|
THIS SECURITY ARRANGEMENT DETAILS THE PROCEDURES
EMPLOYED BY MAYBANK IN SAFEGUARDING THE SECURITY AND INTEGRITY OF ANY
INFORMATION AND TRANSACTIONS TRANSMITTED OR MADE VIA Maybank2e.net
AND OF Maybank2e.net ITSELF.
Introduction
We shall at all times and to the best of our ability, endeavour to ensure
that all materials, data, communications and/or information exchanged,
disclosed, shared, stored or otherwise used ("Information"),
or any transactions which are made via Maybank2e.net
("Transactions") are kept private and confidential. Further
thereto, we shall comply with and adhere to the requirements of Bank Negara
Malaysia pertaining to the privacy and confidentiality of the Information
and Transactions as well as the need to maintain the security and integrity
of Maybank2e.net. In pursuance of these objectives,
we have set in place a multitude of security procedures and requirements
which are designed to ensure the optimum security of the Information,
Transactions and Maybank2e.net at all times, all of
which are elaborated upon below.
 |
Data Privacy, Confidentiality & Integrity
In order to ensure the privacy, confidentiality and integrity of the Information
and Transactions transmitted or made via Maybank2e.net,
we have engaged the use of a combination of authentication, encryption
and auditing mechanisms which serve as a powerful barrier against all
forms of system penetration and abuse.
These mechanisms include but are not limited to
the following:-
 |
Authentication; |
 |
Information Protection; |
 |
Data Confidentiality & Data
Integrity; |
 |
System Security & Monitoring;
and |
 |
Computer Virus Protection. |
Authentication
To prevent unauthorised access to our online financial services as offered
through Maybank2e.net, every user is required to select
a username ("Username") and an alphanumeric password ("Password"),
which are the Access Keys to your financial information, banking facilities
and the product and services offered via Maybank2e.net
. The Username must be between 6 to 16 characters and the Password must
be between 8 to 12 characters. In both cases, special characters and spaces
should not be used, with the exception of underscore.
The Username and Password are case sensitive. For
example, if your Password is "maybank2e" and you key in "maybank2e",
you will not be able to login (the "e" must be lowercase).
To ensure the integrity of these Access Keys, you
are advised to maintain its confidentiality by not sharing it or making
it accessible to any other person and to take all reasonable endeavours
to maintain its security which may include, memorising the Access Keys,
changing your Password regularly and signing off before visiting any other
Internet sites.
In addition, users who are acting as authorisers
are required to use digital certificates for the purposes of ascertaining
and authenticating their identity before a transaction is approved.
Information Protection
We take considerable effort to ensure a safe and secure online experience,
but we do not have control over the computer you use to access Maybank2e.net.
As an added security feature, we have incorporated an automatic log out
function if no activity is detected after a preset time limit.
However, you must ensure that your computer and
you do not provide anyone opportunity to gain access to your account information.
The following are several tips and guidelines that may assist you:
 |
Ensure no one
has access to your computer, Access Keys or records of your online
activities. |
 |
Always log out of Maybank2e.net
immediately after completing transactions and before visiting other
websites. |
 |
Do not send any information about
your account or other financial or confidential information via email.
|
 |
Disable the AutoComplete function
on your browser to avoid automatic completion of your Access Keys
when you type in the said Access Keys. |
For example: To turn AutoComplete "On"
or "Off" in MS Internet Explorer browser:
| 1. |
is requested or
authorised by you or any other persons purporting to be you upon the
satisfactory verification of identity by us in accordance with our
prevailing procedure; |
| 2. |
Click "Internet Options"
to get the "Content" tab. |
| 3. |
From this tab, click the "AutoComplete"
button. |
| 4. |
Uncheck "Usernames and Passwords
on forms". |
Data Confidentiality and Data Integrity
| To ensure data confidentiality
and integrity, all information transmitted over the Internet is encrypted
using the 128-bit Secure Sockets Layer (SSL) protocol from Verisign
Certificate Authority. SSL is a secure way of transferring information
between two computers on the Internet using encryption. Strong end-to-end
encryption is also adopted within our computer networks and resources. |
|
|
Click seal to view the
certificate |
Maybank2e.net
is WebTrust certified. This certifies our compliance with leading
international security standards and Best Practices, as well as our
commitment to maintaining a secure environment. WebTrust is an independent
corporation that monitors and tests our facilities to assure that
we maintain the highest and most current standards in Internet information
security and exchange. |
|
|
Click seal to view the
certificate |
Systems Security and Monitoring
Maybank has adopted a combination of the following systems security and
monitoring measures for online transactions:
 |
Firewall systems,
strong data encryption, anti-virus protection and round-the-clock
security surveillance systems to detect and prevent any form of illegitimate
activities on our network systems. |
 |
Regular security reviews of our
systems by our internal system auditor as well as external security
experts. |
In addition to the measures adopted by us, we would
recommend that you consider installing a personal firewall or, at a minimum,
power-off your PC when it is not in use.
We also take every effort in ensuring collaboration
with major vendors/manufacturers to keep abreast of information security
technology developments, for possible and future implementation.
Computer Virus Protection
Computer viruses are real and once your computer is infected it can cost
you time, loss of information, repair expense, and aggravation. Make sure
your computer has an anti-virus protection program installed to reduce
the risk.
We recommend that you purchase a program that automatically
upgrades your virus protection on a recurring basis. If you currently
have a virus protection program on your computer without the automatic
upgrade feature, make sure you update your virus protection program at
least monthly and/or when you hear of a new virus to minimize your risk.
You can do this by visiting the Internet site of the company that provides
your virus protection program.
In addition, we would advise against opening attachments
from others or using diskettes unless you have absolute certainty that
you can trust the source. Notwithstanding, we would advise that you still
remain cautious as whoever sent you that attachment or gave you the diskette
may themselves be unaware that they have carried the virus to you.
Non-Repudiation
Further to the rest of this Security Arrangement and for the purposes
of clarification, any and all Transactions which are initiated by or originate
from the Customer's Access Keys (which shall be taken to include the Access
Keys of the Customer's duly appointed users) shall be deemed to have been
initiated or originated from the said Customer and accordingly, we shall
be entitled to carry out the said Transactions as if we had been duly
instructed to do so by the respective Customer.
We also maintain and constantly update the logs
of the Transactions which record, among others, the Transactions entered
into by our Customers (including you) and the nature, time and date of
the same, all of which serves to enable us to verify the various Transactions
made and act as evidence thereof should there ever arise a dispute as
to the same.
Access Control & System Design
Maybank2e.net is designed and developed with the primary
and utmost intention of safeguarding the security and integrity of all
Information and Transactions at all times. Pursuant thereto, Maybank2e.net
deploys a wide range of security features all of which are constantly
reviewed and audited to determine their effectiveness and further updated
and maintained to ensure that these security features perform at optimum
standards at all times.
We also adopt a variety of monitoring and review
measures upon the security and integrity of Maybank2e.net,
which include but are not limited to:-
| 1. |
Enhanced data-encryption
methods; |
| 2. |
Anti-virus detection, prevention
and protection procedures; |
| 3. |
Firewall barriers; and |
| 4. |
Surveillance and detection, |
all of which are designed and implemented to intercept
and prevent any form of attack on, penetration of or otherwise unauthorised
access into Maybank2e.net and to ensure that the critical
sectors of Maybank2e.net including the storage of the
Information, the Information itself and the processing and authentication
of the Transactions are, at all times, kept free from such attack, penetration
or unauthorised access ("System Security Monitors").
We shall also endeavour to conduct regular and
thorough reviews or audits of our System Security Monitors, both by our
internal security auditors as well as by external security experts. These
reviews and audits may include but are not limited to actual penetration
testing and intrusion detection on our said System Security Monitors which
will enable us to determine whether there are any defects, faults, malfunctions
or shortcomings (the "said defects") in the same. In the event
the said defects or otherwise a breach of Maybank2e.net
is discovered, we shall in the case of a security breach, promptly report
the same to the appropriate management and Bank Negara Malaysia and immediately
proceed to rectify or remedy the same. For this purpose, we may be required
to temporarily or indefinitely suspend all use of Maybank2e.net
until such time when the said defects are rectified or remedied without
any notice and without any liability whatsoever to you.
While we have the capabilities
to ensure that the privacy, confidentiality and integrity of the Information,
the Transactions as well as the security and integrity of Maybank2e.net
itself are at all times, safeguarded, maintained and secure, we shall
from time to time collaborate efforts with other major hardware, equipment
or software vendors and manufacturers in an effort to keep abreast with
the developments and improvements made to the same. Accordingly, where
we believe that such developments and improvements would serve to provide
enhanced security to the Information, Transactions and Maybank2e.net
above, we shall not hesitate to implement the same for our joint-benefit.
 |

WE FIRMLY BELIEVE THAT THE PRIVACY OF OUR CUSTOMERS'INFORMATION
IS FUNDAMENTAL TO SECURING PUBLIC TRUST AND CONFIDENCE IN OUR PRODUCTS
AND SERVICES AND THEREFORE, IT IS OUR POLICY TO RESPECT, MAINTAIN, PROTECT
AND SAFEGUARD, AT ALL TIMES, THE PRIVACY OF OUR CUSTOMERS' INFORMATION
UNDER THE www.maybank2e.net WEBSITE WHICH IS OPERATED BY US AT MALAYAN
BANKING BERHAD.
Introduction
We have always considered our Customers and their interests as being of
utmost priority in the provision of our products and services. For this
reason and others, we are committed to ensuring that the privacy of your
personal, banking and financial information as well as any other information
in respect of or pertaining to the same which you have disclosed, shared,
exchanged or otherwise provided to us ("Information") is at
all times respected, maintained, protected and safeguarded.
Pursuant thereto and for your benefit, this Privacy
Policy (which we may amend from time to time) is designed to explain and
elaborate upon some of our policies and principles pertaining to the privacy
of your Information, all of which we have adopted as a sign of our commitment
to respecting, maintaining, protecting and safeguarding the privacy of
your Information.
 |
Types of Information Which We Collect
The types of Information which we collect varies depending upon how you
access and use our products and services. Nevertheless, the Information
which we collect generally comprises of data and information pertaining
to yourself such as your name, National Registration Identification Card
(NRIC) No. as well as other financial and banking information as may be
relevant to provide the products and services where the Customer is a
company or organisation, information pertaining to, among others, the
Customer's users and any other relevant business and financial information
pertaining to such company or organisation .
 |
Use of the Information
The Information which we gather from you is generally meant to be used
in the ordinary course of our business including the provision of our
products and services to you as requested. However, our use of your Information
may also extend to other purposes, among others, to enforce or defend
any of our rights, to comply with all applicable legislation, laws and
regulations as well as the requirements of any legal, regulatory or other
authoritative bodies, to enhance the quality of our products and services
and to prevent fraud or illegal activities. Further, such Information
may also be used to prepare demographics concerning our Customers' use
of our products and services which may, at our sole discretion, be made
available to our third party vendors, advertisers, affiliates or relevant
third parties in aggregate or demographic form from which individual Customer's
identities cannot be ascertained.
 |
Employee' Access to the Information
We repeat our commitment to respect, maintain, protect and safeguard the
privacy of your Information by ensuring that any access to the Information
is restricted to our duly authorised employees, all of whom are fully
trained and well-equipped to handle your Information. Each of our said
duly authorised employees is required to adhere to our commitment herein
and specifically to our dedication to safeguarding the privacy of your
Information at all times. Failure by our respective duly authorised employees
herein to comply with the same and generally the terms of this Privacy
Policy shall be met with utmost strict disciplinary action.
 |
Security Measures Employed to Safeguard the
Privacy of the Information
It is our policy to ensure that adequate and stringent security controls,
measures and protocols are employed to safeguard the privacy of your Information,
all of which shall continue even after whatever contractual relationship
between you and us has come to an end. While we shall use our best efforts
to ensure that the privacy of all Information is kept secure, it is an
accepted fact that no data transmission conducted over the Internet can
be guaranteed to be wholly secure.
Further thereto, we shall neither be held responsible
nor liable for any damages or losses which you may suffer, whether directly
or indirectly, as a result of the said Information being stolen, tampered
with, copied, abused, misused or otherwise violated.
Further information on the security controls, measures
and protocols which we have employed herein are specified and elaborated
upon in our SECURITY ARRANGEMENT, which we trust you will read and understand.
 |
Sharing of Information
We shall, at all times, endeavour to safeguard the privacy of your Information
and accordingly, we do not disclose the same to any third party or external
organisations. Notwithstanding this and for the purposes of helping us
serve you better, your non-banking and non-financial information may be
provided to our third party vendors, advertisers, affiliates or relevant
third parties subject to your consenting to the same. Further thereto,
where such non-banking and non-financial information is provided to these
entities, we shall take all reasonable efforts to ensure that they comply
with the same standards regulating the privacy of your Information as
that which is imposed by us. Nevertheless, should you wish at anytime
to withdraw your consent and you do not want your non-banking and non-financial
information being further disclosed to these entities or do not want to
be solicited for further products or services which are offered by us
or them, please notify us accordingly via electronic-mail or post at the
contact addresses as specified in section 9 below.
Notwithstanding the generality of this Privacy
Policy and while we shall, at all times, endeavour to safeguard the privacy
of your Information, we may nevertheless disclose your Information to
other entities where such disclosure:-
| 1. |
is requested or
authorised by you or any other persons purporting to be you upon the
satisfactory verification of identity by us in accordance with our
prevailing procedure; |
| 2. |
is used for the purposes of processing,
completing, verifying or restricting any application, instruction
or transaction made by you; |
| 3. |
is necessary to provide you with
the products and services offered or made available by us, our affiliates
or by third parties as subscribed to or requested by you; |
| 4. |
is made to Bank Negara Malaysia,
the Central Credit Unit or any other body or authority established
by Bank Negara Malaysia, pursuant to its request; |
| 5. |
is made to verify the existence
and conditions of your account(s) for a third party such as a credit
bureau or merchant; |
| 6. |
is lawfully permitted or required;
|
| 7. |
is in compliance with any judicial
order or legal requirement; |
| 8. |
is required to protect and defend
us and our property; and |
| 9. |
is required to protect the interests
of the public including but not limited to the detection of crimes
and the apprehension of criminals. |
 |
Customer's Choices in Respect of the Provision
of the Information
While you are neither bound nor obligated to provide us with any of your
Information, your choice not to do so (whether due to your disagreement
with the methods employed by us to safeguard the privacy of your Information
or otherwise) may result in you being prohibited from accessing or making
full use of our products and services, neither of which shall render us
responsible or liable therefor.
Accuracy of the Information
We acknowledge that the accuracy of your Information provided to us is
essential, among others, to the provision of our products and services
to you. Accordingly, it would be in your best interests to ensure that
whatever Information which you provide to us is, at all times, accurate,
complete, current and true.
For this purpose, you are encouraged to help us
maintain accurate records of your Information by notifying us of any changes
to the same so that we may amend or update your Information where necessary.
Should you also have any other queries concerning your Information or
its accuracy, or have reasons to believe that your records with us are
inaccurate, incomplete or has not been updated, please inform us accordingly.
Any such notification or queries can be made by contacting our Helpdesk
or emailing us, at the contact number and address in the last section.
|