CSP-Assessor Customer Security Programme Assessor Certification(CSPAC) Questions and Answers
The Alliance Web Platform Administrator uses both the GUI and command line to perform configuration and monitoring tasks on AWP SE.

The SWIFT PKI certificates are used for… (Select the correct answer)
• Connectivity
• Generic
• Products Cloud
• Products OnPrem
• Security
Which of the following infrastructures has the smallest SWIFT footprint? (Select the correct answer)
• Connectivity
• Generic
• Products Cloud
• Products OnPrem
• Security
Is the restriction of Internet access only relevant when having SWIFT-related components in a secure zone?
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
The Physical Security control also includes a regular review of physical access lists of the SWIFT-related servers' locations.
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
Select the correct statement about SWIFT Alliance Cloud.
• Connectivity
• Generic
• Products Cloud
• Products OnPrem
• Security
The Swift user would like to perform their CSP assessment in May for the CSCF version that will only be active as from July the same year. Is it allowed?

The outsourcing agent of the SWIFT user provided them with an independent assessment report covering the CSP components in their scope, and using the latest CSCF version for testing. Is it enough to support the CSP attestation for the outsourced components? (Select the correct answer)
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
• CSCF Assessment Completion Letter
• Swift_CSP_Assessment_Report_Template
In the context of CSP, what type of component is the Alliance Access? (Select the correct answer)
• Connectivity
• Generic
• Products Cloud
• Products OnPrem
• Security
The bridging servers supporting the data exchange between the back-office and the SWIFT infrastructure are in scope of security controls (for some as advisory).
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
A detailed CSP assessment report has been provided to the Swift user following the assessment. Is a completion letter also mandated to be supplied?

From the outsourcing agent diagram, which components in the diagram are in scope and applicable for the Swift user.


In an entity having a small infrastructure and only 2 operators, the HR manager explains in a short interview how the security training is implemented providing one example. Would it be acceptable?

On which one of the following components must a Password/PIN Policy not be defined and implemented as per the CSCF? (Select the correct answer)
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
In the illustration, identify the component type of each of the numbered components.


Select the supporting documents to conduct a CSP assessment. (Choose all that apply.)

The Physical Security protection control is also aimed at protecting the “on call” and “working from home” employees’ equipment used to access the Swift-related components.

Select the correct statement(s) about the Swift Alliance Gateway. (Choose all that apply.)

What are the possible impacts for a SWIFT user to be non-compliant to CSP? (Select the two correct answers that apply)
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
• CSCF Assessment Completion Letter
• Swift_CSP_Assessment_Report_Template
Application Hardening basically applies the following principles. (Choose all that apply.)

A SWIFT user is not based in the same country as the assessor. The assessor would like to perform the assessment remotely. Is this permitted? (Select the correct answer)
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
• CSCF Assessment Completion Letter
• Swift_CSP_Assessment_Report_Template
What type of control effectiveness needs to be validated for an independent assessment?

The Internal Audit and an external assessment company are both involved in a SWIFT user’s assessment. Both have shared control assessments to cover the full scope (meaning two separate assessment teams). Who needs to provide a completion letter? (Select the correct answer)
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
• CSCF Assessment Completion Letter
• Swift_CSP_Assessment_Report_Template
As a SWIFT CSP Certified Assessor, my external cybersecurity certification (example: CISA) has expired. Am I still allowed to work as a certified assessor?
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
• CSCF Assessment Completion Letter
• Swift_CSP_Assessment_Report_Template
The SWIFT user has a local communication interface as their main channel to SWIFT. For contingency, the SWIFT user also has a connector as a backup channel. What is the architecture type for this SWIFT user? (Select the correct answer)
• Swift Customer Security Controls Policy
• Swift Customer Security Controls Framework v2025
• Independent Assessment Framework
• Independent Assessment Process for Assessors Guidelines
• Independent Assessment Framework - High-Level Test Plan Guidelines
• Outsourcing Agents - Security Requirements Baseline v2025
• CSP Architecture Type - Decision tree
• CSP_controls_matrix_and_high_test_plan_2025
• Assessment template for Mandatory controls
• Assessment template for Advisory controls
• CSCF Assessment Completion Letter
• Swift CSP Assessment Report Template
The SwiftNet Link (SNL) software is always required for the Swift Alliance Gateway to operate.
• Connectivity
• Generic
• Products Cloud
• Products OnPrem
• Security
Can an internal audit department submit and approve their Swift user's attestation on the KYC-SA Swift portal?

How can PKI certificate requests be submitted to SWIFT? (Select the correct answer)
• Connectivity
• Generic
• Products Cloud
• Products OnPrem
• Security
The objective of the Customer Environment Protection control is to separate the user's Swift infrastructure which restricts malicious access from the external world and from the General IT environment of the Swift user.


