Showing posts with label Reserve Bank of India. Show all posts
Showing posts with label Reserve Bank of India. Show all posts

Wednesday, January 11, 2012

Mobile Governance And E-Authentication In India

Recently World Bank granted a huge loan to India to ensure suitable policies for ensuring electronic delivery of services in India. The loan has been given under the title electronic delivery of public services development policy loan (DPL) project of India. Naturally, India has to start working in this direction to justify the loan.

For the time being we have no implementable electronic delivery of services policy of India though it may be in pipeline. Indian government is working in the direction of ensuring electronic delivery of services in India. In fact a legal framework titled electronic delivery of services bill 2011 (EDS Bill 2011) has also been proposed by Indian government.

While this is a good step taken by Indian government however the Bill has failed to achieve what was most importantly required from it. We have no legal framework for mandatory e-governance services in India and even the proposed EDS Bill 2011 failed to address this issue. As on date neither the information technology act 2000 (IT Act 2000) nor the EDS Bill 2011 provides a right in the hands of Indian citizens to claim e-governance as a matter of right. Thus, both IT Act 2000 and EDS Bill 2011 have little significance in the field of mandatory e-governance services in India.

As far as mobile governance policy in India the same is missing. We cannot rely much upon m-governance in India till we have a suitable m-governance policy of India. Further, authentication in an online environment plays a crucial role in fixing rights and liabilities through mobile transactions. There is no e-authentication policy of India that is operational at national level.

A good example of use of m-governance in India can be mobile banking. Recently Reserve Bank of India (RBI) removed the ceiling for mobile banking transactions in India. This is a good step but its efficacy is still debatable. When banks in India are not interested in maintaining mobile banking cyber security use of mobile banking may create many problems. Banks in India are not providing positive confirmations of NEFT transactions and expecting cyber security from them is unrealistic. Indian banks are also not following the guidelines of RBI prescribing mandatory cyber security requirements for banks of India.

Now the department of information technology (DIT) is formulating a policy that will enable citizens to authenticate their identities online to access various government services electronically, including through mobile phones. I hope DIT would keep all the abovementioned aspects in mind while formulating the proposed policy.

Tuesday, June 14, 2011

Spear Phishing Is A Potential Threat To Financial Institutions

Cyber security of banking and financial institutions has become very important these days. Recently the Citicorp confirmed the occurrence of cyber attack upon its bank’s network. In India as well ATM frauds, credit card frauds, online banking frauds, etc have increased a lot.

However, of all these cyber crimes, phishing is the most dangerous one for banking customers. If it is a case of spear phishing, it becomes deadly as the targeted person is specifically targeted for this purpose. The attack tactics are also specifically designed for the attack purposes.

The spear phishing cases appear so genuine that even tech savvy people are fooled into divulging sensitive information. Recently Reserve Bank of India (RBI) constituted a working group on information security that gave many good cyber security recommendations. However, the implementation of these recommendations has still not been achieved.

This gives lots of space for cyber crimes like spear phishing. Recent break-ins at high-profile targets like the International Monetary Fund (IMF) demonstrate just how proficient hackers have become at spear phishing.

Today's spear phishing is not only more prevalent but also much more technically proficient. They're not going for a password, anymore, they're getting people to install malware on their computers.

According to the reports the IMF suspected that a phishing attack against one of its workers planted malware on a machine, which was then presumably used to scout the network for data to steal. But the IMF incident was only the most recent in a series of specialized attacks this year aimed at targets from the Oak Ridge National Laboratory and the French foreign ministry to Google's Gmail.

Recent cyber attacks on multinational firms and institutions, from Google and Citigroup to the International Monetary Fund, have raised fears that governments and the private sector are ill-prepared to beat off hackers. The latest high-profile target was the U.S. Senate's website, which was hacked over the weekend.

However, as far as India is concerned, it has neither a good cyber security strategy nor a strong cyber law. Even cyber crisis management plan of India is practically missing. Indian banks must urgently revamp their cyber security so that interests of bank customers can be safeguarded.

Friday, June 3, 2011

RBI Recommended Constitution Of Secure Systems To Check Credit Card Frauds

Reserve Bank of India (RBI) has recently released the report of its working group on securing card present transaction. RBI has also prescribed cyber security due diligence standards for banks of India that must be implemented in a phased manner.

Despites these pro active steps, cyber security of banking sector of India is not upto the mark and ATM frauds, credit card frauds, internet banking frauds, etc are increasing in India. This is primarily due to the fact that banks in India are not following the recommendations of RBI.

ATM frauds and credit cards frauds cannot be tackled effectively till we use techno legal measures. Amid rising instances of debit and credit card frauds, an RBI panel has recommended that banks should put in place secure systems to check such cases within a year's time. All acquirers and issuers may put in place adequate fraud risk management systems and processes within 12 months, said the panel in its recommendations for an action plan to implement additional authentication for all card transactions.

For the benefit of debit card holders, it suggested that all transactions through such cards should have a PIN (Personal Identification Number) as an additional factor of authentication at point of sale (POS).

Further, mechanisms like designated time, microchip technology, biometric tokens, enhanced security, ATM monitoring, customised softwares, customer motivation, alerts, etc can be used to minimise and prevent ATM frauds in India. The banks must spread public awareness in this regard among the public so that these frauds can be prevented.

However, preventing ATM frauds is not the sole problem of banks alone. It is a big threat and it requires a coordinated and cooperative action on the part of the bank, customers and the law enforcement machinery. The ATM frauds not only cause financial loss to banks but they also undermine customers’ confidence in the use of ATMs. This would deter a greater use of ATM for monetary transactions. It is, therefore, in the interest of banks to prevent ATM frauds.

Report Of The RBI Working Group On Securing Card Present Transaction

The Reserve Bank of India (RBI) is taking cyber security of banking industry very seriously. RBI has been stressing that banks in India are required to ensure cyber due diligence and cyber security due diligence. However, the banks in India have still not done the needful in this regard even though the first quarterly report in this regard is due on 30th June, 2011.

RBI has now taken another significant step in this regard. RBI today placed on its website the Report of the Working Group on Securing Card Present Transaction. Comments of the Report may be emailed or forwarded by June 30, 2011 to the Chief General Manager, Department of Payment and Settlement System, Reserve Bank of India, Central Office, Mumbai-400001.

Card Present Transactions (at PoS and ATMs) constitute major proportion of card based transactions in the country. Currently, transactions using cards at PoS do not require additional authentication in majority of cards. Further most of the cards used in India, presently used magnetic stripe technology. Taking into account vulnerabilities involved, and to increase customer confidence may countries led by European Union have moved to Chip and Pin technology.

The RBI constituted a Working Group consisting of banks and card companies in March 2011 to look into all the related issues implementing the security of card transactions in India and suggesting a road map for migration. The Working Group submitted its report on June 2, 2011.

The Working Group arrived at the final recommendations based on the following critical factors:

(1) Putting in place a series of measures to strengthen the Payments infrastructure and ecosystem in the country,

(2) The need for a hybrid approach – the evolving nature of UIDAI, varying international and domestic trends. (Ed-The use of UID has been not approved till the suitability of same is well established).

(3) The need for a PIN (to ensure Lost and Stolen fraud is minimized) over and above protecting for skimming (Counterfeit). The choice of PIN though would be at the discretion of the Issuer.

(4) Important to ensure that both offline and online PINs are accepted by the EDC machines so that interoperability is ensured.

(5) Open, reloadable prepaid cards to be treated as “debit” equivalent as far as group recommendations as concerned.

(6) Differentiated implementation timelines for debit and credit cards.

(7) EMV Cards for international travelers to be prioritized

(8) Minimize throw-away costs and technology efforts for all stakeholders.

(9) Evaluation of UIDAI’s Aadhaar rollout as a strong alternative for domestic transactions 18 months from now based on:

(a) Aadhaar enrollment statistics for the existing cardholder base

(b) Proof of Aadhaar working as a second factor through pilots and roll outs

(c) Readiness of UIDAI to work with ATM, POS and device manufacturers to ensure ubiquity of biometric authentication both for existing machines and new deployments

(d) End to end transaction time including biometric authentication to comply with global standards for authentication

(e) Legal framework to be in place for ensuring non-repudiation of biometric authenticated transactions.

(f) Procedural guidelines and engagement model for banks to work with UIDAI for authentication, validation process in case of dispute through logs etc. to be put in place.
(g) UIDAI’s readiness to work with banks, associations and technology partners to make the payments ecosystem ready for a well tested, industry grade solution 18 months from now

(h) Evaluate the risk of being a “single point of failure”.

Perry4Law and Perry4Law Techno Legal Base (PTLB) welcome this initiative of RBI and congratulate the working group for coming out with good guidelines.

Thursday, June 2, 2011

RBI Recommendation On Information Security And Its Implementation In India

Reserve Bank of India (RBI) is taking cyber security of banks and financial institutions very seriously. Firstly, it constituted a Working Group on Information Security, Electronic Banking, Technology Risk Management and Cyber Frauds. Then RBI invited public comments and inputs on the report of this working group. After the inputs were received, RBI released the final version of this report.

RBI did not stop here. It has been punishing deviant banks that do not follow the law of the land in true letter and spirit. Recently, RBI imposed penalty upon 19 commercial banks for non compliance of prescribed standards. Similar dedication is also required regarding the recommendations issued by RBI for ensuring cyber security infrastructure by Indian banks.

The report issued by working group clearly stipulated that all banks would have to create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest. However, banks of India did not take these recommendations seriously. Further, Indian banks are also poor at formulating and implementing cyber security policies.

Recently the RBI has issued a notification for the implementation of the recommendations of its working group. The group examined various issues arising out of the use of information and communication technology (ICT) in banks and made its recommendations in nine broad areas. These areas are IT Governance, Information Security, IS Audit, IT Operations, IT Services Outsourcing, Cyber Fraud, Business Continuity Planning, Customer Awareness programmes and Legal aspects.

The report was placed on the RBI website on January 21, 2011. Subsequently, on February 1, 2011, views/comments of all stake-holders and the public at large on the Report were invited. After taking into account various responses, final guidelines in the respective areas as mentioned above are now being issued to banks for implementation.

The guidelines are not “one-size-fits-all” and the implementation of these recommendations need to be risk based and commensurate with the nature and scope of activities engaged by banks and the technology environment prevalent in the bank and the support rendered by technology to the business processes. Banks with extensive leverage of technology to support business processes would be expected to implement all the stipulations outlined in the circular.

For example, banks which do not offer transactional facilities in internet banking would not be required to implement specific measures for transactional internet banking facility outlined in the guidelines. Further, various instructions in “IT operations” chapter like detailed configuration management practices may not be necessary for banks that do not develop or maintain critical applications internally, though such practices may be expected from the external vendor providing such services.

The group had endeavored to generate self-contained and comprehensive guidelines. This has resulted in reiteration of certain guidelines already prescribed by RBI, for example, in certain areas relating to information security, outsourcing, BCP and IS Audit. However, there are certain guidelines like the checklist for computer audit prescribed in the year 2002 which on the whole cannot be ignored since the nature of coverage is different.

In the event of a direct conflict with an earlier guideline, the new guideline would be the basis for implementation by banks. Else, the relevant guidelines prescribed earlier would be an adjunct to the present guidelines issued herewith. It would be the endeavor of RBI to develop the enclosed guidelines as a Master Circular incorporating relevant old and new circulars on related subject areas in due course. In the event of any further clarifications in the matter, banks may approach RBI for further guidance.

The Group’s report was largely technology neutral except in exceptional circumstances where a specific technology/methodology may be suggested due to legal reasons or for enhanced security or for illustrative purpose. It is clarified that except where legally required, banks may consider any other equivalent/better and robust technology/methodology based on new developments after carrying out a diligent evaluation exercise.

Banks may have already implemented or implementing some or many of the requirements indicated in the circular. In order to provide focused project oriented approach towards implementation of guidelines, banks would be required to conduct a formal gap analysis between their current status and stipulations as laid out in the circular and put in place a time-bound action plan to address the gap and comply with the guidelines. However, banks need to ensure implementation of basic organizational framework and put in place policies and procedures which do not require extensive budgetary support, infrastructural or technology changes, by October 31, 2011. The rest of the guidelines need to be implemented within period of one year unless a longer time-frame is indicated in the circular.

There are also a few provisions which are recommendatory in nature, implementations of which are left to the discretion of banks.Given the fact the guidelines are fundamentally expected to enhance safety, security, efficiency in banking processes leading to benefits for banks and their customers, the progress in implementation of recommendations may be monitored by the top management on an ongoing basis and a review of the implementation status may be put up to the Board at quarterly intervals. Banks may also incorporate in their Annual Report from 2011-12 onwards broadly the measures taken in respect of various subject areas indicated in these guidelines.

The measures suggested for implementation cannot be static. Banks need to pro-actively create/fine-tune/modify their policies, procedures and technologies based on new developments and emerging concerns. Reserve Bank of India would review the progress in implementation of the guidelines in its Quarterly Discussions with banks and would examine comprehensively the efficacy of implementation of the guidelines commensurate with nature and scope of operations of individual banks from the next AFI cycle (for the period 2011-12) onwards.

Perry4Law and Perry4Law Techno Legal Base (PTLB) have been analysing these issues for long and they have been providing their suggestions in this regard. We believe that RBI must play a more pro active role in analysing whether its Policies and Recommendations are duly complied with. It seems the Recommendations of the Working Group constituted by RBI have still not been implemented. A “Progress Report” must be sought from Banks of India in this regard by RBI as soon as possible.

Tuesday, May 24, 2011

RBI Mandates Information Giving Of Strictures Passed Against Directors

Reserve Bank of India (RBI) has been streamlining the management of banking and financial institutions of India. It has taken many pro active steps in this regard. From prescribing a more stringent cyber due diligence policy for banks to mandating a requirement to appoint chief information officers (CIOs) and steering committee at the board level, RBI has taken many reformative steps.

In fact, cyber due diligence and banking due diligence could have prevented the recent Citibank fraud. The truth is that banks and financial institutions in India are not serious at all regarding cyber due diligence, cyber crimes, financial frauds and cyber security. Till now RBI’s guidelines on steering committee and CIOs have not been fulfilled by banks of India. Even RBI has recently imposed non compliance penalty upon 19 banks of India in another case.

However, despite all these actions, the higher management of banks have not been persuaded to take due diligence seriously. Now RBI has decided to change this position and it has asked banks to seek information from their directors on any adverse strictures passed by financial sector regulators against them.

This means if directors of banks are negligent in meeting various due diligence requirements, statutory obligations, cyber law and cyber security requirements, etc and any stricture is passed against them in this regard that would have to be reported.

RBI has also partially modified the format of “Declaration and Undertaking” prescribed for the purpose of conducting due diligence to determine the “fit and proper” status of directors. Banks should get information whether the director at any time come to the adverse notice of a regulator such as the Securities and Exchange Board of India (SEBI) and the Insurance and Regulatory Development Authority (IRDA) .

Henceforth, banks should obtain declaration and undertaking from existing directors and also persons to be appointed or elected as director. It is not necessary for a candidate to mention about orders and findings by regulators which have been later on reversed or set aside in toto. But they would have to make a mention of the same, in case the reversal and setting aside is on technical reasons like limitation or lack of jurisdiction and not on merit. If the order (of the regulator) is temporarily stayed and the appellate or court proceedings are pending, the same also should be mentioned, RBI added.

This is a good step in the right direction by RBI. This would bring not only discipline among the higher management but would also ensure statutory and due diligence compliances on their behalf.

Thursday, May 19, 2011

Mobile Banking In India Still Not Popular Says RBI

Electronic banking in India is still at the infancy stage. Whether it is electronic banking, Internet banking, mobile banking or any other form of e-banking, Indian banks have yet to take the lead. Further, in the context of mobile banking, mobile security in India is also emerging as a roadblock. This has also made mobile banking in India risky. Absence of encryption laws in India has further made the mobile security very weak in India.

Recently, G Gopalakrishna, the executive director of Reserve Bank of India (RBI) said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest. The idea is to use information technology to the maximum possible extent while maintaining the cyber security of banks.

However, banks in India are shying away from using technology assisted banking. Indian banks have shown little progress in the areas of mobile banking and cash at point-of-sales (PoS) terminals, even after nearly two years of the RBI allowing banks to run such facilities.

According to G. Padmanabhan, chief general manager, RBI, though the number of users who registered for mobile banking is substantial in absolute numbers, it is very low vis-à-vis the number of mobile phone subscribers. Implementation of some of the policy directives, which were emanated largely on the demands of stakeholders, has been far from satisfactory, he said.

Earlier this month, RBI had raised the limits on mobile-based transactions without end-to-end encryption from Rs 1,000 to Rs 5,000. The limits on mobile-based semi-closed prepaid instruments issued by non-banks were also raised from Rs 5,000 to Rs 50,000.

RBI has been taking many pro active reforms for the banking sector of India. RBI is not only ensuring strict compliance with various laws, regulations and norms but is also prescribing various policies and strategies for effective and secure banking in India. Further, deviant behaviour of banks is also punished by RBI from time to time. It seems RBI needs to be stricter regarding implementation of its policies and recommendations.