Committed to connecting the world

Girls in ICT

DFS Security Clinic - Addressing security risks to digital finance ecosystem

​​​​​​​​​​​​​​​​​

The International Telecommunication Union organized an online Digital Financial Services Security Clinic jointly with the East African Communications Organization (EACO) from 30 - 31 March 2022 titled: “Addressing security risks to digital finance ecosystem”. 

The main objectives of the DFS Security Clinic are to share the findings and recommendations from the FIGI Security Infrastructure and Trust working group for regulators and DFS providers with regards to addressing security challenges for digital finance. The event provided insights into security best practices for SIM swaps, mobile payment applications operating on USSD, STK and Android, methodology for testing security of mobile payment applications and addressing infrastructure vulnerabilities such as SS7.

Under the Financial Inclusion Global Initiative program (FIGI), the ITU set up a DFS Security Lab in November 2020 to work in collaboration with DFS regulators on adopting a common methodology to manage security risks and conduct security audit for DFS applications. The objectives of the ITU DFS security lab are as follows:
Key guidelines and recommendations for regulators on DFS security:
The intended audience for the DFS Security Clinic were IT security professionals and policymakers from the telecom/ICT regulators, DFS providers, Central Banks and Mobile Network Operators.

Note:  The time indicated below was in East Africa Time​ – UTC+3​​

Watch recording here:

​30 March 2022​​​ ​​

​​​

Programme


​​​Day 1: 30 March 2022

​​10:00 - 10:20
UTC+03

Opening and Welcome Remarks
10:20 - 11:50
UTC+03
​DFS security vulnerabilities: Infrastructure vulnerabilities and mitigation measures (Mobile Infrastructure vulnerabilities)

Telecom infrastructure vulnerabilities such as SS7 can be exploited by an intruder to intercept calls and SMSs, bypass billing, steal money from mobile money accounts, or affect mobile network operations. This session presented the main findings of the Security, Infrastructure and Trust Working Group on securing the infrastructure against SS7 vulnerabilities and threats.
Related Report:  
11:50 - 12:00
UTC+03
​Coffee Break
12:00 - 13:00
UTC+03
​DFS security vulnerabilities: USSD, STK and Android platform vulnerabilities

This session introduced the ITU DFS security lab and highlighted the vulnerabilities to USSD and STK and Android based applications. Threats like Man in the middle attacks that could impact digital financial services and the SIM jacker vulnerability in SIM Cards were discussed. The session provided​ and an overview of the security tests that can be undertaken in the DFS Security Lab at ITU. 
Related Reports: 

​​Day 2: 31 March 2022

10:00 - 11:15
UTC+03
DFS Security Assurance Framework 

This session discussed the DFS security assurance framework that can be implemented by DFS providers to better manage the risks and mitigate their impact.
​Related Report:
11:15 - 11:25
UTC+03
​​​Coffee Break
​​11:25 - 12:00
UTC+03
​DFS security audit guideline

The session covered how a Regulator or DFS provider can assess compliance with the minimum-security controls using the DFS audit guideline
Related Report:
12:00 - 13:00
UTC+03
​Implementing the DFS security recommendations and security audits for DFS.

An interactive session that focused at initiating the process to implement the DFS security recommendations and identifying ​the DFS Mobile Money applications that could be tested at the ITU DFS security lab.​