CFTC System Safeguards (17 CFR 37, 38, 39, 49)
CFTC System Safeguards: Business Continuity and Disaster Recovery

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-30: Outsourcing with Retention of Complete Responsibility

Where required resources are maintained through a contractual outsourcing arrangement, retain complete responsibility for any failure to meet the program and recovery requirements and employ personnel with the expertise necessary to supervise the provider delivery of the services.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 45 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CPS230-39 Register of Material Service Providers
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • CPS230-47 Monitoring and Senior Management Reporting on Material Arrangements
  • CPS230-P15 Precondition for Reliance on a Service Provider
  • NIST-CSF-DE.CM-06 External service provider activities and services are monitored to find potentially adverse events
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.SC-02 Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally
  • NIST-CSF-GV.SC-05 Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

CIS Controls v8 · 3 controls

  • CIS-15.2 Establish and Maintain a Service Provider Management Policy
  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-15.6 Monitor Service Providers

FedRAMP High · 3 controls

  • PS-7 External Personnel Security
  • SA-9 External System Services
  • SR-3 Supply Chain Controls and Processes (SR-3)

FedRAMP Moderate · 3 controls

  • PS-7 External Personnel Security
  • SA-9 External System Services
  • SR-3 Supply Chain Controls and Processes (SR-3)

HIPAA Security Rule · 3 controls

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)
  • 164.314(a)(2)(i) Business Associate Contract Required Provisions

NIST SP 800-161 Rev 1 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

PCI DSS 4.0 · 3 controls

  • 12.8.2 12.8.2 TPSP contracts acknowledging account data responsibility
  • 12.8.3 12.8.3 Due diligence before engaging TPSPs
  • 12.8.5 12.8.5 Responsibility allocation between entity and TPSPs

C5 (Germany) · 2 controls

  • C5-SSO-02 Risk assessment of service providers and suppliers
  • C5-SSO-04 Monitoring of compliance with requirements

ISO 27001:2022 · 2 controls

  • 5.19 Information security in supplier relationships
  • 5.22 Monitoring, review and change management of supplier services

ISO 27002:2022 · 2 controls

  • 5.19 Information security in supplier relationships
  • 5.22 Monitoring, review and change management of supplier services
  • DS-2 Ensure software supply chain security

DORA · 1 control

ISO 22301:2019 · 1 control

  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

SOC 2 · 1 control

  • SOC2-CC9.2 CC9.2 Assessing and managing vendor and business partner risk

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CFTC System Safeguards: Business Continuity and Disaster Recovery

You are reading one control. How much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) have you already done?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-30 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 28 of 39 CFTC System Safeguards (17 CFR 37, 38, 39, 49) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.

Query this from an agent

The graph holds this control, the 45 it maps to, and the evidence behind each claim, over MCP and REST.