Decision Tree To Guide SWIFT Users To Determine Their CSP Architecture Type
Decision Tree To Guide SWIFT Users To Determine Their CSP Architecture Type
Purpose
This document proposes a decision tree to guide SWIFT users to determine their CSP Architecture
type. It is provided for information and illustrative purposes. While designed to provide useful
guidance to SWIFT users to determine their CSP Architecture Type, nothing in this document shall be
interpreted or construed as replacing or otherwise amending the Customer Security Controls
Framework and Customer Security Controls Policy. General principles (or Architecture Types) are not
given any restrictive meaning when they are illustrated with examples.
Audience
This document targets: (i) SWIFT users that need to determine their Architecture Type, (ii) firms
selected by SWIFT users to assist them in this exercise and, (iii) service bureaux that support their
customers in the determination of the Architecture Type.
Sections contents
# Section Contents
Guides the SWIFT user of FIN service (potentially with other
1 FIN Users services) to determine the Architecture Type use in their local
SWIFT Infrastructure.
Guides the SWIFT users of non-FIN messaging services (i.e.
Non FIN Users (i.e. SWIFTNet
2 InterAct, FileAct, or WebAccess (Browse)) to determine the
Users)
Architecture Type for their local SWIFT infrastructure.
SWIFT products & Architecture Replaced by Reference to the TIP 5024040
3
Types
Architecture Types for CREST Guides CREST users to determine their Architecture Type.
4
BICs
Provide Guidance to determine users’ Architecture Type for some
5 Exceptions
exceptional set ups.
Provide examples of Architecture Types for SWIFT users using a
6 Examples of Architecture Types (i), a group hub, (ii) service bureau, (iii) web service or (iv) shared
ARG
1. FIN USERS
Go to Section Non
Fin User No
FIN Users
Yes
No
Application-to-application flow
Yes
from BO?
Using a
yes A3
No (user to application flow) connector
A1
B
No
(Using Middleware or API)
B
Start
2. NON FIN
USERS FIN users Yes
Go to Section FIN
Users
No
Yes
Owner of the
No
MI ?
Use
connector?
Application-to-application flow
from BO ?
Yes
No
Yes
Using a
yes A3
connector
Yes B
No
(Using Middleware or API)
No
(user-to-application flow)
A2
B
A3
(*) See Introduction to determine cases when a BO connecting to a MI is
to be considered as a CI
3. SWIFT Products & Architecture Types
Start
A2 A1
5. Exceptions
- In the rare cases when customers own only the Communication Interface and not the
Messaging Interface, controls A1 apply to the components in scope
(including the Communication Interface and the GUI as appropriate).
- Users of a messaging interface with no notion of owner BIC of the license, need to
define the BIC owner of the communication Interface as A1 while the other BIC codes
defined on the same messaging Interface need to attest as A2
- Shared ARG customers, i.e. using the Access owned by an ARG customer must select
the A3 or B architecture type.
6. Examples of Architecture Types
1. Group Hub Set ups
Architecture Type A1
Alliance Access
Alliance Gateway
SWIFT network
SWIFTNet Link
HSM PKI
(*)
Scope of security controls Alliance Web Platform
Alliance Access
Alliance Gateway
Alliance Access
SWIFT network
SWIFTNet Link
End User
SWIFT network
SWIFTNet Link
Alliance Gateway
SWIFT network
SWIFTNet Link
General
Enterprise IT
Environment
HSM PKI
Messaging Communication
Interface Interface
Back Office
RMA SNL
or Data exchange
Middleware
HSM PKI
GUI
SWIFTNet
Service Bureau
SWIFT User
framework
Institution connecting its Messaging Interface to a Service Bureau– A3 – File
server solution
SBXAXXXX
General Enterprise IT Environment
Scope of security
Communication
Back Office
Data exchange Interface
or Connector
Middleware
GUI
SNL
SWIFTNet
HSM PKI
framework
Institution connecting its BO to a Service Bureau– Architecture Type- B Subject to CSP controls framework.
Strongly recommended to consider
A3 controls for Back Office and
Middleware
General Enterprise IT Environment
Messaging
Interface
Admin End User RMA
Communication
Server Environment Interface
GUI
Back Office Data exchange
or
Middleware SNL
SWIFTNet
HSM PKI
https
End User
General Enterprise IT Environment
Server Environment
Scope of Security
GUI
Alliance
Lite2
Alliance
Lite2
Admin
SWIFT network
Business MultiBic
Back-Office Application AutoClient
RTGS
End User
Alliance Gateway
SWIFT network
SWIFTNet Link
HSM PKI
13
End User
Alliance Access
SWIFT network
15
End User
Admin
Scope of security controls
16