Back to Tools

SWIFT CSP Control Checker

Check your implementation status against all 32 mandatory SWIFT CSCF controls. Identify gaps and get actionable recommendations.

Secure Your Environment

0/16 implemented
1.1

SWIFT Environment Protection

Ensure the protection of the local SWIFT infrastructure from potentially compromised elements of the general IT environment and external environment.

Implement network segmentation with firewalls to create a secure zone for SWIFT infrastructure. Use dedicated VLANs and access control lists.
1.2

Operating System Privileged Account Control

Restrict and control the allocation and usage of administrator-level operating system accounts.

Implement Privileged Access Management (PAM) solution. Enforce just-in-time access and session recording for all privileged accounts.
1.3

Virtualisation Platform Protection

Secure the virtualisation platform and virtual machines (VMs) hosting SWIFT-related components to the same level as physical systems.

Harden hypervisor configurations, restrict management access, and ensure VM isolation. Apply vendor security benchmarks.
1.4

Restriction of Internet Access

Restrict internet access from operator PCs and systems within the secure zone.

Block direct internet access from the SWIFT secure zone. Use proxy servers with content filtering for any necessary connections.
1.5

Customer Environment Protection

Ensure the protection of the customer's connectivity infrastructure from external environments and potentially compromised elements.

Implement defense-in-depth network architecture with multiple security layers between external networks and SWIFT infrastructure.
2.1

Internal Data Flow Security

Ensure the confidentiality, integrity, and authenticity of data flows between local SWIFT-related applications.

Encrypt all internal SWIFT data flows using TLS 1.2+. Implement mutual authentication between SWIFT application components.
2.2

Security Updates

Minimise the occurrence of known technical vulnerabilities within the local SWIFT infrastructure by ensuring vendor support and applying mandatory software updates.

Establish a patch management process for SWIFT zone systems. Apply critical patches within 30 days and maintain vendor support agreements.
2.3

System Hardening

Reduce the cyber-attack surface of SWIFT-related components by performing system hardening.

Apply CIS Benchmarks or vendor hardening guides. Remove unnecessary services, protocols, and user accounts from all systems.
2.4A

Back Office Data Flow Security

Ensure the confidentiality, integrity, and mutual authenticity of data flows between back office applications and SWIFT infrastructure.

Implement encrypted channels for all back-office to SWIFT communications. Use mutual TLS and certificate-based authentication.
2.5A

External Transmission Data Protection

Protect the confidentiality of SWIFT-related data transmitted or stored outside of the secure zone.

Encrypt all SWIFT data before transmission outside the secure zone. Implement data loss prevention controls for SWIFT-related information.
2.6

Operator Session Confidentiality and Integrity

Protect the confidentiality and integrity of interactive operator sessions connecting to the local SWIFT infrastructure.

Use encrypted connections (SSH, RDP with TLS) for all operator sessions. Implement jump hosts for administrative access.
2.7

Vulnerability Scanning

Identify known vulnerabilities within the local SWIFT environment by implementing a regular vulnerability scanning process.

Conduct monthly vulnerability scans of all SWIFT zone systems. Prioritize and remediate critical and high vulnerabilities promptly.
2.8A

Critical Activity Outsourcing

Ensure protection of the local SWIFT infrastructure when relying on critical outsourced activities.

Include SWIFT CSP compliance requirements in outsourcing contracts. Conduct regular assessments of third-party security controls.
2.9

Transaction Business Controls

Restrict transaction activity to validated and approved business counterparties and within expected bounds.

Implement transaction monitoring with business rules. Configure payment limits, approved counterparty lists, and anomaly detection.
2.10

Application Hardening

Reduce the attack surface of SWIFT-related messaging and communication applications.

Harden all SWIFT applications following vendor guidelines. Disable unused features and apply principle of least functionality.
2.11A

RMA Business Controls

Restrict the SWIFT transaction activity with counterparties to those that are needed for business.

Review and clean up Relationship Management Application (RMA) permissions regularly. Remove unused or unnecessary RMA authorizations.

Know and Limit Access

0/6 implemented
4.1

Password Policy

Ensure passwords are sufficiently complex and changed regularly for operator and administrator accounts.

Enforce minimum 12-character passwords with complexity requirements. Implement 90-day rotation and password history enforcement.
4.2

Multi-Factor Authentication

Prevent that a compromised single authentication factor allows access to SWIFT systems.

Deploy MFA for all SWIFT system access using hardware tokens or authenticator apps. Ensure MFA covers both local and remote access.
5.1

Logical Access Control

Enforce the security principles of need-to-know, least privilege, and segregation of duties for operator accounts.

Implement role-based access control. Conduct quarterly access reviews. Ensure segregation between transaction creation and approval.
5.2

Token Management

Ensure the proper management, tracking, and use of connected and authentication tokens.

Maintain an inventory of all tokens. Implement secure storage, issuance, and revocation procedures. Track token assignments.
5.3A

Personnel Vetting Process

Ensure that personnel operating SWIFT systems within the secure zone are trustworthy.

Conduct background checks for all personnel with SWIFT access. Implement ongoing personnel security screening programs.
5.4

Physical Security

Prevent unauthorised physical access to sensitive equipment, workplace environments, hosting sites, and storage.

Implement physical access controls, CCTV monitoring, and visitor management for areas housing SWIFT infrastructure.

Detect and Respond

0/9 implemented
6.1

Malware Protection

Ensure that the local SWIFT infrastructure is protected against malware.

Deploy enterprise anti-malware with real-time protection on all SWIFT zone systems. Implement application whitelisting where possible.
6.2

Software Integrity

Ensure the software integrity of SWIFT-related applications and detect changes.

Implement file integrity monitoring for all SWIFT applications and critical system files. Alert on any unauthorized changes.
6.3

Database Integrity

Ensure the integrity of the database records for the SWIFT messaging interface.

Enable database audit logging. Implement integrity checks for transaction records and detect unauthorized modifications.
6.4

Logging and Monitoring

Record security events and detect anomalous actions and operations within the local SWIFT environment.

Centralize log collection in a SIEM. Monitor for anomalous activities 24/7 with defined alert thresholds and escalation procedures.
6.5A

Intrusion Detection

Detect and prevent anomalous network activity into and within the local SWIFT environment.

Deploy IDS/IPS at network boundaries and within the SWIFT secure zone. Tune signatures for SWIFT-specific traffic patterns.
7.1

Cyber Incident Response Planning

Ensure a consistent and effective approach for the management of cyber incidents.

Develop and test a SWIFT-specific incident response plan. Include playbooks for common SWIFT-related attack scenarios.
7.2

Security Training and Awareness

Ensure all staff are aware of and fulfil their security responsibilities.

Conduct annual security awareness training with SWIFT-specific modules. Include phishing simulations and social engineering awareness.
7.3A

Penetration Testing

Validate the operational security configuration and identify security gaps.

Conduct annual penetration testing of the SWIFT environment by qualified external testers. Remediate critical findings within 30 days.
7.4A

Scenario-Based Risk Assessment

Assess and document the risk of the local SWIFT infrastructure based on cyber threat scenarios.

Conduct scenario-based risk assessments using current threat intelligence. Update risk register and treatment plans accordingly.

Compliance Status

0%compliant

0 implemented

31 gaps

By Objective

Secure Your Environment0%
Know and Limit Access0%
Detect and Respond0%
Request Full Assessment