RBI

RBI warns banks on vulnerability of ATMs running on windows XP or unsupported version of operating system

RBI warns banks on vulnerability of ATMs running on windows XP or unsupported version of operating system and non-implementation of other security measures

Control measures for ATMs – Timeline for compliance

RBI has expressed concerns over the ATMs running on Windows XP and/or other unsupported operating systems.

In a recent communication made to all Scheduled Commercial Banks, Small Finance Banks and Payment Banks and  white-Label ATM Operators, the RBI has expressed displeasure over slow progress on the part of the banks in addressing these issues.

RBI has frawn attention to the vulnerability arising from the ATMs operating on unsupported version of operating system and non-implementation of other security measures which could potentially affect the interests of the banks’ customers adversely, apart from impinging on the image of the bank.

Banks and White-Label ATM Operators have been advised to initiate immediate action in this regard and implement the following control measures as per the prescribed timelines indicated there against:

Sr. No. Control Measures for the ATMs To be completed by
a. Implement security measures such as BIOS password, disabling USB ports, disabling auto-run facility, applying the latest patches of operating system and other softwares, terminal security solution, time-based admin access, etc. August 2018
b. Implement anti-skimming and whitelisting solution. March 2019
c. Upgrade all the ATMs with supported versions of operating system. Such upgrades shall be carried out in a phased manner to ensure that in respect of the existing ATMs running on unsupported versions of operating system,  
i. Not less than 25% of them shall be upgraded by September 2018
ii. Not less than 50% of them shall be upgraded by December 2018
iii. Not less than 75% of them shall be upgraded by March 2019
iv. All of them shall be upgraded by June 2019

Share

Recent Posts

  • Income Tax

CIT notice u/s 263 quashed as AO rightly took DVO value of property as actual sale price

CIT Revision notice u/s 263 quashed as the Assessing Officer rightly taken DVO value of property sold as actual sale…

6 hours ago
  • GST

Extension of timeline for implementation of Ship To GSTIN & Voluntary Closure of E-Way Bill functionalities

Extension of timeline for implementation of mandatory "Ship To GSTIN" and Voluntary Closure of E-Way Bill functionalities GSTN Advisory dated…

7 hours ago
  • Income Tax

No protective addition required when additions is confirmed in hands of searched person – ITAT

No protective addition required in the hand of a third party when additions have been confirmed in the hands of…

1 day ago
  • arbitration

Limitation u/s 34 of Arbitration Act commences on disposal of application u/s 33 by Arbitral Tribunal – SC

Limitation for filing application u/s 34 of Arbitration Act commence from date on which application u/s 33 is disposed of…

5 days ago
  • Income Tax

Case remanded in absence of finding if disallowance u/s 40A(3) covered by Rule 6DD

Case remanded as no finding was given whether cash payments disallowed u/s 40A(3) were covered by Rule 6DD under Income…

6 days ago
  • Income Tax

For investment in share capital, source of investment is outside the control of the investee company

In case of investment in share capital, the source of investment may remain outside the control of the investee company.…

7 days ago