Overview
ISO/TS 12812-2:2017 - "Core banking - Mobile financial services - Part 2: Security and data protection for mobile financial services" - is a Technical Specification that defines a security management framework and minimum security requirements for Mobile Financial Services (MFS). It helps MFS providers, banks and system designers select and implement proportional security controls for mobile banking, mobile payments and electronic money systems while addressing data protection and regulatory obligations (e.g., AML/CFT).
Keywords: ISO/TS 12812-2:2017, mobile financial services security, MFS security, mobile banking security, data protection.
Key topics and technical requirements
- Security framework and three-layer model: organizational/process, application and infrastructure layers for managing MFS security.
- Minimum security requirements: remote access, transaction processing, protection of sensitive data, mobile device requirements and customer education.
- Device and platform security: guidance on mobile device hardening, wireless network protections, secure remote management (OTA), Trusted Execution Environments (TEE) and Secure Elements (SE).
- Cryptographic components: recommended cryptographic protocols and mechanisms for device authentication, secure financial message exchange and external authentication; requirements for cryptographic hardware and software modules.
- Payments-specific controls: security for proximate (contactless) and remote mobile payments, authentication, proof of consent and gateway processing.
- Data protection and privacy: legal compliance guidance, privacy assessment, recommendations for handling sensitive personal and financial data.
- Security evaluation and certification: guidance on cryptographic and software module evaluation, interoperability of certifications and TEE assessment.
- Supporting materials: informative annexes on risk analysis, Know-Your-Customer (KYC) implementations, cryptographic mechanisms and common vulnerabilities.
Keywords: cryptographic protocols, secure element, TEE, mobile proximate payments, mobile remote payments, KYC, AML/CFT.
Practical applications and who uses it
- Banks and mobile financial service providers (MFSPs) use this standard to design and document MFS security policies and to select appropriate security mechanisms.
- Security architects and developers apply device hardening, cryptographic and application-level guidance when building mobile banking apps, wallet services and payment gateways.
- Regulators and auditors reference the document for compliance expectations on data protection, AML/CFT and certification interoperability.
- Trusted Service Managers and certification bodies use the certification guidance to align interoperable assurance levels.
Practical benefits: reduces fraud risk, supports secure customer onboarding, enables interoperable certification approaches and helps align technical controls with legal/privacy requirements.
Related standards
- References and alignment with work from ISO/TC 68/SC 2 (financial services) and ISO/IEC JTC 1/SC 27 (IT security techniques).
- Part of the broader ISO 12812 series on Mobile Financial Services (see ISO 12812-1 and other related parts).
Keywords: ISO 12812 series, ISO security standards, mobile payments security.