Agentforce, the GenAI Agent by Salesforce
SWIFT has established the Customer Security Program to support its customers in the fight against cyber-fraud targeting their SWIFT-related infrastructure.
In order to support its customers reinforce their security, SWIFT introduced the Customer Security Program2 (CSP) ) in May 2016, that sets guidelines and controls to improve information sharing throughout the community, enhances SWIFT-related tools for customers and provides control frameworks.
As part of the CSP, SWIFT published its Customer Security Controls Framework in April 2017 which introduces 16 mandatory security controls that all SWIFT users must apply to their SWIFT-related infrastructure.
SWIFT requirements should be considered as users’ high priority as failure to comply with the requirements, on an annual basis, will be reported to regulators.
Each organization is required to assess, define, document, implement and attest the compliance of their SWIFT Local infrastructure processes and technologies against SWIFT’s controls through:
The 27 controls3 presented by SWIFT are mapped against international standards where applicable, such as NIST, PCI-DSS and ISO 27002.
Each of these principles are then divided into controls, for example, the Principle “7. Plan for incident Response and Information Sharing” describes the 4 controls:
7.1 Cyber Incident Response Planning – Mandatory
7.2 Security Training and Awareness – Mandatory
7.3A Penetration Testing – Advisory
7.4A Scenario Risk Assessment – Advisory
Users are required to self-attest the compliance of their SWIFT local environments against CSCF. The first self-attestation must be submitted by 31 December 2017, and on a yearly basis thereafter.
Here are some of the challenges SWIFT users will face when preparing for the self-assessment exercise.
Companies will have to assess the necessity of the 11 advisory controls4, based on the maturity assessment of the cybersecurity existing frameworks.
The assessment of mandatory and advisory controls can lead to major technological enhancements, including the deployment of local intrusion detection technology on all critical SWIFT systems.
Depending on your organization architecture and governance, some of the controls may not be applicable to your organization and they will need to be justified in your self-attestation.
Sia Partners can assist SWIFT users in evaluating the maturity of their current cybersecurity framework, including processes, controls and governance. Our objective is to design the most efficient controls to close the gaps with the targeted framework and help the organization in the controls implementation. Sia Partners can also support the client in preparing the SWIFT CSP attestation.
Key Takeaways