Scope
This document provides security controls and implementation guides for the third party payment service providers (TPPSPs). These security controls consist of
- Security governance control group
- Cross-sectional control group
- Section-specific control group
- Audit and assurance control group In ISO/AWI TS 9546, the guidelines for security framework of information system of TPP services are covered, while this proposal deals with all the matters necessary for deployment and operation of the system which is made in compliance with the ISO/AWI TS 9546. So, this document deals with the overall security controls of TPPSPs, from developing and testing to installing, operating and auditing the system.
Purpose
This document provides guidelines for implementing security controls for TPP service providers.
Fintech-centered innovation is actively underway around the world right now. Third party payment service providers (TPPSPs) are proliferating, and the security of these institutions is becoming an important issue in financial field.
Furthermore, through TPP service, various financial services are being provided across borders between countries nowadays.
Since most of the information used by TPPSPs includes the customer's personally identifiable information (PII), the issue of the security of the TPPSP becomes even more important. In addition, in the case of small and medium-sized TPPSPs, the risk may increase because the system implementation may be relatively difficult. Thus, financial institutions that provide TPP services with customer information also need to review the security of those TPPSPs.
In accordance with these environmental requirements, TPPSPs establish and operate security controls on their own. This document intends to help enhance the security of TPP service by providing the security controls and implementation guidelines necessary for TPPSPs based on the global financial security experience.
This document is designed to provide a comprehensive set of internationally recognized best practices for TPPSPs in order to ensure that any necessary controls have not been omitted.
This document can be used as a guideline to establish, operate, maintain and improve the security of TPPSPs, can be used as a reference standard when TPPSPs evaluate their security posture, and can help them to verify reliability when connecting TPP services between countries.
Comment on proposal
Required form fields are indicated by an asterisk (*) character.