United States (CFTC)

CFTC System Safeguards (17 CFR 37, 38, 39, 49)

39 controls. 27 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

39 controls 27 frameworks share controls with it United States (CFTC) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CFTC-SS-1Program of Risk Analysis and Oversight22
CFTC-SS-10Geographic Dispersal of Backup Infrastructure and Personnel16
CFTC-SS-11Testing and Review of Business Continuity and Disaster Recovery Capabilities20
CFTC-SS-12Capacity and Performance Planning Category16
CFTC-SS-13Vulnerability Testing21
CFTC-SS-14External Penetration Testing15
CFTC-SS-15Controls Testing23
CFTC-SS-16Security Incident Response Plan and Testing23
CFTC-SS-17Enterprise Technology Risk Assessment19
CFTC-SS-18Independence of Testers17
CFTC-SS-19Prompt Notification to the Commission23
CFTC-SS-2Enterprise Risk Management and Governance Category21
CFTC-SS-20Production of System Safeguards Books and Records21
CFTC-SS-21Remediation of Vulnerabilities and Deficiencies23
CFTC-SS-22Business Continuity and Disaster Recovery Planning Category16
CFTC-SS-23Resources Sufficient to Fulfil Obligations15
CFTC-SS-24Periodic Update of the Recovery Plan and Emergency Procedures16
CFTC-SS-25Same Day Recovery Time Objective for Critical Entities10
CFTC-SS-26Own Resources or Contractual Arrangements to Meet the Recovery Objective21
CFTC-SS-27Coordination of the Recovery Plan with Members and Market Participants11
CFTC-SS-28Synchronised Testing with Members and Market Participants10
CFTC-SS-29Recovery Plan Accounts for Essential Service Providers17
CFTC-SS-3Information Security Category26
CFTC-SS-30Outsourcing with Retention of Complete Responsibility22
CFTC-SS-31Testing Covers Outsourced Resources and Tester Independence from Providers17
CFTC-SS-32Timely Advance Notice of Material Planned Changes16
CFTC-SS-33Regular Periodic Objective Testing and Review of Automated Systems20
CFTC-SS-34Internal Penetration Testing15
CFTC-SS-35Scope of Testing and Assessment16
CFTC-SS-36Internal Reporting and Review by Senior Management and the Board18
CFTC-SS-37Protection of Swap Data Repository Data21
CFTC-SS-38Production of Annual Total Trading Volume5
CFTC-SS-39Critical Financial Market Designation Obligations8
CFTC-SS-4Systems Operations Category22
CFTC-SS-5Systems Development and Quality Assurance Category22
CFTC-SS-6Physical Security and Environmental Controls Category20
CFTC-SS-7Generally Accepted Standards and Best Practices15
CFTC-SS-8Business Continuity and Disaster Recovery Plan and Resources21
CFTC-SS-9Next Business Day Recovery Time Objective19

Tell me when CFTC System Safeguards (17 CFR 37, 38, 39, 49) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Control testing plan
  • Test results
  • Effectiveness metrics
  • Remediation plan
  • internal audit plan and schedule
  • internal audit reports of the ISMS
  • list of controls in scope with the basis for inclusion
  • reference to the system security and privacy plans
  • record of controls excluded and why
  • evidence scope matches the purpose of the assessment

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for CFTC System Safeguards (17 CFR 37, 38, 39, 49), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition