Công văn 758/CNTH8 2016 đảm bảo an toàn thông tin với Hệ thống thanh toán quốc tế SWIFT
- Tổng hợp lại tất cả các quy định pháp luật còn hiệu lực áp dụng từ văn bản gốc và các văn bản sửa đổi, bổ sung, đính chính…
- Khách hàng chỉ cần xem Nội dung MIX, có thể nắm bắt toàn bộ quy định pháp luật hiện hành còn áp dụng, cho dù văn bản gốc đã qua nhiều lần chỉnh sửa, bổ sung.
thuộc tính Công văn 758/CNTH8
Cơ quan ban hành: | Cục Công nghệ tin học |
Số công báo: | Đã biết Vui lòng đăng nhập tài khoản gói Tiêu chuẩn hoặc Nâng cao để xem Số công báo. Nếu chưa có tài khoản Quý khách đăng ký tại đây! |
Số hiệu: | 758/CNTH8 |
Ngày đăng công báo: | Đang cập nhật |
Loại văn bản: | Công văn |
Người ký: | Phan Thái Dũng |
Ngày ban hành: | 10/06/2016 |
Ngày hết hiệu lực: | Đang cập nhật |
Áp dụng: | |
Tình trạng hiệu lực: | Đã biết Vui lòng đăng nhập tài khoản gói Tiêu chuẩn hoặc Nâng cao để xem Tình trạng hiệu lực. Nếu chưa có tài khoản Quý khách đăng ký tại đây! |
Lĩnh vực: | Tài chính-Ngân hàng, Khoa học-Công nghệ |
tải Công văn 758/CNTH8
NGÂN HÀNG NHÀ NƯỚC VIỆT NAM CỤC CÔNG NGHỆ TIN HỌC ------- Số: 758/CNTH8 V/v: Tăng cường, đảm bảo an toàn thông tin đối với Hệ thống SWIFT | CỘNG HÒA XÃ HỘI CHỦ NGHĨA VIỆT NAM Độc lập - Tự do - Hạnh phúc --------------- Hà Nội, ngày 10 tháng 06 năm 2016 |
Kính gửi: | - Các tổ chức tín dụng; - Các chi nhánh ngân hàng nước ngoài. |
Nơi nhận: - Như trên; - Cục trưởng (để b/c); - Lưu CNTH, CNTH8. | KT. CỤC TRƯỞNG PHÓ CỤC TRƯỞNG Phan Thái Dũng |
THE STATE BANK OF VIETNAM
THE INFORMATION TECHNOLOGY DEPARTMENT
Official Dispatch No. 758/CNTH8dated June 10, 2016 of the State Bank of Vietnam on strengthening and ensuring information security of SWIFT system
To: | -Credit institutions; |
In the past period, the fact that cybercrime offenders attacking banks financial systems, especially SWIFT international payment system (hereinafter referred to as SWIFT system), has happened in a complicated manner, caused adverse impacts and influences on operations of banking system.
TheInformation Technology Department, affiliated to the State Bank of Vietnam, upon the inspection and assessment, finds that the management, operation and use of SWIFT System are facing certain risks. To be specific:
-Risks in processes of SWIFT payment operations: processes ofrelevant operations in SWIFT System are notformulated or have been available but the enforcement thereof is not strict without the supervision of compliance thereof. For example: lending user account; a SWIFT member only buys 1 concurrent user license or fails to make appropriate arrangement of personnel resulting in that the separation between personnel creating messages and that verifying existing messages is not ensured; conducting irregular comparison and control of messages or failing to carry out careful control, etc.
-Risks in integration and development of SWIFT System;
+ A number of institutions enter into lease contracts with SWIFT payment service providers but fail to take measures for managing and supervising safety and security of such services.
+ A number of institutions carry out the integration of other systems (such as core banking system) into SWIFT System by using connectivity solutions which cannot ensure the authentication resulting in fraudulent messages sent over SWIFT System from a malware or another operational computer.
- Risks inconfigurationof SWIFT System:
+ There is no limitation on the number of host computers which can be connected to SWIFT Network (SWIFTNet).
+ Fail to set up prior authorization before messages are sent overSWIFTNet.
+ Financial institution still remains a Relationship ManagementApplication (RMA)with institutions who are no longer its counterparties (counterparty’s BIC).
-Authentication of login in SWIFT system and prior authorization of messages: Presently, almost users log in on SWIFT system by using a private username and corresponding password. Therefore, if an institution fails to create a strong password for a user account or application privileged account, it is unable to manage and control the operating system and database of SWIFT System in an appropriate manner resulting in account information leaked and hackers may take advantage of this situation to access swift system for conducting fraudulent transactions and changing database, deleting and/or removing any transactions from the hacked account history, installing illegal software or changing the system configuration, etc.
+ Failing to set up timeout period for SWIFT System or the existing timeout period is so long.
-Risks in human factors: Administrators, operators and users are not disseminated and provided with operational process and training courses in awareness of information security.
-Other risks:
+ Failing to monitor or limit the number of servers performing connection operations to SWIFT System.
+ Servers performing connection operations to SWIFT System may access to Internet or be connected with unsecure network areas; users may install new software and modified software at the level of operating system; failing to install anti-malware software; failing to monitor the connection withperipheralequipment.
TheInformation Technology Department, affiliated to the State Bank of Vietnam, upon the above-mentioned risk analysis, requests any institutions that are using SWIFT payment system to perform the following duties:
-Adopt processes and regulations for operations of SWIFT system in compliance with the following contents:
+ Regulations on a transaction:
•With regard to manual transactions, a payment transaction is conducted with the participation of at least 3 persons: message creator, verifier and tracker;
•With regard to transactions automatically generated on the core banking system and transmitted to SWIFT System, the Information Technology Department, affiliated to the State Bank of Vietnam, encourages involved institutions to set up the step of verification on SWIFT system before messages are sent toSWIFTNet.If involved institutions set up automatic transmission without going through the verification on SWIFT system, they must check the entire process, infrastructure and assume responsibility for any risks incurred thereof (if any).
+ Checking and comparing information in order to timely discover the variation of information of message between SWIFT System and core banking system of a given institution; or between the SWIFT System of a given institution with its counterparties.
+ Carrying out assignment and determination of duties of administrator, operators and users of SWIFT system.
+ Establishing a division in charge of inspecting and reporting of the compliance with prevailing processes and regulations relating to SWIFT system.
-If an institution is usingSWIFT payment services provided by a service provider under lease contract, it should make plan for move the SWIFT system to its base for managing and adopting measures for ensuring information security.
-Doing research and implementing solutions for connectivity between other systems and SWIFT system in order to ensure security, authentication and integrity of a message.
-Checking and optimizing the configuration of SWIFT System for the purpose of improving the security of information in administration and operation of SWIFT system.
-Limitingthe number of host computersin SWIFT Systemwhich can be connected to SWIFTNet.
+ Evaluating SWIFT System according toKB tip 5020788 - Security Guidance for Allianceand carrying out remedial measures against discovered risks as well as research and implementation of SWIFT’s security guidelines(referred athttps://www2.swift.com/uhbonline/books/protected/en_uk/aa_7_1_10_sec_guid/index.htm)
+ Improving the strength in login verification: setting up strength of passwords of user accounts; setting up appropriate timeout period; doing research on OTP or PKI integration for verification of login or transactions.
+ Checking user accounts and managing and/or connecting such accounts to the system for ensuring users’ correct rights, removing all unused accounts, changing passwords of the system’s default accounts and adopting appropriate measures for managing and protecting privileged accounts such as accounts ofProfile SuperKey, SuperVisor, MsgEntry, MsgPartner; Administrator/Rootof the operating system; accounts for database administration, etc.
+ Checking RMAs and removing unused RMAs.
-Checking and optimizing configuration of relevant systems or adopting security solutions or other services for improving SWIFT system’s information security:
+ Monitoring and limiting the number of servers performing connection operations to SWIFT System and adopting information security measures for these servers. To be specific: locating these servers in a separate secured network area; installing and updating hotfixes and anti-malware software on a regular basis; limiting the internet access; determining rights to user accounts in order that users can use appropriate operational applications and cannot install new software or modified software at the level of operating system; limiting the user ofperipheralequipment, etc.
+ Doing research on implementing measures for detecting and preventing fraudulent transactions on SWIFT System; analysis and warning on abnormal transactions on the basis of history of SWIFT System and that of relevant systems.
-Administrators, operators and users of SWIFT System should be provided with training courses in information security in order to how to prevent risks such as discovery of malicious emails and websites, and aware of their responsibility for management and use of user accounts and sensitive information.
TheInformation Technology Departmentaffiliated to the State Bank of Vietnam hereby requests involved institutions to implement this document.
For further details, please contact the Information Security Division -Information Technology Department, No. 64 Nguyen Chi Thanh Street, Dong Da District, Hanoi City, telephone:04.38354775, fax: 04.38358135, email: cnth8@sbv.gov.vn./.
Sincerely./.
For the General Director
The Deputy General Director
Phan Thai Dung
Vui lòng Đăng nhập tài khoản gói Nâng cao để xem đầy đủ bản dịch.
Chưa có tài khoản? Đăng ký tại đây
Lược đồ
Vui lòng Đăng nhập tài khoản gói Tiêu chuẩn hoặc Nâng cao để xem Lược đồ.
Chưa có tài khoản? Đăng ký tại đây
Chưa có tài khoản? Đăng ký tại đây