logo

Database

SWIFT CSCF

Last updated: 2024/02/07
logo

SWIFT Customer Security Controls Framework (CSCF) establishes a set of mandatory and advisory security controls for the operating environment of SWIFT users. SWIFT provides the global messaging system that financial organizations use to transmit information and instructions securely. Users can compare the security controls they have implemented with those listed in the CSCF to identify and remediate any compliance gaps. The version used in this section is v2024.

Control-Requirement Mapping

DefinitionRequirements
1_2. Operating system privilege account control
1_3. Virtualization or cloud platform protection
1_4. Restriction of Internet access
2_1. Internal data flow security
2_2. Security updates
2_3. System hardening
2_5A. External transmission data protection
2_6. Operator session confidentiality and integrity
2_10. Application hardening
3_1. Physical security
4_1. Password policy
4_2. Multi-factor authentication
5_1. Logical access control
5_2. Token management
5_4. Password repository protection
6_1. Malware protection
6_2. Software integrity
6_3. Database integrity
6_4. Logging and monitoring