PSD2
PSD 2 relates to the payment’s legislation in Europe, which introduced new payment handling principles and was transposed into law within each EEA country. The Payment Service Directive currently only applies to payment in EEA currencies between accounts located with the EEA. The directive essentially deals with the following three issues:
- Establishes a new authorization regime for payment institutions
- Establishes transparency requirements to ensure that payment service providers give the required information to their customers relating to payments
- Sets out the rights and obligations of Payments service Providers and users, laying down rules on the movement of funds from the origin of payment through its execution, including dealing with disputes between users and providers. PSD2 controls relate to the following areas:
- Governance-Operational and security risk management framework
- Risk management and control models
- Outsourcing (Third Party Services)
- Risk assessments-Identification of functions, processes and assets
- Classification of functions, processes and assets
- Protection-Preventive security measures against identified operational and security risks
- Data and systems integrity and confidentiality
- Physical Access
- Access Control
- Detection-Continuous monitoring and detection of operations
- Monitoring and reporting of operational or security incidents
- Business continuity
- Scenario-based business continuity planning
- Testing of business continuity plans
- Crisis communication
- Testing of security measures
- Situational awareness and continuous learning – Threat landscape and situational awareness
- Training and security awareness programs
- Payment service user relationship management-Payment service user awareness on security risks and risk-mitigating actions
The service Kyte provides to its clients is to review their IT related controls or planned controls and see if adherence with the PSD2 regulations is in place.