RBI Guidelines on Digital Payment Security
RBI Guidelines on Digital Payment Security
on Digital Payment
Security Controls
W: [Link]
E: info@[Link]
US Tel: +1-415-513-5261 | SG Tel: +65-3129-0397 |
IN Tel: +91 73045 57744
An ISO27001 Certified Company, CERT-IN Empanelled, PCI QSA | USA. SINGAPORE. INDIA. UK. MIDDLE EAST. CANADA.
Topics Covered Introduction
Sr. Titles Pg.
No. No.
01. Introduction 02
02. Key Highlights of Master Direction 03 Given the dynamic digital landscape and skyrocket
-ing online payment transactions, the industry has witne
-ssed huge spike in cybercrimes. Addressing the growing
03. Applicability of the Master Direction 03 need for stringent digital payment security controls in the industr-
y, RBI recently issued a comprehensive Master Direction for organiza-
tions to follow. The Master Direction works as a guideline for organiza-
04. Key Areas Covered in the Master Direction 04 tions to improve the security, and governance of payment gateways,
wallets, and other digital payment transactions that they deal with on a
day-to-day basis.
05. Digital Payment Security Controls in a Glance 06
The guidelines will help organizations establish a robust digital pay-
ment system and implement effective standards of security controls
06. Chapter II 07 for online payments. With this Master Direction, it is now expected that
entities like banks and NBFC’s emphasise on their quality of gover-
07. Chapter III 11 nance, risk management, and internal security controls for establishing
a safer digital payment environment. The issued guidelines specify
security protocols to be implemented in mobile applications, internet
08. Chapter IV 11 banking, and card payments by scheduled commercial banks, small
financial and payment banks, and card issuing institutes.
09. Chapter V 12 The Master Direction is issued at crucial time when the financial indus-
try is in the mid of its rapid digital transformation and evolving security
landscape. The guidelines issued is a technological and applica-
10. Going Ahead with the Master Direction 14 tion-based framework that improves the digital payment environment
Plan of Action & Key Recommendat- for customers to securely embrace the evolving digitization of the finan-
ions for Businesses cial industry. While this initiative is seen as a positive move to towards
strengthening the regulations and supervision, it is yet to be seen as to
how the enforcement of the security framework takes it course.
[Link] 02
It provides a comprehensive gover-
Key Highlights of the Master nance structure and minimum-securi-
ty control standards for systems like
Direction internet banking, mobile banking,
card payment, etc.
It contains requirements for strong governance, implementa- Typically speaking the issued guide-
tion, and monitoring of security control standards by sched- lines will also affect the business
uled commercial banks, small financial and payment banks, models of several payment gateways.
and card issuing institutes. The directions will have implications
Applicability on third-party payment applications
The Master Directions will also have implications on the such as Google Pay, PhonePe, etc.
third-party payment applications such as Google Pay, Pho- of the Master
nePe, etc. Timeline
Direction The guidelines is set to come into full
RBI’s Master Direction covers a diverse area, including import- effect from August 2021 (6 months
ant security controls concerning the Governance and Manage- post-release of the guidelines)
ment of Security Risks, Generic Security Controls, Application
Security Life Cycle (ASLC), Authentication Framework, Fraud
Risk Management, Reconciliation Mechanism, Customer Pro-
Objective of the Master
tection, Awareness and Grievance Redressal Mechanism relat- Direction
ed to Internet Banking, Mobile Payments Application Security
Controls, and Card Payments Security. The guideline aims is to
strengthen the regulations and
supervision of non-cash, digital
It will come into effect on August which is six months from the
payments in the industry.
day they are placed on the official website of the Reserve Bank
of India (RBI). The timeline would be with immediate effect
Improve the security, and gov-
from thereon.
ernance of payment gateways,
wallets, and other digital pay-
ment transactions.
[Link] 03
The guideline aims is to strengthen the regulations
and supervision of non-cash, digital payments in
the industry.
Key Areas Covered in
Improve the security, and governance of payment
the RBI’s Master Direction
gateways, wallets, and other digital payment trans-
actions. The Master Direction is a detailed 21-page dossier issued by the RBI
which specifies security protocols to be implemented in mobile applica-
Aims to ensure regulated entities prioritize and
focus on the quality of governance, risk manage- The Master Direction is a detailed 21-page dossier
ment, and internal security controls for building a issued by the RBI which specifies security pro
safer digital payment environment. tocols to be implemented in mobile appli
cations, internet banking, and card
payments by scheduled com-
Strengthen and improve the internal grievance mercial banks, small finan-
redress mechanism with enhanced disclosures on cial and payment banks,
customer complaints. and card issuing institutes.
The guide line includes spe-
Effective implementation and monitoring of certain cifications on diverse areas,
minimum standards on security controls. including important Securi-
ty Controls concerning:-
Overall, aim is to ensure secure online payment
transactions and prevent incidents of a data
breach, theft, or data leakage of sensitive customer
information.
[Link] 04
Governance and Management of Security Risks
Authentication Framework
Reconciliation Mechanism
Customer Protection
[Link] 05
Digital Payment Security Controls
CHAPTER II
Governance & Management of Security Risks
Policy for Digital Risk Controls for Risk Capacity Management Plan Data Recovery
Payment Products & Management & Monitoring the Assessment System & Procedure
Services Governance Ac�vi�es of the
Program Third Party
Authen�ca�on Framework
Mul�-factor Authen�ca�on Authentica�on A�empts
System Fraud Management
Reconcilia�on Mechanism
Incident Response
[Link] 06
Minimal customer service disruption with high availability of
CHAPTER II systems/ channels.
of Security Risk Adequate and appropriate review mechanism followed by swift cor-
rective action.
ing customer data in the payment ecosystem and ensure compliance 3. Implementation of Firewalls &
with applicable PCI standards in each of the systems. DDoS Protection - Regulated Entities are
required to implement Web Application Firewall
5. Capacity Management Plan - Entities must have in place (WAF) and DDoS mitigation techniques to secure
appropriate Capacity Management Plan to ensure the established digital the digital payment products and services.
payment infrastructure is robust, scalable and resilient to meet the grow-
ing demands. 4. Renewal of Digital Certificates -
Digital certificates used in the ecosystem should
6. Data Recovery System & Procedure - Entities should be renewed on time by the Regulated Entities.
have procedures to periodically test systems and applications that
account data back-ups, and recovery pertaining to digital products and 5. Logging and Monitoring Activi-
services to ensure there is no loss of transactions or audit-trails. ties - Mobile Application and Internet Banking
Application should have effective logging and
Generic Security Controls monitoring capabilities to track user activity, secu-
rity changes and identify anomalous behavior
1. Communication Protocols - Entities should adhere to a and transactions.
[Link] 08
Application Security Lifecycle Authentication Framework
2. Threat Modeling Approach - The Regulated entities must 2. Authentication Attempts - Regulated Entities should set
adopt and incorporate a threat modelling approach into their policies, maximum number of failed log-in or authentication attempts after which
processes, guidelines and procedures during the course of Application access to the digital payment product/ service shall be blocked.
Lifecycle Management.
Fraud Risk Management
3. Security Testing - Entities must conduct various security testing
including review of source code, Vulnerability Assessment (VA) and Pene- 1. System Alerts - Entities must have in place parameterized and
tration Testing (PT) of their digital payment applications at a regular inter- monitored alert systems to alert the customers in case of failed authenti-
val to ensure that the application is secure. cation, fund transfers, cash withdrawals, payments through electronic
modes, adding new beneficiaries etc.
4. Activity Monitoring Mechanism - Entities must imple-
ment a mechanism to actively monitor non-genuine/ unauthorized/ mali- 2. Fraud Analysis Mechanism - Fraud analysis mechanism
cious Payment Applications on app stores and webs and respond accord- must be in place to identify fraud occurrence and determine mechanism
ingly to bring them down. to prevent such frauds.
5. Security controls for Digital Payment Applica- 3. Train staff - Regular training should be provided to staff in the
tions - Considering various OWASP standards, security and data pro- fraud control function to educate and train them with skills and areas of
tection guidelines in ISO 12812, threat catalogues and guides developed expertise in-
by NIST, entities must accordingly deploy the best Security controls for
digital payment applications.
[Link] 09
Fraud control tools and their usage;
[Link] 10
2. Controls for Mobile Applications - Entities must
CHAPTER III implement the below mentioned controls for their mobile applica-
tions -
Internet Banking Security Device policy enforcement;
Controls Application secure download/ install;
1. Secure Internet Banking Websites - Entitles must Deactivating older application versions in a phased but time
ensure securing the internet banking websites against authentica- bound manner and maintain only one version of the mobile
tion-related attacks such as the DOS and brute force attacks by imple-
application on a platform/ operating system;
ment additional levels of authentication such as adaptive authentica- Storage of Customer Data;
tion, strong CAPTCHA (preferably with anti-bot features) with serv-
Device or Application Encryption;
er-side validation, etc. Further, measures to be taken to prevent DNS
cache poisoning attacks and for secure handling of cookies. Ensuring minimal data collection/ app permissions;
CHAPTER V
Card Payment Security
1. Follow PCI Standards - Regulated Entities are
expected to follow various PCI Standards applicable to them
which includes -
PCI-PIN (secure management, processing, and transmission
of personal identification number (PIN) data);
6. Robust Surveillance/
Monitoring of Card Transactions-
Entities must institute a mechanism to
monitor breaches, if any, on a 24x7 basis,
including weekends, long holidays and have
in place a robust incident response
mechanism to mitigate the fraud loss, on
account of suspicious transactions.
7. Transaction Limits -
Entities must have in place transaction limits for
domestic and international transactions at Card, BIN
as well as at the Regulated Entities levels, set at the card
network switch itself.
[Link] 14
About Us
VISTA lnfoSec is a Global Cyber Security
Consulting firm offering exceptional Cyber
Security Consulting & Audit Service, Regulat-
ory & Compliance Consulting Services and
Infrastructure Advisory Solutions. With stro-
ng industrial presence since 2004, we
have been serving clients from across the
world with our robust, end-to-end security
services and solutions. We are a 100% vendor neut-
ral company with strict no outsourcing policy and built on
our core values of strict code of ethics, transparency and
professionalism.
[Link]
OUR SERVICES OFFERINGS
[Link]
OUR OFFICES
VISTA INFOSEC LLC VISTA INFOS EC PTE. LTD VISTA INFOSEC PVT. LTD 6 AMBER COURT
24007 VENTURA BLVD 20 COLLYER QUAY 001, NORTH WING, GOLDSMITH CLOSE
SUITE 285 #09-01 2ND FLOOR, HARROW, GREATER LONDON
CALABASAS CA 91302 20 COLLYER QUAY NEOSHINE HOUSE, UNITED KINGDOM
SINGAPORE (049319) LINK ROAD, ANDHERI (W) HA20EZ
MUMBAI - 400053
[Link]
Webinar : RBI’s Master Direction
on Digital Payment Security
Controls
CONTACT US
W: [Link] | E: info@[Link]