non-reusable and non-replicable factor.
- BP 7.1: Guidance on strong authentication is provided in the Recommendations.
Recommendation 8: Enrolment for Authentication Tools
- Defines enrolment processes for authentication tools and software.
- Ensures that these tools are securely delivered to customers.
Recommendation 9: Log-in Attempts, Session Timeout, and Authentication Validity
- Establishes controls on log-in attempts, session timeouts, and authentication validity to prevent unauthorised access.
Recommendation 10: Transaction Monitoring
- Encourages ongoing monitoring of transactions to detect fraud or anomalies.
Recommendation 11: Protection of Sensitive Payment Data
- Requires encryption, secure storage, and protection of data used for payment initiation and authentication.
3. Customer Awareness, Education, and Communication
Recommendation 12: Customer Education and Communication
- Promotes customer awareness and education on internet payment security.
Recommendation 13: Notifications and Setting of Limits
- Encourages customer notifications and limit setting for transactions.
Recommendation 14: Access to Payment Status
- Ensures customer access to information on the status of payment initiation and execution.
III. IMPLEMENTATION
- Comply or explain principle: PSPs and GAs must comply with the recommendations or justify deviations.
- Supporting documents include:
- Security policy
- Risk assessment reports
- Incident management policies
- Complaints management policies
- Contracts
- Assessment questions are provided to ensure harmonised interpretation, but are not prescriptive.
- Electronic submission of answers and background documentation is encouraged.
IV. GLOSSARY OF TERMS
- PSP: Payment Service Provider
- GA: Governance Authority
- KC: Key Consideration
- BP: Best Practice
- PSD: Payment Services Directive
- ISO: International Organization for Standardization
- SQL injection: A method of attacking data in a database
- Cross-site scripting: A type of malicious code injection
- Buffer overflow: An overflow of data in a buffer
V. KEY TAKEAWAYS
- The guide outlines minimum security expectations for internet payment services.
- It encourages flexibility in implementation due to technological changes and evolving threats.
- Strong authentication is a central requirement, with mutual independence of factors and non-reusability of at least one factor.
- Risk assessment and incident monitoring are core components of the security framework.
- Customer awareness and communication are essential to ensure secure payment practices.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载