CFTC System Safeguards (17 CFR 37, 38, 39, 49)
CFTC System Safeguards: Risk Analysis and Oversight Program

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-4: Systems Operations Category

Address systems operations within the program, covering system maintenance, configuration management including baseline configuration, configuration change and patch management, least functionality and inventory of authorised and unauthorised devices and software, and event and problem response and management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 103 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 9 controls

  • CIS-1.1 Establish and Maintain Detailed Enterprise Asset Inventory
  • CIS-1.2 Address Unauthorized Assets
  • CIS-2.1 Establish and Maintain a Software Inventory
  • CIS-2.3 Address Unauthorized Software
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.6 Securely Manage Enterprise Assets and Software
  • CIS-4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
  • CIS-7.3 Perform Automated Operating System Patch Management
  • CIS-7.4 Perform Automated Application Patch Management

NIST SP 800-53 Rev 5 · 9 controls

  • AM-2 Use only approved services
  • AM-3 Ensure security of asset lifecycle management
  • ASBv3-AM-1 Track asset inventory and their risks
  • ASBv3-NS-8 Detect and disable insecure services and protocols
  • ASBv3-PV-1 Define and establish secure configurations
  • ASBv3-PV-3 Define and establish secure configurations for compute resources
  • ASBv3-PV-6 Rapidly and automatically remediate vulnerabilities
  • PV-2 Audit and enforce secure configurations

FedRAMP High · 8 controls

  • CM-11 User-Installed Software
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-6 Configuration Settings
  • CM-7 Least Functionality
  • CM-8 System Component Inventory
  • MA-2 Controlled Maintenance
  • SI-2 Flaw Remediation

FedRAMP Moderate · 8 controls

  • CM-11 User-Installed Software
  • CM-2 Baseline Configuration
  • CM-3 Configuration Change Control
  • CM-6 Configuration Settings
  • CM-7 Least Functionality
  • CM-8 System Component Inventory
  • MA-2 Controlled Maintenance
  • SI-2 Flaw Remediation
  • NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
  • NIST-CSF-ID.AM-02 Inventories of software, services, and systems managed by the organization are maintained
  • NIST-CSF-ID.AM-08 Systems, hardware, software, services, and data are managed throughout their life cycles
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-02 Software is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk
  • NIST-CSF-PR.PS-05 Installation and execution of unauthorized software are prevented

PCI DSS 4.0 · 7 controls

  • 10.7.2 10.7.2 Detect and alert on critical security control failures
  • 11.5.2 11.5.2 Change detection on critical files
  • 12.5.1 12.5.1 Inventory of in-scope system components
  • 2.2.1 2.2.1 System configuration standards maintained
  • 2.2.4 2.2.4 Only necessary functionality enabled
  • 6.3.3 6.3.3 Timely installation of security patches
  • 6.5.1 6.5.1 Change control procedure for production

CMMC 2.0 · 6 controls

NIST SP 800-171 Rev 3 · 6 controls

C5 (Germany) · 4 controls

  • C5-AM-01 Asset Inventory
  • C5-DEV-03 Policies for changes to information systems
  • C5-OPS-18 Managing Vulnerabilities, Malfunctions and Errors - Concept
  • C5-OPS-23 Managing Vulnerabilities, Malfunctions and Errors - System Hardening

ISO 27001:2022 · 4 controls

  • 5.37 Documented operating procedures
  • 5.9 Inventory of information and other associated assets
  • 8.19 Installation of software on operational systems
  • 8.9 Configuration management

ISO 27002:2022 · 4 controls

  • 5.37 Documented operating procedures
  • 5.9 Inventory of information and other associated assets
  • 8.19 Installation of software on operational systems
  • 8.9 Configuration management

NIST SP 800-161 Rev 1 · 4 controls

SOC 2 · 4 controls

  • SOC2-CC5.2 CC5.2 General controls over technology (COSO principle 11)
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-P25 Information and Technology Capability and Asset Health

DORA · 2 controls

HIPAA Security Rule · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CFTC System Safeguards: Risk Analysis and Oversight Program

You are reading one control. How much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) have you already done?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) CFTC-SS-4 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CFTC System Safeguards (17 CFR 37, 38, 39, 49) your existing evidence covers. Hold NIST Cybersecurity Framework 2.0 and 28 of 39 CFTC System Safeguards (17 CFR 37, 38, 39, 49) controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 5 were rejected on the NIST Cybersecurity Framework 2.0 pair alone.

Query this from an agent

The graph holds this control, the 103 it maps to, and the evidence behind each claim, over MCP and REST.