0% found this document useful (0 votes)
171 views

SWIFT Customer Security Programme: The Essentials

SWIFT
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
171 views

SWIFT Customer Security Programme: The Essentials

SWIFT
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 2

SWIFT Customer

Security Programme
The essentials

December 2020

Why is it important?
What is the SWIFT Customer In response to a number of cyber In 2020*, SWIFT promoted 2 existing
Security Programme (CSP)? attacks and breaches throughout advisory controls to mandatory and
2016, in 2017 SWIFT identified, 16 introduced 2 new advisory controls
mandatory and 11 optional security resulting in 21 mandatory and 10
SWIFT has introduced its Customer controls for all of its 11,000 advisory controls in the CSCF
Security Controls Framework customers worldwide. All customers V2020. For 2021, SWIFT promoted 1
(CSCF) to drive security are asked to attest to meeting the control to mandatory resulting in 22
improvement and transparency controls on an annual basis, and the mandatory and 9 advisory controls in
across the global financial results of same are shared with the CSCF v2021. As from mid-2021,
community.The SWIFT CSP counterparts and regulators. organizations will need to support
focuses on three mutually How will this impact their attestation against CSCF
reinforcing areas: protecting and SWIFT customers? v2021 with an independent internal
securing your local environment, or external assessment.
preventing and detecting fraud in The SWIFT CSP has evolved, and will
your commercial relationships, and continue to do so, since inception. What are the success factors?
continuously sharing information Customers will need to continue to To be successful, organisations must
and preparing to defend against implement security controls and raise take a thoughtful and systematic
future cyber threats. the bar to ensure compliance with the approach, requiring collaboration
CSCF. Previously, SWIFT customers across the three lines of defence,
While all customers remain were required to self-attest to the
primarily responsible for protecting strong leadership and a diverse
CSCF V2019 by 31 December 2019. organised team. Are you ready for
their own environments, SWIFT’s This updated framework contained 19
CSP aims to support its community this increased level of mandatory
mandatory and 10 advisory requirements?
in the fight against cyber-attacks. security controls.

How is the SWIFT CSP framework structured?

Security principles Controls objectives Controls

Description – Includes items such Validation measures – Includes the


as control frequency, who or what method by which control design and
performs the action, what action was effectiveness will be validated, the
performed and what action or effect frequency and associated artefacts
is the result.
Components – Includes specific Owner – Includes information related
people, process and technology to the control owner such as name
elements associate with the control. and functional title.

*Given the global COVID-19 situation SWIFT has published updated guidelines on 18 June 2020 regarding
changes to CSP self-attestation and independent assessment requirements for 2020. SWIFT has announced that
in 2020, customers can self-attest against the 2019 version of the SWIFT CSP and can optionally support the
self-attestation with an independent assessment. In 2021, independent assessment will be a mandatory
requirement and customers will be required to attest against the 2021 version of the CSP framework.
What milestones should you be aware of?
2020 2020 2021 2021

Annual attestation Self-attestation SWIFT CSP v 2021 Independent assessment


Comply with the CSCF v2019 submission Customers must comply with SWIFT requires all customers
or optionally against the CSCF SWIFT will require all CSCF v2021 including to support their attestation with
v2020 framework organisations to submit their 22 mandatory and 9 an independent assessment by
attestation for 2020 by the end of 2021
advisory controls
31 Dec 2020

PwC capabilities
How can Pwc help to meet SWIFT’S Independent assessment?
SWIFT CSP assessment Embedded in internal audit
A detailed independent assessment of Work alongside your Internal Audit,
SWIFT CSP controls by leveraging our Information Technology, and/or Risk
CSP accelerator functions to report on SWIFT CSP controls

Additional cyber security services

Cybersecurity Vulnerability Security Awareness


Governance and Risk Assessments and Training using PwC’s
Incident Response
Assessments Penetration Testing Game of Threats

Why PwC? Contacts


Proven CSP assurance experience Carolyn Bell-Wisdom
We have performed numerous SWIFT CSP assessment Partner, Risk Assurance Services
engagements across multiple territories and industries. M: +1(876)383 8949
E: [email protected]

Cohesive team who understands SWIFT Anthony Zamore


We understand SWIFT like no other and our team consists Director, Advisory Services
of qualified IT security experts with experience conducting M: +1(868)331 7707
reviews on SWIFT systems. Our regional teams are also E: [email protected]
supported by PwC SWIFT CSP experts.
Alessandro Frenza
Adapting to your requirements Global SWIFT CSP Lead (Cyber Security)
PwC will leverage inhouse accelerators and our extensive M: +44(0)7493 319240
SWIFT CSP expertise to ensure that your needs are met E: [email protected]
ahead of SWIFTs required independent assessment due on
31 December 2021.

For further information refer to:


pwc.com/tt/swift

This content is for general information purposes only, and should not be used as a substitute for consultation with professional advisors.
© 2020 PwC. All rights reserved. PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity. Please see
www.pwc.com/structure for further details.

You might also like