The Swift Customer Security Controls Framework (CSCF) includes both required and recommended security controls. Over time, the controls change to counter emerging risks and incorporate new cybersecurity advancements.
Strengthening the global banking system's security
Security measures for Swift users that are both required and recommended make up the SWIFT CSCF Compliance. The community as a whole is given a security baseline thanks to the required security procedures. All users are required to implement them on their personal Swift infrastructure. Swift has decided to give these required controls top priority in order to establish a reasonable target for immediate, observable security improvements and risk mitigation.
Swift advises all users to adopt the suggested practices that form the basis of the advisory controls. Controls may alter over time as a result of the threat landscape changing, new technologies emerging, significant jurisdictions' security-related laws changing, advancements in cybersecurity techniques, or user input. As a result, new controls might be added, or some advised controls might be made necessary.
Three main goals serve as the foundation for all controls:
• Protect your surroundings.
• Recognize and restrict access.
• Recognize and Act
Lastly, control definitions adhere to current industry standards for information security.
The generally product-agnostic controls are based on the data described in the CSCF paper. Every user is required to thoroughly examine the rules outlined in this paper and get their own organization ready for deployment.
Swift releases product-specific Security Guidance (SG) materials to supplement the CSCF. Along with extra instructions on how to set up Swift's messaging interface suite's current security features to comply with the most recent CSCF, they offer the bare minimum security guidelines.
Swift publishes additional information about the associated attestation policy and procedure in the Swift Customer Security Controls (CSCF) Policy document to guarantee adoption and to supplement the CSCF.
The document includes details about:
• the need to vouch for Swift's required security measures.
• the procedure and due dates for presenting your validation to the application for KYC-Security Attestation.
• the process for viewing counterparties’ attestation via the KYC Security Attestation application
• Follow-up actions in case of non-compliance according to the reporting timelines.
• To stay updated on CSP news, subscribe to our quarterly updates.
Change Management
The Swift community will have enough time (up to 18 months) to comprehend and execute the necessary modifications to the control specifications thanks to the change management procedure.
Evaluation and compliance with the amended obligatory controls must be finished between July and December of the following year, based on when the user's certification expires. In the latter half of the year, any changes to the regulations will be announced.
Rarely, but in extraordinary cases, an emergency discharge may be necessary.
To realistically and jointly raise the security threshold for everyone, new SWIFT CSCF Compliance policies or guidelines will be introduced that take into consideration robust cybersecurity practices that address known, emerging, and new threats.