The CSP Assessment

Time to Independently Assess

IBIS Management and Finastra, a SWIFT listed expert, assures timely compliance if you apply today!
Effective since 2021, SWIFT mandated that all Customer Security Programme (CSP) attestations must be independently assessed annually, to help combat fraudulent activities. Finastra, our service bureau partner, successfully launched an independent assessment service in 2021 to support customers through this process, and has since been helping many to achieve SWIFT CSP compliance. 

Have you chosen an Independent CSP Assessment Provider yet?

SWIFT’s Customer Security Programme (CSP) is a common set of security controls aimed at assisting users to secure their SWIFT environments. The SWIFT Customer Security Controls Framework (CSCF) consists of both mandatory and advisory security controls. These mandatory security controls establish a general security baseline and must be implemented by all users, including those that use a Service Bureau.

Please take note of the timeline of sign-up window and timeline of project scope below

To ensure that SWIFT members and all SWISSRoute and or Alchemy clients comply on time, IBIS Management is offering independent CSP assessment services through Finastra. Hire certified professionals that know your needs and environment best. Finastra is also listed on SWIFT’s directory of independent CSP providers and complies with the required criteria. 

The CSP assessment scope

Finastra’s assessment scope covers all mandatory controls and components of the SWIFT-related infrastructure, which include the following:

Data exchange layer

Local SWIFT infrastructure

– Secure zone

– Messaging interface

– Communication interface

– SWIFTNet Link (SNL)

– Connector

– SWIFT hardware security modules (HSMs)

– Firewalls, routers and switches surrounding the SWIFT infrastructure

– Graphical user interface (GUI)

– Jump server

– Virtualization platform

– Dedicated operator PC 

Operators and their general purpose operator PCs

Finastra’s CSP service includes

• Scope and architecture type assessment
 
• Project plan to achieve attestation
 
• Scope document detailing architecture model; relevant infrastructures and applications; message flows; users and in-scope assets
 
• Controls tracker – a detailed breakdown of compliance against each CSCF control requirement
 
• Attestation report – detailed findings against each SWIFT CSCF control, including supporting evidence, assessment, gap analysis and recommendations
 
• Remediation report, including remediation path
 
• Executive summary report
 
• Bi-monthly steering group follow up (optional)

Contact a consultant today before the sign-up window closes