SWIFT CSP Control Checker
Check your implementation status against all 32 mandatory SWIFT CSCF controls. Identify gaps and get actionable recommendations.
Secure Your Environment
0/16 implementedSWIFT Environment Protection
Ensure the protection of the local SWIFT infrastructure from potentially compromised elements of the general IT environment and external environment.
Operating System Privileged Account Control
Restrict and control the allocation and usage of administrator-level operating system accounts.
Virtualisation Platform Protection
Secure the virtualisation platform and virtual machines (VMs) hosting SWIFT-related components to the same level as physical systems.
Restriction of Internet Access
Restrict internet access from operator PCs and systems within the secure zone.
Customer Environment Protection
Ensure the protection of the customer's connectivity infrastructure from external environments and potentially compromised elements.
Internal Data Flow Security
Ensure the confidentiality, integrity, and authenticity of data flows between local SWIFT-related applications.
Security Updates
Minimise the occurrence of known technical vulnerabilities within the local SWIFT infrastructure by ensuring vendor support and applying mandatory software updates.
System Hardening
Reduce the cyber-attack surface of SWIFT-related components by performing system hardening.
Back Office Data Flow Security
Ensure the confidentiality, integrity, and mutual authenticity of data flows between back office applications and SWIFT infrastructure.
External Transmission Data Protection
Protect the confidentiality of SWIFT-related data transmitted or stored outside of the secure zone.
Operator Session Confidentiality and Integrity
Protect the confidentiality and integrity of interactive operator sessions connecting to the local SWIFT infrastructure.
Vulnerability Scanning
Identify known vulnerabilities within the local SWIFT environment by implementing a regular vulnerability scanning process.
Critical Activity Outsourcing
Ensure protection of the local SWIFT infrastructure when relying on critical outsourced activities.
Transaction Business Controls
Restrict transaction activity to validated and approved business counterparties and within expected bounds.
Application Hardening
Reduce the attack surface of SWIFT-related messaging and communication applications.
RMA Business Controls
Restrict the SWIFT transaction activity with counterparties to those that are needed for business.
Know and Limit Access
0/6 implementedPassword Policy
Ensure passwords are sufficiently complex and changed regularly for operator and administrator accounts.
Multi-Factor Authentication
Prevent that a compromised single authentication factor allows access to SWIFT systems.
Logical Access Control
Enforce the security principles of need-to-know, least privilege, and segregation of duties for operator accounts.
Token Management
Ensure the proper management, tracking, and use of connected and authentication tokens.
Personnel Vetting Process
Ensure that personnel operating SWIFT systems within the secure zone are trustworthy.
Physical Security
Prevent unauthorised physical access to sensitive equipment, workplace environments, hosting sites, and storage.
Detect and Respond
0/9 implementedMalware Protection
Ensure that the local SWIFT infrastructure is protected against malware.
Software Integrity
Ensure the software integrity of SWIFT-related applications and detect changes.
Database Integrity
Ensure the integrity of the database records for the SWIFT messaging interface.
Logging and Monitoring
Record security events and detect anomalous actions and operations within the local SWIFT environment.
Intrusion Detection
Detect and prevent anomalous network activity into and within the local SWIFT environment.
Cyber Incident Response Planning
Ensure a consistent and effective approach for the management of cyber incidents.
Security Training and Awareness
Ensure all staff are aware of and fulfil their security responsibilities.
Penetration Testing
Validate the operational security configuration and identify security gaps.
Scenario-Based Risk Assessment
Assess and document the risk of the local SWIFT infrastructure based on cyber threat scenarios.
Compliance Status
0 implemented
31 gaps