Security working group meeting 2 – July 28, 2022

This discussion guide is provided to assist security working group members in preparing for the second meeting, which builds on the main risks discussed at the first meeting.

For questions or comments, please contact obbo@fin.gc.ca.

On this page:

Discussion guide

Data security

The Advisory Committee on Open Banking noted that data security, which includes authentication, authorization, confidentiality, availability, integrity and non-repudiation, should be a key element of an open banking system.

Leveraging industry expertise and existing frameworks/certifications can help set up a minimum set of effective rules that protects the confidentiality, integrity and availability of information and data in the open banking ecosystem.

For example, under the Australian Consumer Data Right (CDR) regime, certain entities applying for accreditation must satisfy information security obligations. To this end, applicants may provide evidence of compliance with frameworks such as ISO 27001. The United Kingdom’s Open Banking Implementation Entity takes a similar approach. 

Discussion

  1. Are there existing frameworks/certification regimes that could provide the baseline requirements to address data security risks?
  2. Are these frameworks/certifications suitable for organizations of varying sizes, complexity, and risk levels?
  3. What benefits do frameworks/certifications offer to potential accreditation applicants?
  4. What challenges can be foreseen in implementing frameworks/certification regimes and how can they be addressed?

Outcomes

Data security

Discussion 1

Are there existing frameworks/certification regimes that could provide the baseline requirements to address data security risks?

Discussion 2

Are these frameworks/certifications suitable for organizations of varying sizes, complexity, and risk levels?

Discussion 3

What benefits do frameworks/certifications offer to potential accreditation applicants?

Discussion 4

What challenges can be foreseen in implementing frameworks/certification regimes and how can they be addressed?

Security working group attendees

Members

  • Affinity Credit Union
  • Alterna Savings and Credit Union Limited
  • ATB Financial
  • Canadian Imperial Bank of Commerce
  • Clearco
  • Equitable Bank
  • Flinks
  • nanopay
  • PayBright
  • Questrade
  • Royal Bank of Canada
  • TD Canada Trust

External guests

  • Credit Union Deposit Guarantee Corporation of Alberta
  • Financial Consumer Agency of Canada
  • Office of the Superintendent of Financial Institutions

Chair

  • Abraham Tachjian, Open banking lead

Secretariat

  • Department of Finance Canada

Page details

Date modified: