What is SWIFT CSP?
The SWIFT Customer Security Programme (CSP) was established in response to sophisticated cyber attacks targeting SWIFT-connected financial institutions. It defines mandatory security controls through the Customer Security Control Framework (CSCF) that all SWIFT users must implement and attest to annually.
Control Framework
The CSCF organizes controls into three objectives:
- Secure Your Environment: Restrict internet access, protect critical systems, reduce attack surface
- Know and Limit Access: Manage identities, enforce least privilege, control physical access
- Detect and Respond: Monitor for anomalies, plan incident response, share threat intelligence
Mandatory vs. Advisory Controls
The framework includes 32 mandatory controls that all SWIFT users must implement, plus advisory controls that represent best practices. SWIFT regularly elevates advisory controls to mandatory status.
Annual Attestation
All SWIFT users must submit an annual self-attestation confirming their compliance status. Independent assessment by qualified assessors is now mandatory for most institution types.
Back to Glossary