Project

General

Profile

Actions

Feature #306

closed

Reg : KMB Bank Audit Observation

Added by Payodhi about 2 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
High
Assignee:
Shiva_CIMS
Start date:
07/31/2023
Due date:
08/30/2023
% Done:

0%

Estimated time:
Project categorization:
New

Description

Dear Shiva,

Kindly close the below mentioned observation points in KMB server.

Observations :

• Physical and Scanned copy of Aadhaar were not Encrypted: As per UIDAI Circular No 11020/205/2017 dated 25th July 2017 and Frequently Asked Question (FAQs), The agencies need to keep the scanned copies encrypted and ensure security of both scanned copies and physical copies as per Aadhaar Act 2016 and Regulations.
• Reviewed security control for sample BC ‘NOCPL’ we noted that the KYC document which are scanned and uploaded into MLOS application are not encrypted when stored on the local system.

• Storage of Customer Aadhaar Numbers: As per UIDAI Circular No. 11020/205/2017 dated 25-July-2017, All entities / agencies are directed to mandatorily store Aadhaar Numbers and any connected Aadhaar data only on a separate secure database/vault/system. Aadhaar numbers shall not be stored in any other systems. The Aadhar Number and any connected data maintained on the Aadhar Data Vault shall always be encrypted.

• On review we noted the customer Aadhar number is converted into a 14 digit reference number before it is stored. However, we observed that same is not stored on a separate database / vault / system. Instead it is getting saved in the same application database.

• Customer Details Stored in Clear Text: On review we observed PII details shared by the customer for availing loan from the Business Correspondent “BC” (NOCPL) i.e. Voter ID, Date of Birth are stored in clear text in the database of the application used by BC i.e. PHP My Admin


Files

clipboard-202310301730-d9c8q.png (806 KB) clipboard-202310301730-d9c8q.png Encryption_PII Shiva_CIMS, 09/20/2023 11:30 AM
Security_TC_NOCPL_KMBL.xlsx (24.7 KB) Security_TC_NOCPL_KMBL.xlsx Rajkumar, 09/20/2023 01:30 PM
Actions #1

Updated by Shiva_CIMS about 2 years ago

  • Status changed from New to In Progress
  • Assignee set to Payodhi

Dear sir,

As per the below e-mail confirmation,

1. we have removed Aadhar storage in our system.
2. PII information encryption has pending.

Actions #2

Updated by Payodhi about 2 years ago

  • Assignee changed from Payodhi to Shiva_CIMS

Dear Shiva,

Thanks for updation. Kindly complete the PII information and update the same.

Actions #3

Updated by Shiva_CIMS almost 2 years ago

Dear sir,

PII information has been encrypted using method as AES 256.

Encryption_PII

Actions #4

Updated by Rajkumar almost 2 years ago

Dear Shiva,

Please find the security test case.

Actions #5

Updated by Payodhi almost 2 years ago

  • Status changed from In Progress to Closed

Dear Shiva,

We've cross-checked the information in the database, and we appreciate your valuable assistance.

Actions

Also available in: Atom PDF