[フレーム] [フレーム]

Connecting the world and beyond

Digital Financial Services Security Clinic - Sierra Leone

Rollup Image
Page Content 10

The International Telecommunication Union is organising an online Digital Financial Services Security Clinic jointly with the National Telecommunications Commission (NATCOM), Sierra Leone from 26 to 27 September 2022 from 9h00 to 11h30 UTC.

The main objectives of the DFS Security Clinic are to share the findings and recommendations from the FIGI Security Infrastructure and Trust working group for regulators and DFS providers with regards to addressing security challenges for digital finance.

The event will provide insights into security best practices for SIM swaps, mobile payment applications operating on USSD, STK and Android, methodology for testing security of mobile payment applications and addressing infrastructure vulnerabilities such as SS7.

Target audience: The security clinic is intended for IT security professionals, security auditors and policymakers from the telecom/ICT regulator and Central Bank/Financial Regulator. ​​





Programme

Page Content 2

Day 1: 26 September 2022 (9:00 - 11:30)​​

9:00 - 9:10
(UTC)
​Opening Remarks
​9:10 - 10:15
(UTC)

DFS security vulnerabilities: USSD, STK and Android platform vulnerabilities

This session will introduce the ITU DFS security lab and highlight the vulnerabilities to USSD and STK and Android based applications. Threats like Man in the middle attacks that could impact digital financial services and the SIM jacker vulnerability in SIM Cards would be discussed. The session will also provide and an overview of the security tests that can be undertaken in the DFS Security Lab at ITU. 
  • "Introduction to ITU DFS security lab" Vijay Mauree, Programme Coordinator, TSB, ITU
  • "Android, USSD and STK tests" Arnold Kibuuka, Project Officer, TSB, ITU
Related Reports: 
  • ​​Security testing for USSD and STK based DFS applications EN | FR
  • Security audit of various DFS applications EN | FR
10:15 - 10:25​
(UTC)
Coffee Break
​10:25 - 11:30
(UTC)
​DFS Security Assurance Framework 

This session will discuss the DFS security assurance framework that can be implemented by DFS providers to better manage the risks and mitigate their impact.
  • Vijay Mauree, Programme Coordinator, TSB, ITU
Related Report:
  • DFS Security Assurance  Framework EN | FR

​Day 2: 27​ September 2022 (9:00 - 11:30)​

​9:00 - 10:00
(UTC)
​Summary of key guidelines for regulators on DFS security

This session will focus on the summary of the key ITU DFS recommendations on DFS security especially in issues of SS7, SIM swaps, SIM recycling and SIM vulnerabilities like SIM jacker that could be used to compromise DFS.
  • Arnold Kibuuka, Project Officer, TSB, ITU
​10:00 - 10:20
(UTC)
​DFS security audit guideline

The session also covered how a Regulator or DFS provider can assess compliance with the minimum-security controls using the DFS audit guideline. 
  • ​​Arnold Kibuuka, Project Officer, TSB, ITU
Related Report:
  • DFS security audit guideline EN | FR​
​10:20 - 10:30
(UTC)
​Coffee Break
​10:30 - 11:30
(UTC)
​Implementing the DFS security recommendations and security audits for DFS

An interactive session focused at initiating the process to implement the DFS security recommendations and identify the DFS Mobile Money applications that could be tested at the ITU DFS security lab. This session includes an exercise.

Page Content 3
Page Content 4
Page Content 5
Page Content 17
Page Content 18
Page Content 19
Page Content 20
Page Content 15
Page Content 6
​​​​.










Page Content 7
Page Content 8
Page Content 14
Page Content 16

AltStyle によって変換されたページ (->オリジナル) /