Description
Applicability
Applicability of guideline
The issued guideline is applicable on all payment gateways may also adopt technology-related recommendation as follow:
Security-related recommendation:
Information Security Governance: In order to recognize risk exposures with remedial steps and residual risks, the entities shall carry out a comprehensive security risk assessment of their people, IT, business process environment, etc. This may be an internal security audit or an external security audit carried out by an independent security auditor or an impaneled auditor of CERT.
Data security standards: Data security standards and best practices, like PCI-DSS, PA-DSS, latest encryption standards, protection of transport channels, etc.
Reporting of security incidents: The entities shall report to RBI security incidents/cardholder data breaches within the specified timeframe. Monthly records of information security incidents shall be sent to RBI with root cause analysis and preventive measures undertaken.
Merchant Onboarding: The agencies conduct a thorough safety review during the merchant onboarding process to ensure that the merchants conform to these minimum baseline security controls.
Cyber Security Audit and Reports: The entities shall carry out and submit to the IT Committee quarterly internal and annual external audit reports; bi-annual Vulnerability Assessment / Penetration Test (VAPT) reports; PCI-DSS including Attestation of Compliance (AOC) and Report of Compliance (ROC) compliance report with observations noted if any including corrective/preventive actions planned with action closure date; inventory of applications which store or process or transmit customer sensitive data; PA-DSS compliance status of payment applications which stores or processes cardholder data.
Others provided in annexure 2 of guideline
Other recommendations
The credentials of the customer card shall not be kept in the merchant's database or server.
No choice shall be given for ATM PIN as an authentication factor for card transactions that are not present.
Instructions concerning the handling of payment system data shall apply as applicable to PSOs.
All refunds shall be made to the original payment system unless the consumer has expressly agreed to reimburse an alternate mode.
Quick Details
Reviews
To write a review, you must login first.
From the Same Seller