SWIFT CSCF
Physical Security

SWIFT CSCF SWIFTCSCF-3: Physically Secure the Environment (Objective 3)

Per SWIFT CSCF Objective 3: Physical Security including data centre + administrator workstations + media.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 35 controls across 22 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • QMSR-820.10 Requirements for a Quality Management System - ISO 13485:2016 Sections 4-8 incorporation (§820.10)
  • QMSR-ISO13485-Sec6 Resource management (ISO 13485:2016 Section 6 - incorporated via §820.10)
  • QMSR-ISO13485-Sec7_Purchasing Purchasing controls + supplier management (ISO 13485:2016 Section 7.4)
  • QMSR-ISO13485-Sec8 Measurement, analysis and improvement (ISO 13485:2016 Section 8)
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • PICSGMP-3 Chapter 3: Premises and Equipment - Design, Qualification, Calibration
  • PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • GGAP-IFA-CropsBase-Production-PPP-IPM GLOBALG.A.P. IFA v6 Crops Base (CB): Propagation, Soil, Water, IPM, PPP, Fertilizer and Harvest
  • IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement
  • IATF16949-Clause4-Context-Scope-CustomerSpecific-ProductSafety IATF 16949 Clause 4 - Context of Organization + QMS Scope + Customer Specific Requirements + Product Safety
  • AQAP2110-7 Production, Special Processes, Inspection, Testing, and Records
  • AQAP2110-8 Internal Audit, Management Review, Corrective Action, CofC, and Continual Improvement

PCI DSS 4.0 · 2 controls

  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 2.1.3 Food Safety and Quality Culture
  • 2.5.2 Verification Activities
  • FSSC-Additional-Requirements-v6 FSSC 22000 Additional Requirements v6 (Food Defense + Food Fraud + Allergen + Environmental + Culture)
  • ICAO-ANX17-Chap3-QualityControl-Audits-Inspections-Tests-Certification-Training ICAO Annex 17 Chapter 3 - National Quality Control Programme + Audits + Inspections + Tests + Surveys + Certification + Aviation Security Training Programme (ASTP)
  • IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience

ISO/IEC 27014:2020 · 1 control

  • 27014-5.6 Continuous improvement
  • ITAR-CompliancProgram-ICP-EmpoweredOfficial-Recordkeeping-5Years-Training-IT-Cloud-SupplyChain-Coord-EAR-OFAC-Wassenaar ITAR Compliance Program + Internal Compliance Program (ICP) + Empowered Official + 5-Year Recordkeeping + Training + IT/Cloud (GovCloud + Azure Gov + GCC High) + Supply Chain + Coord EAR + OFAC + Wassenaar + MTCR

NIST SP 800-30 · 1 control

  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

NIST SP 800-37 · 1 control

  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 1 control

  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 35 it maps to, and the evidence behind each claim, over MCP and REST.