← Frameworks / Financial Security

SWIFT Customer Security Controls Framework v2024

Mandatory security controls framework for all 11,000+ SWIFT-connected financial institutions globally. 32 controls (25 mandatory, 7 advisory) across 3 objectives: secure your environment, know and limit access, detect and respond. Annual independent assessment attestation required. Covers network segmentation, privileged access, system hardening, transaction business controls, malware protection, logging/monitoring, and incident response for SWIFT financial messaging infrastructure. Aligned with ISO 27002, NIST CSF, PCI DSS 4.0.

Clause Title SP 800-53 Controls
SWIFT.1.1 SWIFT Environment Protection (Mandatory)
SWIFT.1.2 Operating System Privileged Account Control (Mandatory)
SWIFT.1.3 Virtualisation or Cloud Platform Protection (Mandatory)
SWIFT.1.4 Restriction of Internet Access (Mandatory)
SWIFT.1.5 Customer Environment Protection (Mandatory)
SWIFT.2.1 Internal Data Flow Security (Mandatory)
SWIFT.2.2 Security Updates (Mandatory)
SWIFT.2.3 System Hardening (Mandatory)
SWIFT.2.4A Back Office Data Flow Security (Advisory)
SWIFT.2.5A External Transmission Data Protection (Advisory)
SWIFT.2.6 Operator Session Confidentiality and Integrity (Mandatory)
SWIFT.2.7 Vulnerability Scanning (Mandatory)
SWIFT.2.8 Outsourced Critical Activity Protection (Mandatory)
SWIFT.2.9 Transaction Business Controls (Mandatory)
SWIFT.2.10 Application Hardening (Mandatory)
SWIFT.2.11A RMA Business Controls (Advisory)
SWIFT.3.1 Physical Security (Mandatory)
SWIFT.4.1 Password Policy (Mandatory)
SWIFT.4.2 Multi-Factor Authentication (Mandatory)
SWIFT.5.1 Logical Access Control (Mandatory)
SWIFT.5.2 Token Management (Mandatory)
SWIFT.5.3A Staff Screening Process (Advisory)
SWIFT.5.4 Password Repository Protection (Mandatory)
SWIFT.6.1 Malware Protection (Mandatory)
SWIFT.6.2 Software Integrity (Mandatory)
SWIFT.6.3 Database Integrity (Mandatory)
SWIFT.6.4 Logging and Monitoring (Mandatory)
SWIFT.6.5A Intrusion Detection (Advisory)
SWIFT.7.1 Cyber Incident Response Planning (Mandatory)
SWIFT.7.2 Security Training and Awareness (Mandatory)
SWIFT.7.3A Penetration Testing (Advisory)
SWIFT.7.4A Scenario-Based Risk Assessment (Advisory)