logo

SWIFT CSCF


Summary

SWIFT Customer Security Controls Framework (CSCF) establishes a set of mandatory and advisory security controls for the operating environment of SWIFT users. SWIFT provides the global messaging system that financial organizations use to transmit information and instructions securely. Users can compare the security controls they have implemented with those listed in the CSCF to identify and remediate any compliance gaps. The version used in this section is v2024.


Definitions

DefinitionRequirements
SWIFTCSC-1_2. Operating system privilege account control
SWIFTCSC-1_3. Virtualization or cloud platform protection
SWIFTCSC-1_4. Restriction of Internet access
SWIFTCSC-2_1. Internal data flow security
SWIFTCSC-2_2. Security updates
SWIFTCSC-2_3. System hardening
SWIFTCSC-2_5A. External transmission data protection
SWIFTCSC-2_6. Operator session confidentiality and integrity
SWIFTCSC-2_10. Application hardening
SWIFTCSC-3_1. Physical security
SWIFTCSC-4_1. Password policy
SWIFTCSC-4_2. Multi-factor authentication
SWIFTCSC-5_1. Logical access control
SWIFTCSC-5_2. Token management
SWIFTCSC-5_4. Password repository protection
SWIFTCSC-6_1. Malware protection
SWIFTCSC-6_2. Software integrity
SWIFTCSC-6_3. Database integrity
SWIFTCSC-6_4. Logging and monitoring

Last updated

2024/02/07