AIRLINK 73.00 Decreased By ▼ -2.16 (-2.87%)
BOP 5.35 Decreased By ▼ -0.10 (-1.83%)
CNERGY 4.31 Decreased By ▼ -0.08 (-1.82%)
DFML 28.55 Increased By ▲ 0.91 (3.29%)
DGKC 74.29 Increased By ▲ 2.29 (3.18%)
FCCL 20.35 Increased By ▲ 0.06 (0.3%)
FFBL 30.90 Decreased By ▼ -0.15 (-0.48%)
FFL 10.06 Increased By ▲ 0.09 (0.9%)
GGL 10.39 Increased By ▲ 0.12 (1.17%)
HBL 115.97 Increased By ▲ 0.97 (0.84%)
HUBC 132.20 Increased By ▲ 0.75 (0.57%)
HUMNL 6.68 Decreased By ▼ -0.19 (-2.77%)
KEL 4.03 Decreased By ▼ -0.17 (-4.05%)
KOSM 4.60 Decreased By ▼ -0.17 (-3.56%)
MLCF 38.54 Increased By ▲ 1.46 (3.94%)
OGDC 133.85 Decreased By ▼ -1.60 (-1.18%)
PAEL 23.83 Increased By ▲ 0.43 (1.84%)
PIAA 27.13 Decreased By ▼ -0.18 (-0.66%)
PIBTL 6.76 Increased By ▲ 0.16 (2.42%)
PPL 112.80 Decreased By ▼ -0.36 (-0.32%)
PRL 28.16 Decreased By ▼ -0.59 (-2.05%)
PTC 14.89 Decreased By ▼ -0.61 (-3.94%)
SEARL 56.42 Decreased By ▼ -0.91 (-1.59%)
SNGP 65.80 Decreased By ▼ -1.19 (-1.78%)
SSGC 11.01 Decreased By ▼ -0.16 (-1.43%)
TELE 9.02 Decreased By ▼ -0.12 (-1.31%)
TPLP 11.90 Decreased By ▼ -0.15 (-1.24%)
TRG 69.10 Decreased By ▼ -1.29 (-1.83%)
UNITY 23.71 Increased By ▲ 0.06 (0.25%)
WTL 1.33 Decreased By ▼ -0.01 (-0.75%)
BR100 7,434 Decreased By -20.9 (-0.28%)
BR30 24,206 Decreased By -44.4 (-0.18%)
KSE100 71,359 Decreased By -74.1 (-0.1%)
KSE30 23,567 Increased By 0.5 (0%)

KARACHI: The State Bank of Pakistan (SBP) has issued comprehensive security guidelines for mobile payment applications to ensure confidentiality and integrity of customer data and availability of app services in a secure manner.

According to the SBP, the objective of the “guidelines” is to provide baseline security requirements for app owners in order to ensure confidentiality and integrity of customer data and availability of services in a secure manner when developing payment applications.

App owners will use the guidelines for the architecture, design, development and deployment of mobile payment apps and their associated environment that the consumers use for payment transactions.

The requirements of the guidelines will be applicable to all Financial Institutions, authorised Payment Systems Operators/Payment Service Providers (PSOs/PSPs), Electronic Money Institutions (EMI) and any other SBP regulated/licensed/authorised institutions, which are developing, procuring, operating, facilitating, or providing digital financial services through mobile apps to end users.

Mobile payment applications have become an alternative payment channel for a growing number of users and, accordingly, SBP-regulated entities have been offering innovative products and services through the applications. Consequently, opportunities for fraudsters to exploit vulnerabilities in mobile apps and defraud the customers have also increased manifold.

In line with international standards and best practices, the SBP has developed Mobile App Security Guidelines, providing baseline security requirements for app owners in order to ensure confidentiality and integrity of customer data and availability of services in a secure manner, when developing payment applications for mobile or other smart devices.

The central bank has advised that app owners must ensure that their mobile apps and associated infrastructure become compliant with the requirements of these guidelines latest by December 31, 2022.

The convenience, availability and acceptance of mobile app-based payment services have phenomenally increased the adoption of these apps by customers. Data storage, inter-app communication, proper usage of cryptography, Application Programming Interfaces or APIs, and secure network communication are only some of the major areas to consider during mobile app development lifecycle.

The protection of sensitive data and payment transactional information is crucial to mobile app-based payment security.

The SBP aims to provide baseline security requirements for the mobile apps, broadly covering the areas of data storage, network communication with endpoints, authentication and authorisations, interaction with mobile platforms, code quality and exploit mitigation and anti-tampering, etc.

As per the guidelines, app owners will develop a policy governing mobile apps business objectives, standards, compliance, guidelines, controls, responsibilities, and liabilities. App owners may formulate this policy separately or include the same as part of their overall digital channels development policy.

As a principle, the policy shall achieve a balance among security of apps, convenience and performance. The policy shall at least be revised annually and/or when a significant change is made in the environment.

App owners will be required to ensure that sensitive information is not stored in a shared store segment with other apps on mobile devices. It is recommended that only the device internal storage is utilised, which is virtually sandboxed per app or preferably in a container app without meddling with other applications or security settings of the mobile devices.

App owners will also ensure that confidential data is deleted from caches and memory after it is used and/or uninstalled. Further, app owners shall ensure that mobile apps erase/expire all application-specific sensitive data stored in all temporary and permanent memories of the device during logoff or on unexpected termination of app instance.

Copyright Business Recorder, 2022

Comments

Comments are closed.