Third-party ATM switch ASPs to comply with cybersecurity controls: RBI

The RBI-regulated entities have to amend their contracts at the earliest or at the time of renewal, in any case not later than March 31, 2020

ATM
Photo: Shutterstock
Subrata Panda Mumbai
2 min read Last Updated : Jan 01 2020 | 1:31 AM IST
The Reserve Bank of India (RBI) on Tuesday said all RBI-regulated entities entering into a contract with third-party automated teller machine (ATM) switch application service providers (ASPs) need to comply with cybersecurity controls prescribed by the central bank. They also have to give access to the RBI for on-site or off-site supervision.

The RBI-regulated entities have to amend their contracts at the earliest or at the time of renewal, in any case not later than March 31, 2020.

In the fifth bi-monthly monetary policy statement of the RBI in December, the central bank had said that a number of commercial banks, urban co-operative banks (UCBs), and other regulated entities are dependent upon third-party ASPs for shared services for ATM switch applications.

Since these service providers also have exposure to the payment system landscape and are, therefore, exposed to the associated cyber threats, the RBI decided that certain baseline cybersecurity controls shall be mandated by the regulated entities in their contractual agreements with these service providers.

The guidelines would require implementation of several measures to strengthen the process of deployment and changes in application software in the ecosystem, continuous surveillance, implementation of controls on storage, processing and transmission of sensitive data, building capacity for forensic examination, and making the incident response mechanism more robust.

Meanwhile, the RBI has also recommended a comprehensive cybersecurity framework for UCBs, based on their digital depth and interconnectedness with the payment system landscape, digital products offered by them, and assessment of cybersecurity risk.

Among the requirements, the RBI has said UCBs have to put in place a two-factor authentication for accessing their core banking system (CBS) and applications connecting the CBS — with the second factor being dynamic in nature.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :ATMs in IndiaATM normsUrban cooperative banks

Next Story