Accounts must be authenticated using at least a username and a secret key with a minimum length of 6 characters... this is one of the requirements for ensuring the security of transactions in providing electronic banking services.
Circular 35, recently issued by the State Bank of Vietnam, will replace Circular 29, which regulates safety and security for providing banking services on the Internet.
Accordingly, the circular requires that accounts be authenticated using at least a username and a secret key. The username must be at least 6 characters long and must not contain all identical characters or characters in consecutive alphabetical or numerical order.
The secret key must also be at least 6 characters long, including letters and numbers, and contain uppercase letters and special characters. The maximum validity period of the secret key is 12 months from the date of creation.
At the same time, the document also mentions the use of OTP codes sent via SMS or email to authenticate people's banking transactions. Specifically, when people conduct banking transactions that require the use of OTP codes sent via SMS, banks must include a warning message so that users understand the purpose of the OTP code in banking transactions. After 5 minutes of non-use, the OTP code will become invalid.
For secure banking transactions and card authentication, OTPs (One-Time Passwords) have a maximum validity period of one year from the card registration date, and the provided OTP code is only valid for 2 minutes.
For OTP codes generated from software installed on mobile devices, banks must also clearly provide a link on their website or app store for people to download and install the OTP generation software. According to the State Bank of Vietnam, this will help prevent fraudsters from creating fake websites to scam and steal customer information.
The OTP generation software must use a key provided by the provider to activate it before use and ensure security during electronic transactions. One key can only be used for one mobile device. The OTP generation software must be subject to access control. If the access authentication fails 5 times in a row, the bank must automatically block the customer from further use. Once provided, the OTP code will be valid for 2 minutes.
Download the full Circular 35/2016/TT-NHNN: Circular 35/2016/TT-NHNN
For further information, please see the other services offered by EXPERTIS.
- Accounting and
- Auditing services
- Building a management system

