Pass the Swift Customer Security Programme (CSP) CSP-Assessor Questions and answers with CertsForce

Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions
Questions # 11:

When hesitant on the applicability of a CSCF control to a particular component? What steps should you take? (Choose all that apply.)

Question # 11

Options:

A.

Call your Swift contact


B.

Check appendix F of the CSCF


C.

Check carefully the Introduction section of the CSCF


D.

Open a case with Swift support via the case manager on swift com if further information or solution cannot be found in the documentation


Expert Solution
Questions # 12:

What are the three main objectives of the Customer Security Controls Framework? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

Options:

A.

1. Secure your environment

2. Know and Limit Access

3. Detect and Respond


B.

1. Restrict Internet Access and Protect Critical Systems from General IT Environment

2. Reduce Attack Surface and Vulnerabilities

3. Physically Secure the Environment


C.

1. Secure and Protect

2. Prevent and Detect

3. Share and Prepare


D.

1. Raise pragmatically the security bar

2. Maintain appropriate cyber-security hygiene

3. React promptly


Expert Solution
Questions # 13:

An application only uses (i) the SWIFT API for reporting and gpi basic tracker calls through (ii) a tailored account not allowing business transactions management. Is this application in scope of the CSCF? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

Yes, it is in scope and considered a customer connector because it reads business transaction data


B.

No, it can be descoped because there is no business transaction management being performed


C.

No, it is not in scope because the API connection method is not in scope of the CSP


D.

Yes, it is in scope because the API connection method is less secure than SWIFT interfaces


Expert Solution
Questions # 14:

Must Swift users submit a copy of their final assessment report to Swift?

Question # 14

Options:

A.

Yes, all documents produced from the assessment must be provided proactively to Swift


B.

No, it is not required to provide Swift with any documents by default. However, Swift can request a copy of the Assessment completion letter


C.

Yes, a copy of (only) the assessment report must be provided to Swift, no other documents


D.

Yes, in cases where a customer performs an Independent assessment rather than an audit then a copy of the assessment report must be provided. However, it is not required for the Swift user to provide any forms when an Internal/External Audit is performed


Expert Solution
Questions # 15:

A Swift user has moved from one Service Bureau to another What are the obligations of the Swift user in the CSP context?

Question # 15

Options:

A.

To inform the SB certification office at Swift WW


B.

To reflect that in the next attestation cycle


C.

None if there is no impact in the architecture tope


D.

To submit an updated attestation reflecting this change within 3 months


Expert Solution
Questions # 16:

As a SWIFT CSP Certified Assessor, my external cybersecurity certification (example: CISA) has expired. Am I still allowed to work as a certified assessor?

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

No, a valid external cybersecurity certification is mandatory to keep the CSP Certified Assessor certification


B.

Yes, if the SWIFT CSP Assessor certification is still valid


Expert Solution
Questions # 17:

Must all CSCF controls be subject to an assessment?

Question # 17

Options:

A.

Yes


B.

No, only the mandatory controls


C.

No, only the attested controls (with as a minimum the mandatory ones]


D.

No, the control selection is defined between the Swift User and their assessor


Expert Solution
Questions # 18:

Select the environment that is not in scope in a SWIFT user CSP assessment (assuming the environments are separated).

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

SWIFT infrastructure (sometimes known as Live)


B.

Development


C.

Disaster Recovery


D.

Cold backup systems


Expert Solution
Questions # 19:

Is it necessary to formally explain to the Swift user the testing methodology that will be used for the CSP assessment during the kick-off?

Question # 19

Options:

A.

Yes


B.

No


Expert Solution
Questions # 20:

Which operator session flows are expected to be protected in terms of confidentiality and integrity? (Select the correct answer)

•Swift Customer Security Controls Policy

•Swift Customer Security Controls Framework v2025

•Independent Assessment Framework

•Independent Assessment Process for Assessors Guidelines

•Independent Assessment Framework - High-Level Test Plan Guidelines

•Outsourcing Agents - Security Requirements Baseline v2025

•CSP Architecture Type - Decision tree

•CSP_controls_matrix_and_high_test_plan_2025

•Assessment template for Mandatory controls

•Assessment template for Advisory controls

•CSCF Assessment Completion Letter

•Swift_CSP_Assessment_Report_Template

Options:

A.

System administrator sessions towards a host running a SWIFT-related component (on-premises or remote)


B.

All sessions to and from a jump server used to access a component in a secure zone


C.

All sessions towards a SWIFT-related application run by an Outsourcing Agent, a Service Bureau, or an L2BA Provider


D.

All of the other answers are valid


Expert Solution
Viewing page 2 out of 4 pages
Viewing questions 11-20 out of questions