The Reserve Bank of India (RBI) has published guidelines to boost India’s digital payments through enhanced security. Mobile payment application security controls have been mentioned prominently in the RBI master circular on the subject. Regulated Entities (RE) like commercial banks, payments banks, small finance banks, and credit card issuing NBFCs are advised to strengthen their mobile application payment ecosystem. Here are the key pointers from RBI that an RE must know:
I. On detection of any anomalies or exceptions for which the mobile application was not programmed, the customer shall be directed to remove the current copy/ instance of the application and proceed with the installation of a new copy/ instance of the application. REs shall be able to verify the version of the mobile application before the transactions are enabled.
II. Validation of the security and compatibility condition of the device/ operating system and the mobile application.
III. Implement a code that checks if the device is rooted/jailbroken prior to the installation of the mobile application and disallows the mobile application to install / function if the phone is rooted/ jailbroken.
IV. Checksum of the currently active version of the application shall be hosted on a public platform so that users can verify the same.
V. REs shall ensure device binding of the mobile application.
VI. For the additional factor of authentication, REs may consider implementing alternatives to SMS-based OTP authentication mechanisms.
VII. Applications must be able to identify non-usage beyond a specified period, new network connections, or connections from unsecured networks like unsecured Wi-Fi connections and must implement appropriate authentication/ checks/ measures to perform transactions under those circumstances.
VIII. The mobile application should not store/ retain sensitive personal/ consumer authentication information such as user IDs, passwords, keys, hashes, and hard-coded references on the device.
IX. Native encryption & decryption of local data storage (e.g., in temp files).
X. Design anti-malware capabilities into mobile apps.
XI. Mobile applications should be secured from SQL injection type of vulnerabilities.
XII. REs shall conduct security testing, including review of source code, Vulnerability Assessment (VA), and Penetration Testing (PT) of their digital payment applications to assure that the application is secure for putting through transactions while preserving confidentiality and integrity of the data that is stored and transmitted.
XIII. Secure download/install of the mobile app after baseline requirements are met.
XIV. Deactivate older versions of the application in a phased but timely manner. Maintain a single version of the mobile apps, excluding the overlap period while phasing out the older version.
XV. Application sandbox/containerization.
XVI. Mobile app to have the ability to identify remote access applications (to the extent possible) and prohibit remote login access to the mobile app.
How AppProtectt helps?
AppProtectt, by Protectt.ai, is the ideal state-of-the-art RASP solution that provides end-to-end protection. The security solution assists the REs in handling with finesse the Mobile Payment Application Security Control aspect of the RBI’s master circular.
Powered by Artificial Intelligence (AI) and Machine Learning (ML), AppProtectt is the ultimate solution to protect and safeguard the payment or banking application from malicious cyber-attacks and unwanted intrusions.
AppProtectt ensures quick implementation and reduces TCO. AppProtectt by Protectt.ai injects comprehensive, 360-degree security with 40+ cyber security features that enable Runtime Application Self Protection (RASP) for advanced detection and mitigation of all types of mobile threats - from app tampering to being reverse engineered. We help your organization offload security concerns enabling you to focus on developing your main business logic.
As written by Sunita Handa - Principal Advisor, Protectt.ai