Committed to connecting the world

DFS Security Clinic for Ethiopia

​​​​​​

The International Telecommunication Union (ITU)​ and the United Nations Capital ​Development Fund (UNCDF)​ jointly organised a Webinar on the DFS Security Clinic for Ethiopia on 19-20 March 2024. It took place from 08:00 to 10:30 CET on both days. The Security Clinic provided deep-dive sessions to share insights, recommendations, and lessons from the FIGI Security Infrastructure and Trust working group with DFS and telco regulators.​

The main objectives of the Security Clinic on DFS security was to share findings and lessons learned from the FIGI Security Infrastructure and Trust working group. These findings assisted regulators and providers in:

Target Audience: The the DFS Security Clinic was targeted at representatives from telecommunications regulators, national cybersecurity agencies, Central Banks, Financial Service Providers, Banks, ministries, service and IT security solution providers.




Programme


Day 1:  19 March 2024 (UTC+ 03)
​10:00 - 10:10
Welcome remarks:
​10:10 - 11:10
​Introduction to ITU DFS ​​​Security Lab and Knowledge Sharing Platform 

This session provided a general overview of the ITU DFS Security  Lab and the assistance that it provides to developing countries to adopt the DFS Security recommendations. This session also introduced the ITU knowledge sharing platform. The ITU DFS Security Knowledge Sharing Platform was designed to foster collaboration among regulators and other stakeholders in the development and implementation of security guidelines and best practices for Digital Financial Services (DFS).

​​​Speaker:  Vijay Mauree, Programme Coordinator, TSB, ITUPresentation​ ]
​11:10 - 11:20
Break
​11:20 - 12:20
ITU DFS security recommendations

This session presented the  security measures from the ITU DFS security recommendations to be adopted by DFS regulators and providers  to secure the telecom infrastructure and payment system infrastructure. In particular, the following recommendations were presented:
Speaker:  Arnold Kibuuka, Project Officer, TSB, ITU [ Presentation ​]

​​ ​​Day 2:  20 March 2024 (UTC+ 03)

​10:00 - 11:00
DFS application security best practices and DFS Application Security testing 

Following up on the ITU DFS security recommendations on Day 1, this session continued the elaboration of the security control measures to the application layer. As DFS cyber threats continue to evolve, protecting applications from vulnerabilities becomes paramount. The DFS application security best practices included in the ITU DFS security recommendations can be adopted by regulators to establish a minimum security baseline for DFS providers to build in security at the design phase. This session explored the security tests that are conducted in the ITU DFS security lab to verify compliance of mobile payment apps against the Security best practices. 
Speaker:  Arnold Kibuuka, Project Officer, TSB, ITU [ Presentation​ ]
​11:00 - 11:10
​Break
​11:10 - 11:45
DFS Security Assurance Framework 

This session discussed the DFS security assurance framework that can be implemented by DFS providers to better manage the risks and mitigate their impact.

Related Reports:
​​​Speaker:  Vijay Mauree, Programme Coordinator, TSB, ITU [ Presentation ]
11:45- 12:30​DFS Cyber Resilience Framework 

This session introduced the ITU DFS cyber resilience toolkit for regulators to safeguard critical digital finance infrastructure. 

Speaker:  Arnold Kibuuka, Project Officer, TSB, ITU​ [ Presentation ]