Skip to content
BOL Conferences
Thread Options
#282097 - 11/30/04 07:13 PM ACH Data Security Requirements
Anonymous
Unregistered

Could someone give me a few examples of what is not allowed under the new ACH Data Security Requirements. Would faxing a NOC to an originator be allowed?

Thanks

Return to Top
Audit
#282098 - 12/01/04 03:35 AM Re: ACH Data Security Requirements
Anonymous
Unregistered

Having a customer originate an ACH file across the internet or through email without encryption is a no-no because that entails sending an unsecured file through an unsecured public network. While not recommended, having a customer transmit an unencrypted file via telephone transfer (not going through a PBX) is OK according to the NACHA rules but the UCC says that you need to have a commercially reasonable security procedure to protect you from liability. Yes, faxing a NOC is OK.

Return to Top
#282099 - 12/07/04 07:11 PM Re: ACH Data Security Requirements
Anonymous
Unregistered

The Audit Program asks "what process is used to ensure that the session is protected or the information is encrypted" What would be the correct answeer for this?

Return to Top
#282100 - 12/07/04 08:16 PM Re: ACH Data Security Requirements
Anonymous
Unregistered

The key term in the audit progrem section you quote is "transmitted or exchanged ... via an Unsecured Electronic Network". The use of the telephone to call from the Bank to a client's telephone or fax machine is not considered going through an "Electronic Network."

(However, a telephone dial-up to an ISP for internet access is considered going through an "Unsecured Electronic Network" and is subject to encryption requirements.)

The protection of a telephone or fax session can be done in a number of commercially reasonable ways. The most frequent, short of actual encryption, is via telephone call-backs for the Bank to pick up ACH files. Most important is that the client should acknowledge the security procedure you use so that they can either "accept" the commercially reasonable procedure you're offering or go someplace else.

Return to Top
#282101 - 12/16/04 06:28 PM Re: ACH Data Security Requirements
Happy Offline
Gold Star
Happy
Joined: Jan 2002
Posts: 282
Can you tell me where in the NACHA Operating Rules this verbiage is stated,( "transmitted or exchanged ... via an Unsecured Electronic Network".)? Thanks

Return to Top

Moderator:  Andy_Z