CFTC System Safeguards (17 CFR 37, 38, 39, 49)
CFTC System Safeguards: Risk Analysis and Oversight Program

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-2: Enterprise Risk Management and Governance Category

Address enterprise risk management and governance within the program, covering assessment, mitigation and monitoring of security and technology risk, security and technology capital planning and investment, board and management oversight, technology audit and controls assessments, and remediation of deficiencies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 53 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.RR-02 Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced
  • CPS230-13 Board Accountability for Operational Risk Management
  • CPS230-14 Board Setting of Senior Manager Roles and Responsibilities
  • CPS230-15 Operational Risk Elements of the Risk Management Framework
  • CPS230-16 Internal Audit Review of the Business Continuity Plan

FedRAMP High · 4 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • RA-3 Risk Assessment

FedRAMP Moderate · 4 controls

  • CA-2 Control Assessments
  • CA-5 Plan of Action and Milestones
  • CA-7(4) Continuous Monitoring | Risk Monitoring (CA-7(4))
  • RA-3 Risk Assessment

HIPAA Security Rule · 4 controls

NIST SP 800-161 Rev 1 · 4 controls

NIST SP 800-66 Rev 2 · 4 controls

PCI DSS 4.0 · 4 controls

  • 12.1.1 12.1.1 Overall information security policy established and disseminated
  • 12.1.3 12.1.3 Security roles defined and acknowledged by all personnel
  • 12.3.1 12.3.1 Targeted risk analysis for flexible-frequency requirements
  • 12.4.1 12.4.1 Executive responsibility for a PCI DSS compliance program

C5 (Germany) · 3 controls

  • C5-COM-03 Internal audits of the information security management system
  • C5-COM-04 Information on information security performance and management assessment of the ISMS
  • C5-OIS-07 Application of the Risk Management Policy

SOC 2 · 3 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)

DORA · 2 controls

  • GS-1 Align organization roles, responsibilities and accountabilities

ISO 22301:2019 · 1 control

  • 5.3 Roles, responsibilities and authorities

ISO 27001:2022 · 1 control

  • 5.2 Information security roles and responsibilities

ISO 27002:2022 · 1 control

  • 5.2 Information security roles and responsibilities

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CFTC System Safeguards: Risk Analysis and Oversight Program

You are reading one control. How much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) have you already done?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 28 of 39 CFTC System Safeguards (17 CFR 37, 38, 39, 49) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.

Query this from an agent

The graph holds this control, the 53 it maps to, and the evidence behind each claim, over MCP and REST.