Mobile Payments Application Security Controls
Mobile Payments Application Security Controls: RBI Guidelines You Must Know
Blogs
Latest Insights and Articles
RBI Digital Payment Security Controls, Compliance, and Mobile App Security: a Growth Driver in the Mobile-First Digital Economy
The Indian banking sector has undergone significant transformation over the past decade. With over a billion mobile connections and rapidly growing digital adoption, Mobile Apps have become the preferred gateway...
Dynamic Code Loading
The rise of mobile banking has revolutionized the financial industry, offering unparalleled convenience to users worldwide.....
Clickjacking on Mobile Apps Exposed: How It Threatens Mobile Security and RASP Security Methods to Combat It
Clickjacking, also known as UI redressing, is a malicious technique used by attackers to trick users into clicking on something different...
RBI Mobile Payment Application Security Controls
With the increase in mobile app users & transactions & the corresponding increase in mobile app-related cyber threats, the requirement for minimum security control standards is the need of the hour to ensure the safety & security of users' data and funds. The Reserve Bank of India (RBI) has published guidelines to boost India's digital payments through enhanced security. Mobile payment application security controls have been mentioned prominently in the RBI master circular on the subject. Regulated Entities (RE) like commercial banks, payments banks, small finance banks, and credit card issuing NBFCs are advised to strengthen their mobile application payment ecosystem. Here are the key pointers from RBI that an RE must know:
- On detection of any anomalies or exceptions for which the mobile application was not programmed, the customer shall be directed to remove the current copy/ instance of the application and proceed with the installation of a new copy/ instance of the application. REs shall be able to verify the version of the mobile application before the transactions are enabled.
- Validation of the security and compatibility condition of the device/ operating system and the mobile application.
- Implement a code that checks if the device is rooted/jailbroken prior to the installation of the mobile application and disallows the mobile application to install / function if the phone is rooted/ jailbroken.
- Checksum of the currently active version of the application shall be hosted on a public platform so that users can verify the same.
- REs shall ensure device binding of the mobile application.
- For additional factor of authentication, REs may consider implementing alternatives to SMS-based OTP authentication mechanisms.
- Applications must be able to identify non – usage beyond a specified period, new network connections, or connections from unsecured networks like unsecured Wi-Fi connections & must implement appropriate authentication/ checks/ measures to perform transactions under those circumstances.
- The mobile application should not store/ retain sensitive personal/ consumer authentication information such as user IDs, passwords, keys, hashes, and hard-coded references on the device.
- Native encryption & decryption of local data storage (e.g., in temp files).
How AppProtectt helps?
AppProtectt, by Protectt.ai, is the ideal state-of-the-art RASP solution that provides end-to-end protection. The security solution assists the REs in handling with finesse the Mobile Payment Application Security Control aspect of the RBI’s master circular. AppProtectt ensures quick implementation and reduces TCO. AppProtectt by Protectt.ai injects comprehensive, 360-degree security with 100+ cyber security features that enable Runtime Application Self Protection (RASP) for advanced detection and mitigation of all types of mobile threats – from app tampering to being reverse engineered. We help your organization offload security concerns enabling you to focus on developing your main business logic.
As written by Sunita Handa – Principal Advisor, Protectt.ai
Security Build for Speed and Scale
At Protectt.ai, we are shaping the future of cybersecurity with cutting-edge innovations.