What are measures for authentication of online transaction for credit institutions and foreign bank branches in Vietnam from July 1, 2024?
What are measures for authentication of online transaction for credit institutions and foreign bank branches in Vietnam from July 1, 2024?
According to Appendix 02 issued together with Decision 2345/QD-NHNN in 2023, the measures for authentication of online transaction include:
What are measures for authentication of online transaction for credit institutions and foreign bank branches in Vietnam from July 1, 2024? (Image from the internet)
What do customers need to authenticate when accessing Internet Banking services in Vietnam?
According to Article 9 of Circular 35/2016/TT-NHNN (amended and supplemented by Clauses 7 and 8, Article 1 of Circular 35/2018/TT-NHNN), authentication in Internet Banking transactions is regulated as follows:
Customer authentication for accessing Internet Banking services
1. Customers accessing and using Internet Banking services must be authenticated at least by a username and a secret key that meets the following requirements:
a) The username must be at least six characters long and cannot use completely identical or sequential characters in the alphabet or numerical order;
b) The secret key must be at least six characters long, including letters and numbers, containing uppercase and lowercase letters or special characters. The secret key's validity period is a maximum of 12 months.
c) For accessing the Internet Banking system via a browser, the unit must have measures against automatic login.
2. The Internet Banking application software must have a function that requires customers to change the secret key immediately upon the first login; lock the access account if the secret key is entered incorrectly consecutively beyond the limit set by the unit. The unit will unlock the account only upon customer request and must authenticate the customer before unlocking the account to prevent fraud and impersonation.
Thus, based on the above provisions, customers accessing Internet Banking services must authenticate:
- Username: must be at least six characters long; cannot completely use identical or sequential characters in the alphabet or numerical order;
- Secret key: must be at least six characters long, including letters and numbers, containing uppercase and lowercase letters or special characters. The secret key's validity period is a maximum of 12 months.
For accessing the Internet Banking system via a browser, the unit must have measures against automatic login.
What are the general principles of ensuring safety and security of information technology systems for providing Internet Banking services in Vietnam?
According to Article 3 of Circular 35/2016/TT-NHNN (amended by Clause 1, Article 1 of Circular 35/2018/TT-NHNN), the general principles of ensuring the safety and security of information technology systems for providing Internet Banking services are as follows:
- The Internet Banking system is an important information system according to the State Bank's regulations on information system safety in banking activities.
- Ensure the confidentiality and integrity of customer information; ensure the availability of the Internet Banking system to provide continuous service.
- Customer transaction information is assessed for risk levels based on customer groups, transaction types, transaction limits, and based on that provide appropriate authentication measures for customers to choose. The authentication measures must meet:
+ Apply at least multi-factor authentication when changing customer identification information;
+ Apply authentication measures for each customer group, transaction type, transaction limit according to the decision of the Governor of the State Bank from time to time;
+ For multi-step transactions, apply at least authentication at the final approval step.
- Conduct periodic annual security evaluations and assessments of the Internet Banking system.
- Regularly identify risks, risk-causing threats, and promptly determine the causes of risks, promptly take preventive measures, control, and handle risks in providing banking services on the Internet.
- Information technology infrastructure equipment for providing Internet Banking services must have clear copyright, origin, and provenance.
For equipment nearing end-of-life and will no longer be supported by the manufacturer, the unit must have an upgrade or replacement plan according to the manufacturer's notice to ensure the infrastructure equipment can install the latest software version.
Decision 2345/QD-NHNN in 2023 is effective from July 1, 2024.
LawNet