Committed to connecting the world

Security Clinic on Security of Digital Financial Services

​​​​​​​​​​​​​​​​​​​​​​​​​​​​​​ 27- 29 October 2021


The main objectives of the Security Clinics on DFS security were to share findings and lessons learned from the FIGI Security Infrastructure and Trust working group.  The findings assisted the regulators and providers to:
 The security clinics were  intended for IT security professionals and policymakers from the telecom/ICT regulator, DFS provider and Central Bank.

The sessions addressed the following areas of focus: 
​Target audience: This event was for DFS and Telco regulators in Zimbabwe

​​

Programme

​​​

 ​​Day 1:  27 October 2021

​​10:00 - 10:15
CEST​
Welcome Address
​​10:15 -11:15
CEST
​DFS security vulnerabilities: Infrastructure vulnerabilities and mitigation measures (Mobile Infrastructure vulnerabilities)

Telecom infrastructure vulnerabilities such as SS7 can be exploited by an intruder to intercept calls and SMSs, bypass billing, steal money from mobile money accounts, or affect mobile network operations.  This session  presented the main findings of the Security, Infrastructure and Trust Working Group on securing the infrastructure against SS7 vulnerabilities and threats. 

Panellists:
Related Report

​​ ​​Day 2: 28 October 2021

10:00 - 11:15
CEST
DFS Security Assurance Framework 

This session discussed the DFS security assurance framework that can be implemented by DFS providers to better manage the risks and mitigate their impact.

Panellists:
​Related Reports:
​​11:15- 12:30
CEST
​DFS Security Vulnerabilities: USSD, STK and Android Platform Vulnerabilities

This session introduced the ITU DFS security lab and highlighted the vulnerabilities to USSD and STK and Android based applications. Threats like Man in the middle attacks that could impact digital financial services and the SIM jacker vulnerability in SIM Cards would be discussed. The session also provided and an overview of the security tests that can be undertaken in the DFS Security Lab at ITU. 

​Related Reports:

​Day 3: 29 October 2021​

​​10:00 - 11:00
CEST​​
​Implementing the DFS security assurance framework and security audit for DFS.

This was a hands-on session focusing on initiating the process to implement the DFS security assurance framework in Zimbabwe and identify the DFS Mobile Money applications that could be tested in the ITU DFS security lab. POTRAZ and RBZ team should familiarize themselves with the DFS security assurance framework prior to the session. A follow-up session was held afterwards to assess the implementation.