Yeah I think the equivalent step to get to what we are doing in NZ was OVpay, which went live in 2023 - that is the system that allows payment by bank card rather than by stored value transit card.
That is PCI-DSS 4.0 Requirement 8.5. 1: MFA solutions must not be susceptible to replay attacks, cannot be bypassed by any user including an administrator (unless expressly documented) and PCI has now solidified that two different MFA authentication factors must be used. 12 Sept 2023
Comments