Retail Banking

The security of retail electronic banking is largely dependent upon the security of cryptographic devices (e.g. PIN pads, ATMs, etc.), which are generally situated in non-secure environments. There is a risk that the devices may be tampered with or otherwise compromised to disclose or modify data. It is essential that the risk of financial loss is reduced through the appropriate use of cryptographic devices that have proper physical and logical security characteristics and are properly managed.

BSI’s standards specify the characteristics and the management of the secure cryptographic devices used to protect messages, cryptographic keys, electronic payments and other sensitive information used in a retail banking environment.  
BS ISO 11568-1:2005
Banking. Key management (retail). Principles

BS ISO 21188:2006
Public key infrastructure for financial services. Practices and policy framework  PAS 76:2006
Accounting software. Valued Added Tax in the UK. Specification 

BS ISO 11568-2:2012
Financial services. Key management (retail). Symmetric ciphers, their key management and life cycle

BS ISO 13491-2:2005
Banking. Secure cryptographic devices (retail) Security compliance checklists for devices used in financial transactions

