SWIFT Customer Security Controls Framework v2024
Mandatory security controls framework for all 11,000+ SWIFT-connected financial institutions globally. 32 controls (25 mandatory, 7 advisory) across 3 objectives: secure your environment, know and limit access, detect and respond. Annual independent assessment attestation required. Covers network segmentation, privileged access, system hardening, transaction business controls, malware protection, logging/monitoring, and incident response for SWIFT financial messaging infrastructure. Aligned with ISO 27002, NIST CSF, PCI DSS 4.0.
Controls: 67
Total Mappings: 116
Publisher: SWIFT (Society for Worldwide Interbank Financial Telecommunication) Version: v2024 AC (10) AT (3) AU (6) CA (2) CM (6) CP (2) IA (3) IR (5) MP (3) PE (4) PM (1) PS (3) RA (2) SA (3) SC (7) SI (4) SR (3)
AC Access Control
| Control | Name | SWIFT CSCF References |
|---|---|---|
| AC-02 | Account Management | SWIFT.1.2SWIFT.2.11ASWIFT.5.1 |
| AC-03 | Access Enforcement | SWIFT.2.9SWIFT.2.11ASWIFT.5.1SWIFT.5.4SWIFT.6.3 |
| AC-04 | Information Flow Enforcement | SWIFT.1.1SWIFT.1.3SWIFT.1.4SWIFT.1.5SWIFT.2.4A |
| AC-05 | Separation of Duties | SWIFT.1.2SWIFT.5.1 |
| AC-06 | Least Privilege | SWIFT.1.2SWIFT.5.1SWIFT.6.3 |
| AC-07 | Unsuccessful Logon Attempts | SWIFT.4.1 |
| AC-11 | Device Lock | SWIFT.2.6 |
| AC-12 | Session Termination | SWIFT.2.6 |
| AC-17 | Remote Access | SWIFT.2.6 |
| AC-20 | Use of External Systems | SWIFT.1.4 |
AT Awareness and Training
AU Audit and Accountability
| Control | Name | SWIFT CSCF References |
|---|---|---|
| AU-02 | Event Logging | SWIFT.1.2SWIFT.2.9SWIFT.5.4SWIFT.6.4 |
| AU-03 | Content of Audit Records | SWIFT.6.4 |
| AU-06 | Audit Record Review, Analysis, and Reporting | SWIFT.2.9SWIFT.6.4 |
| AU-09 | Protection of Audit Information | SWIFT.6.4 |
| AU-12 | Audit Record Generation | SWIFT.6.4 |
| AU-14 | Session Audit | SWIFT.2.6 |
CA Security Assessment and Authorization
CM Configuration Management
| Control | Name | SWIFT CSCF References |
|---|---|---|
| CM-02 | Baseline Configuration | SWIFT.2.3 |
| CM-03 | Configuration Change Control | SWIFT.6.2 |
| CM-05 | Access Restrictions for Change | SWIFT.6.2 |
| CM-06 | Configuration Settings | SWIFT.1.3SWIFT.2.3SWIFT.2.10 |
| CM-07 | Least Functionality | SWIFT.1.1SWIFT.1.4SWIFT.2.2SWIFT.2.3SWIFT.2.10 |
| CM-08 | System Component Inventory | SWIFT.2.7 |
CP Contingency Planning
IA Identification and Authentication
IR Incident Response
MP Media Protection
PE Physical and Environmental Protection
PM Program Management
| Control | Name | SWIFT CSCF References |
|---|---|---|
| PM-16 | Threat Awareness Program | SWIFT.7.4A |
PS Personnel Security
RA Risk Assessment
SA System and Services Acquisition
SC System and Communications Protection
| Control | Name | SWIFT CSCF References |
|---|---|---|
| SC-07 | Boundary Protection | SWIFT.1.1SWIFT.1.3SWIFT.1.4SWIFT.1.5SWIFT.2.3SWIFT.6.5A |
| SC-08 | Transmission Confidentiality and Integrity | SWIFT.2.1SWIFT.2.4ASWIFT.2.5ASWIFT.2.6 |
| SC-12 | Cryptographic Key Establishment and Management | SWIFT.2.1SWIFT.2.5A |
| SC-13 | Cryptographic Protection | SWIFT.2.1SWIFT.2.4A |
| SC-28 | Protection of Information at Rest | SWIFT.1.3SWIFT.2.5ASWIFT.5.4SWIFT.6.3 |
| SC-32 | System Partitioning | SWIFT.1.1 |
| SC-39 | Process Isolation | SWIFT.1.3 |