Only a few debit cards were misused, says RBI
The Reserve Bank of India has clarified that
the number of debit cards misused in the recent revelation of fraud was ‘few’.
Background:
Recently, India’s largest bank, State Bank of
India, said it had blocked close to 6 lakh debit cards following a
malware-related security breach in a non-SBI ATM network. Several other banks,
such as Axis Bank, HDFC Bank and ICICI Bank, too have admitted being hit by
similar cyber attacks — forcing Indian banks to either replace or request users
to change the security codes of as many as 3.2 million debit cards over the
last two months.- The issue is currently being investigated by an
approved forensic auditor, under PCI-DSS (Payment Card Industry-Data
Security Standard) framework.
What is PCI DSS?
The Payment Card Industry Data Security
Standard (PCI DSS) is a widely accepted set of policies and procedures intended
to optimize the security of credit, debit and cash card transactions and
protect cardholders against misuse of their personal information.
- The PCI DSS was created jointly in 2004 by four
major credit-card companies: Visa, MasterCard, Discover and American
Express.
The PCI DSS specifies and elaborates on six
major objectives. These include:
- A secure network must be maintained in which transactions
can be conducted. This requirement involves the use of firewalls that are
robust enough to be effective without causing undue inconvenience to
cardholders or vendors. In addition, authentication data such as personal
identification numbers (PINs) and passwords must not involve defaults
supplied by the vendors. Customers should be able to conveniently and
frequently change such data.
- Cardholder information must be protected wherever it
is stored. Repositories with vital data such as dates of birth, mothers’
maiden names, Social Security numbers, phone numbers and mailing addresses
should be secure against hacking. When cardholder data is transmitted
through public networks, that data must be encrypted in an effective way.
- Systems should be protected against the activities
of malicious hackers by using frequently updated anti-virus software,
anti-spyware programs, and other anti-malware solutions. All applications
should be free of bugs and vulnerabilities that might open the door to
exploits in which cardholder data could be stolen or altered. Patches
offered by software and operating system (OS) vendors should be regularly
installed to ensure the highest possible level of vulnerability
management.
- Access to system information and operations should be
restricted and controlled. Cardholders should not have to provide
information to businesses unless those businesses must know that
information to protect themselves and effectively carry out a transaction.
Every person who uses a computer in the system must be assigned a unique
and confidential identification name or number. Cardholder data should be
protected physically as well as electronically.
- Networks must be constantly monitored and regularly
tested to ensure that all security measures and processes are in place,
are functioning properly, and are kept up-do-date.
- A formal information security policy must be defined, maintained, and followed at all times and by all participating entities. Enforcement measures such as audits and penalties for non-compliance may be necessary.