Global · SWIFT (Society for Worldwide Interbank Financial Telecommunication) · SWIFT CSCF

SWIFT Customer Security Controls Framework

The mandatory and advisory security controls that SWIFT users must implement and self-attest against each year.

What it is

The CSCF sets security expectations for every SWIFT user across three objectives: secure your environment, know and limit access, and detect and respond. Users self-attest annually against mandatory controls, with compliance independently assessed on a risk-tiered schedule. Non-compliance with mandatory controls can be reported to regulators and trigger counterparty de-risking. The framework is revised each year, and customers attest against the version active at the attestation date.

Who it applies to

All SWIFT-connected entities - banks, payment institutions, central securities depositories and qualifying intermediaries.

Requirements

Restrict internet access

Segregate the SWIFT environment from the general IT estate and restrict internet access.

Reduce attack surface

Harden and patch systems hosting or supporting SWIFT, including operator PCs.

Physically secure the environment

Prevent physical tampering with SWIFT-related assets.

Prevent compromise of credentials

MFA, password policy, least privilege and privileged-access controls.

Detect anomalies and respond

Monitor, log and alert on SWIFT-related activity, and have a documented incident response plan.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.