We use cookies to give you the best experience and to help improve our website

Find out what cookies we use and how to disable them

ISO/NP 18960 Security controls and implementation guidance for third party payment service providers

Scope

This document provides security controls and implementation guides for the third party payment service providers (TPPSPs). These security controls consist of

- Security governance control group

- Cross-sectional control group

- Section-specific control group

- Audit and assurance control group In ISO/AWI TS 9546, the guidelines for security framework of information system of TPP services are covered, while this proposal deals with all the matters necessary for deployment and operation of the system which is made in compliance with the ISO/AWI TS 9546. So, this document deals with the overall security controls of TPPSPs, from developing and testing to installing, operating and auditing the system.

Purpose

This document provides guidelines for implementing security controls for TPP service providers.

Fintech-centered innovation is actively underway around the world right now. Third party payment service providers (TPPSPs) are proliferating, and the security of these institutions is becoming an important issue in financial field.

Furthermore, through TPP service, various financial services are being provided across borders between countries nowadays. 

Since most of the information used by TPPSPs includes the customer's personally identifiable information (PII), the issue of the security of the TPPSP becomes even more important. In addition, in the case of small and medium-sized TPPSPs, the risk may increase because the system implementation may be relatively difficult. Thus, financial institutions that provide TPP services with customer information also need to review the security of those TPPSPs. 

In accordance with these environmental requirements, TPPSPs establish and operate security controls on their own. This document intends to help enhance the security of TPP service by providing the security controls and implementation guidelines necessary for TPPSPs based on the global financial security experience.

This document is designed to provide a comprehensive set of internationally recognized best practices for TPPSPs in order to ensure that any necessary controls have not been omitted.

This document can be used as a guideline to establish, operate, maintain and improve the security of TPPSPs, can be used as a reference standard when TPPSPs evaluate their security posture, and can help them to verify reliability when connecting TPP services between countries.

Comment on proposal

Required form fields are indicated by an asterisk (*) character.


Please email further comments to: debbie.stead@bsigroup.com

Follow standard

You are now following this standard. Weekly digest emails will be sent to update you on the following activities:

You can manage your follow preferences from your Account. Please check your mailbox junk folder if you don't receive the weekly email.

Unfollow standard

You have successfully unsubscribed from weekly updates for this standard.

Error