CFTC System Safeguards (17 CFR 37, 38, 39, 49)
CFTC System Safeguards: Risk Analysis and Oversight Program

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-3: Information Security Category

Address information security within the program, covering access to systems and data with least privilege, separation of duties and account monitoring, user and device identification and authentication, security awareness training, audit log maintenance and analysis, media protection, personnel security and screening, system and communications protection, system and information integrity, vulnerability management, penetration testing and security incident response.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 273 controls across 23 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

FedRAMP High · 24 controls

  • AC-1 Policy and Procedures
  • AC-2 Account Management
  • AC-3 Access Enforcement
  • AC-5 Separation of Duties
  • AC-6 Least Privilege
  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-3 Device Identification and Authentication
  • IA-4 Identifier Management
  • IR-5 Incident Monitoring
  • MP-1 Policy and Procedures
  • MP-4 Media Storage
  • MP-6 Media Sanitization
  • PS-1 Policy and Procedures
  • PS-3 Personnel Screening
  • RA-5 Vulnerability Monitoring and Scanning
  • SC-7 Boundary Protection
  • SC-8 Transmission Confidentiality and Integrity
  • SI-3 Malicious Code Protection
  • SI-4 System Monitoring

FedRAMP Moderate · 24 controls

  • AC-1 Policy and Procedures
  • AC-2 Account Management
  • AC-3 Access Enforcement
  • AC-5 Separation of Duties
  • AC-6 Least Privilege
  • AT-1 Policy and Procedures
  • AT-2 Literacy Training and Awareness
  • AU-12 Audit Record Generation
  • AU-2 Event Logging
  • AU-6 Audit Record Review, Analysis, and Reporting
  • IA-2 Identification and Authentication (Organizational Users)
  • IA-3 Device Identification and Authentication
  • IA-4 Identifier Management
  • IR-5 Incident Monitoring
  • MP-1 Policy and Procedures
  • MP-4 Media Storage
  • MP-6 Media Sanitization
  • PS-1 Policy and Procedures
  • PS-3 Personnel Screening
  • RA-5 Vulnerability Monitoring and Scanning
  • SC-7 Boundary Protection
  • SC-8 Transmission Confidentiality and Integrity
  • SI-3 Malicious Code Protection
  • SI-4 System Monitoring

ISO 27001:2022 · 24 controls

  • 5.14 Information transfer
  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 5.19 Information security in supplier relationships
  • 5.2 Information security roles and responsibilities
  • 5.23 Information security for use of cloud services
  • 5.24 Information security incident management planning and preparation 
  • 5.29 Information security during disruption
  • 5.3 Segregation of duties
  • 5.8 Information security in project management
  • 6.1 Screening
  • 6.3 Information security awareness, education and training
  • 6.8 Information security event reporting
  • 7.10 Storage media
  • 7.14 Secure disposal or re-use of equipment
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.2 Privileged access rights
  • 8.20 Networks security
  • 8.3 Information access restriction
  • 8.5 Secure authentication
  • 8.7 Protection against malware

ISO 27002:2022 · 23 controls

  • 0.2 Information security requirements
  • 5.14 Information transfer
  • 5.15 Access control
  • 5.16 Identity management
  • 5.17 Authentication information
  • 5.18 Access rights
  • 5.19 Information security in supplier relationships
  • 5.2 Information security roles and responsibilities
  • 5.23 Information security for use of cloud services
  • 5.29 Information security during disruption
  • 5.3 Segregation of duties
  • 6.1 Screening
  • 6.3 Information security awareness, education and training
  • 6.8 Information security event reporting
  • 7.10 Storage media
  • 7.14 Secure disposal or re-use of equipment
  • 8.15 Logging
  • 8.16 Monitoring activities
  • 8.2 Privileged access rights
  • 8.20 Networks security
  • 8.3 Information access restriction
  • 8.5 Secure authentication
  • 8.7 Protection against malware

NIST SP 800-53 Rev 5 · 23 controls

HIPAA Security Rule · 17 controls

NIST SP 800-171 Rev 3 · 16 controls

NIST SP 800-66 Rev 2 · 16 controls

  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • ASBv3-GS-4 Define and implement network security strategy
  • ASBv3-GS-6 Define and implement identity and privileged access strategy
  • ASBv3-LT-1 Enable threat detection capabilities
  • ASBv3-PA-4 Review and reconcile user access regularly
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • ES-2 Use modern anti-malware software
  • IM-1 Use centralized identity and authentication system
  • IM-6 Use strong authentication controls
  • LT-3 Enable logging for security investigation
  • LT-5 Centralize security log management and analysis
  • PA-1 Separate and limit highly privileged/administrative users

CMMC 2.0 · 13 controls

PCI DSS 4.0 · 13 controls

  • 10.2.1 10.2.1 Audit logging enabled on all system components
  • 10.4.1 10.4.1 Daily review of security-relevant logs
  • 12.6.1 12.6.1 Formal security awareness program
  • 12.6.3 12.6.3 Security awareness training on hire and annually with acknowledgment
  • 12.7.1 12.7.1 Pre-hire screening of personnel with CDE access
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 8.2.1 8.2.1 Unique ID assigned to every user
  • 8.3.1 8.3.1 Access authenticated with at least one factor
  • 9.4.1 9.4.1 Physical security of all media
  • 9.4.7 9.4.7 Destruction of electronic media
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 7.3.1 7.3.1 Need-to-know access control system covers all components
  • NIST-CSF-DE.CM-01 Networks and network services are monitored to find potentially adverse events
  • NIST-CSF-DE.CM-03 Personnel activity and technology usage are monitored to find potentially adverse events
  • NIST-CSF-GV.RR-04 Cybersecurity is included in human resources practices
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-03 Users, services, and hardware are authenticated
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.DS-02 The confidentiality, integrity, and availability of data-in-transit are protected
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage
  • NIST-CSF-PR.PS-04 Log records are generated and made available for continuous monitoring

CIS Controls v8 · 8 controls

  • CIS-10.1 Deploy and Maintain Anti-Malware Software
  • CIS-14.1 Establish and Maintain a Security Awareness Program
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.8 Define and Maintain Role-Based Access Control
  • CIS-8.1 Establish and Maintain an Audit Log Management Process
  • CIS-8.11 Conduct Audit Log Reviews

SOC 2 · 8 controls

  • SOC2-CC1.4 CC1.4 Attracting, developing and retaining competent people (COSO principle 4)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.7 CC6.7 Restricting and protecting information in transmission, movement and removal
  • SOC2-CC7.2 CC7.2 Monitoring system components for anomalies

ISO 27701:2019 · 7 controls

  • 5.2.4 Information security management system
  • 5.6.2 Information security risk assessment
  • 5.6.3 Information security risk treatment
  • 6.13 Information security incident management
  • 6.14.1 Information security continuity
  • 6.15.2 Information security reviews
  • 6.2 Information security policies

C5 (Germany) · 4 controls

  • C5-HR-01 Verification of qualification and trustworthiness
  • C5-IDM-01 Policy for user accounts and access rights
  • C5-OPS-10 Logging and Monitoring - Concept
  • C5-SIM-01 Policy for security incident management

NIST SP 800-161 Rev 1 · 4 controls

ISO 27005:2022 · 3 controls

  • 5.1 Information security risk management process
  • 5.2 Information security risk management cycles
  • 8.6 Information security risk treatment plan

ISO 27017:2015 · 3 controls

  • 15.1 Information security in supplier relationships
  • 17.1 Information security continuity
  • 18.2 Information security reviews

DORA · 2 controls

ISO 27018:2019 · 2 controls

  • 18.2 Information security reviews
  • 6.1.1 Information security roles and responsibilities

ISO 22301:2019 · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CFTC System Safeguards: Risk Analysis and Oversight Program

You are reading one control. How much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) have you already done?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 28 of 39 CFTC System Safeguards (17 CFR 37, 38, 39, 49) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.

Query this from an agent

The graph holds this control, the 273 it maps to, and the evidence behind each claim, over MCP and REST.