Swift Customer Security Programme Assessor Certification(CSPAC) CSP-Assessor Question # 13 Topic 2 Discussion

Swift Customer Security Programme Assessor Certification(CSPAC) CSP-Assessor Question # 13 Topic 2 Discussion

CSP-Assessor Exam Topic 2 Question 13 Discussion:
Question #: 13
Topic #: 2

An application only uses (i) the SWIFT API for reporting and gpi basic tracker calls through (ii) a tailored account not allowing business transactions management. Is this application in scope of the CSCF? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template


A.

Yes, it is in scope and considered a customer connector because it reads business transaction data


B.

No, it can be descoped because there is no business transaction management being performed


C.

No, it is not in scope because the API connection method is not in scope of the CSP


D.

Yes, it is in scope because the API connection method is less secure than SWIFT interfaces


Get Premium CSP-Assessor Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.