AIRLINK 72.59 Increased By ▲ 3.39 (4.9%)
BOP 4.99 Increased By ▲ 0.09 (1.84%)
CNERGY 4.29 Increased By ▲ 0.03 (0.7%)
DFML 31.71 Increased By ▲ 0.46 (1.47%)
DGKC 80.90 Increased By ▲ 3.65 (4.72%)
FCCL 21.42 Increased By ▲ 1.42 (7.1%)
FFBL 35.19 Increased By ▲ 0.19 (0.54%)
FFL 9.33 Increased By ▲ 0.21 (2.3%)
GGL 9.82 Increased By ▲ 0.02 (0.2%)
HBL 112.40 Decreased By ▼ -0.36 (-0.32%)
HUBC 136.50 Increased By ▲ 3.46 (2.6%)
HUMNL 7.14 Increased By ▲ 0.19 (2.73%)
KEL 4.35 Increased By ▲ 0.12 (2.84%)
KOSM 4.35 Increased By ▲ 0.10 (2.35%)
MLCF 37.67 Increased By ▲ 1.07 (2.92%)
OGDC 137.75 Increased By ▲ 4.88 (3.67%)
PAEL 23.41 Increased By ▲ 0.77 (3.4%)
PIAA 24.55 Increased By ▲ 0.35 (1.45%)
PIBTL 6.63 Increased By ▲ 0.17 (2.63%)
PPL 125.05 Increased By ▲ 8.75 (7.52%)
PRL 26.99 Increased By ▲ 1.09 (4.21%)
PTC 13.32 Increased By ▲ 0.24 (1.83%)
SEARL 52.70 Increased By ▲ 0.70 (1.35%)
SNGP 70.80 Increased By ▲ 3.20 (4.73%)
SSGC 10.54 No Change ▼ 0.00 (0%)
TELE 8.33 Increased By ▲ 0.05 (0.6%)
TPLP 10.95 Increased By ▲ 0.15 (1.39%)
TRG 60.60 Increased By ▲ 1.31 (2.21%)
UNITY 25.10 Decreased By ▼ -0.03 (-0.12%)
WTL 1.28 Increased By ▲ 0.01 (0.79%)
BR100 7,546 Increased By 137.4 (1.85%)
BR30 24,809 Increased By 772.4 (3.21%)
KSE100 71,902 Increased By 1235.2 (1.75%)
KSE30 23,595 Increased By 371 (1.6%)

KARACHI: The State Bank of Pakistan (SBP) has issued comprehensive security guidelines for mobile payment applications to ensure confidentiality and integrity of customer data and availability of app services in a secure manner.

According to the SBP, the objective of the “guidelines” is to provide baseline security requirements for app owners in order to ensure confidentiality and integrity of customer data and availability of services in a secure manner when developing payment applications.

App owners will use the guidelines for the architecture, design, development and deployment of mobile payment apps and their associated environment that the consumers use for payment transactions.

The requirements of the guidelines will be applicable to all Financial Institutions, authorised Payment Systems Operators/Payment Service Providers (PSOs/PSPs), Electronic Money Institutions (EMI) and any other SBP regulated/licensed/authorised institutions, which are developing, procuring, operating, facilitating, or providing digital financial services through mobile apps to end users.

Mobile payment applications have become an alternative payment channel for a growing number of users and, accordingly, SBP-regulated entities have been offering innovative products and services through the applications. Consequently, opportunities for fraudsters to exploit vulnerabilities in mobile apps and defraud the customers have also increased manifold.

In line with international standards and best practices, the SBP has developed Mobile App Security Guidelines, providing baseline security requirements for app owners in order to ensure confidentiality and integrity of customer data and availability of services in a secure manner, when developing payment applications for mobile or other smart devices.

The central bank has advised that app owners must ensure that their mobile apps and associated infrastructure become compliant with the requirements of these guidelines latest by December 31, 2022.

The convenience, availability and acceptance of mobile app-based payment services have phenomenally increased the adoption of these apps by customers. Data storage, inter-app communication, proper usage of cryptography, Application Programming Interfaces or APIs, and secure network communication are only some of the major areas to consider during mobile app development lifecycle.

The protection of sensitive data and payment transactional information is crucial to mobile app-based payment security.

The SBP aims to provide baseline security requirements for the mobile apps, broadly covering the areas of data storage, network communication with endpoints, authentication and authorisations, interaction with mobile platforms, code quality and exploit mitigation and anti-tampering, etc.

As per the guidelines, app owners will develop a policy governing mobile apps business objectives, standards, compliance, guidelines, controls, responsibilities, and liabilities. App owners may formulate this policy separately or include the same as part of their overall digital channels development policy.

As a principle, the policy shall achieve a balance among security of apps, convenience and performance. The policy shall at least be revised annually and/or when a significant change is made in the environment.

App owners will be required to ensure that sensitive information is not stored in a shared store segment with other apps on mobile devices. It is recommended that only the device internal storage is utilised, which is virtually sandboxed per app or preferably in a container app without meddling with other applications or security settings of the mobile devices.

App owners will also ensure that confidential data is deleted from caches and memory after it is used and/or uninstalled. Further, app owners shall ensure that mobile apps erase/expire all application-specific sensitive data stored in all temporary and permanent memories of the device during logoff or on unexpected termination of app instance.

Copyright Business Recorder, 2022

Comments

Comments are closed.