TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
News Archive

Tips For Mobile Payments

by Msecadm4921

With the increased use of mobile devices to pay for goods and services, traditional wallets with cash and credit cards could one day be obsolete. A new paper from the IT and information security body ISACA titled, โ€œMobile Payments: Risk, Security and Assurance Issues,โ€ examines this growing trend and offers guidance on managing risk and increasing security. Mobile Payments: Risk, Security and Assurance Issues.

A study from Juniper Research found that the value of mobile payments for digital and physical goods, money transfers and other transactions will reach almost US $630 billion by 2014. The Mobile Payments white paper, available as a free download from ISACA, a nonprofit global professional association, identifies consumer benefits, including the speed and convenience of not carrying cash and credit cards, the consolidation of many cards and an enhanced layer of security. Enterprises benefit by reaching more consumers, reducing the amount of stored data needed to meet compliance requirements, improving transaction security and fraud detection, and engaging in location-based marketing (geo-marketing).

โ€œMobile payments offer many benefits, but we also need proactive planning and measures to manage risk, which can include anything from theft of identities and services; loss of revenue, brand reputation and customer information; and money laundering and terrorist funding,โ€ said Nikolaos Zacharopoulos, CISA, CISSP, IT auditor for Geniki Bank, Greece, and chair of ISACAโ€™s project development team for the white paper. โ€œThis guidance identifies the risk types and the countermeasures that should be in place to mitigate them.โ€

The Mobile Payments white paper provides advice for enterprises:
โ€ขBuild robust controls into the planning process.
โ€ขEnsure that transactions are carried out only by the authorized person.
โ€ขIdentify the data that are considered personal and sensitive, and ensure it is protected.
โ€ขEnsure that third parties involved have robust security governance in place.
โ€ขPay specific attention to the originating point of a mobile transactionโ€”the customer device and the user

โ€œSecurity will be a major driver for the adoption of mobile payments, as trust plays a very important role when the customer decides to use a new payment tool,โ€ said Zacharopoulos. โ€œWhile more regulation in the mobile payment ecosystem is developing, it is important that enterprises proceed with care so they can offer consumers the conveniences of mobile payments as well as the security and privacy necessary.โ€

โ€œMobile paying allows for companies more revenues if applied in a smart manner, meaning if consumers can use mobile devices to select the product or service easily and pay without additional devices but pay via the bill of their mobile operatorโ€, said Marc Vael, chief audit executive at Smals and director of ISACA (and chair of the Knowledge Board). โ€œUnfortunately, we see in some cases that mobile payment solutions does not function at all since the security requirements insist on mandatory authentication evidence via additional authentication devices, which undermines the whole concept of mobility. ISACA clearly recommends in this paper a proper approach to promote mobile payment taking into account security and risk managementโ€.

For more information on mobile payments, download the free ISACA white paper from www.isaca.org/mobilepayments. Further ISACA guidance on mobile devices is available from the Business Model for Information Security (BMIS), COBIT the Securing Mobile Devices white paper and the Mobile Computing Security Audit Assurance Program.