Deutsch: această pagină nu e încă tradusă. Textul de mai jos e în English.
Every institution connected to the SWIFT network must attest annually against the controls in the Customer Security Controls Framework (CSCF). What many underestimate is that, since 2021, the attestation no longer takes your word for it: it is valid only if backed by an independent assessment — internal (an audit function independent of operations) or, more commonly, an external assessor. Without it, you are non-compliant, regardless of what you ticked. This is where we come in, as the external assessor, with the report SWIFT requires.
The first step that changes everything: architecture type
Not all controls apply to everyone. What applies to you depends on your architecture type (A1–A4 or B) — how much of the SWIFT infrastructure you own and operate. A wrong determination here means either wasted effort or missed controls. That is why we establish it correctly before anything else.
What we assess
CSCF groups controls under three objectives — secure your environment, know and limit access, detect and respond — with mandatory and advisory controls. In short, we look at:
- Separation of SWIFT infrastructure from the rest of the network (secure zone) and internet access restriction
- Operating system and product hardening, multi-factor authentication
- Least privilege and privileged access management
- Physical security, logging, anomaly detection and incident response
How it works and what you get
We establish architecture type → define the secure zone → assess each applicable control, design and operating effectiveness → produce the independent assessment report (per the Independent Assessment Framework) → support your annual attestation (KYC-SA). You receive the architecture type determination, control-by-control assessment with evidence, the independent assessment report and a remediation roadmap. We also flag advisory controls that become mandatory in upcoming cycles, so you are not caught off guard.