The
International Telecommunication Union (ITU) organized an
online Digital Financial Services Security Clinic jointly with The Gambia Public Utilities Regulatory Authority (PURA) from
5 - 6 June 2023, fully virtual.
The main objectives of the DFS Security Clinic were to share the findings and recommendations from the FIGI Security Infrastructure and Trust working group for regulators and DFS providers with regards to addressing security challenges for digital finance.
The event provided insights into security best practices for SIM swaps, mobile payment applications operating on USSD, STK and Android, methodology for testing security of mobile payment applications and addressing infrastructure vulnerabilities such as SS7. The participants of the event learned:
- The different infrastructure and application vulnerabilities within the DFS ecosystem.
- The DFS security assurance framework, security governance, and how to manage security risks in the DFS ecosystem.
- How to mitigate DFS threats and perform continuous assessments on the security of DFS to ensure applicable controls are in place to mitigate threats and vulnerabilities.
- The DFS security recommendations for regulators on SS7 vulnerabilities, SIM swap fraud, and application security best practices.
Target audience: The security clinic was intended for IT security professionals, security auditors from the telecom/ICT regulator, Central Bank/Financial Regulator, and DFS providers.