Back to Frameworks

CFTC System Safeguards (17 CFR 37, 38, 39, 49)

United States (CFTC)
v2023 (final rule amendments to Parts 37, 38, 39, and 49)
4 domains
21 controls

The Commodity Futures Trading Commission (CFTC) System Safeguards rules (17 CFR Parts 37, 38, 39, and 49) establish comprehensive cybersecurity, business continuity, incident reporting, system integrity, and risk management requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

CFTC System Safeguards: Business Continuity and Disaster Recovery

4 controls
Controls in the CFTC System Safeguards: Business Continuity and Disaster Recovery domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)4 controls
CodeTitle
CFTC-SS-10Geographically Separate Backup Resources
CFTC-SS-11Business Continuity-Disaster Recovery Testing
CFTC-SS-8Business Continuity-Disaster Recovery Plan and Resources
CFTC-SS-9Recovery Time Objective

CFTC System Safeguards: Cybersecurity Testing

6 controls
Controls in the CFTC System Safeguards: Cybersecurity Testing domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)6 controls
CodeTitle
CFTC-SS-13Vulnerability Testing
CFTC-SS-14Penetration Testing
CFTC-SS-15Controls Testing
CFTC-SS-16Security Incident Response Plan Testing
CFTC-SS-17Enterprise Technology Risk Assessment
CFTC-SS-18Testing by Independent Professionals

CFTC System Safeguards: Notification, Records and Remediation

3 controls
Controls in the CFTC System Safeguards: Notification, Records and Remediation domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)3 controls
CodeTitle
CFTC-SS-19Notification to the Commission
CFTC-SS-20Recordkeeping of System Safeguards
CFTC-SS-21Remediation of Deficiencies

CFTC System Safeguards: Risk Analysis and Oversight Program

8 controls
Controls in the CFTC System Safeguards: Risk Analysis and Oversight Program domain of CFTC System Safeguards (17 CFR 37, 38, 39, 49)8 controls
CodeTitle
CFTC-SS-1Program of Risk Analysis and Oversight
CFTC-SS-12Capacity and Performance Planning
CFTC-SS-2Enterprise Risk Management and Governance
CFTC-SS-3Information Security
CFTC-SS-4Systems Operations
CFTC-SS-5Systems Development and Quality Assurance
CFTC-SS-6Physical Security and Environmental Controls
CFTC-SS-7Generally Accepted Standards and Best Practices

Your Compliance Coverage

If you comply with CFTC System Safeguards (17 CFR 37, 38, 39, 49), you already cover:

Maps to 9 other frameworks

21 total controls
NIST Cybersecurity Framework 2.0
9 source controls mapped|5 target controls covered
43%
SOC 2
8 source controls mapped|8 target controls covered
38%
NIST SP 800-53 Rev 5
8 source controls mapped|8 target controls covered
38%
ISO 27701:2019
2 source controls mapped|8 target controls covered
10%
ISO 27017:2015
1 source controls mapped|3 target controls covered
5%
ISO 27005:2022
1 source controls mapped|3 target controls covered
5%
ISO 27018:2019
1 source controls mapped|2 target controls covered
5%
ISO 27002:2022
1 source controls mapped|6 target controls covered
5%
ISO 27001:2022
1 source controls mapped|8 target controls covered
5%

Frequently Asked Questions

What is CFTC System Safeguards (17 CFR 37, 38, 39, 49)?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) is a compliance framework from United States (CFTC) with 4 domains and 21 controls. The Commodity Futures Trading Commission (CFTC) System Safeguards rules (17 CFR Parts 37, 38, 39, and 49) establish comprehensive cybersecurity, business continuity, incident reporting, system integrity, and risk management requirements for designated contract markets (DCMs), swap execution facilities (SEFs), derivatives clearing organizations (DCOs), and swap data repositories (SDRs). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does CFTC System Safeguards (17 CFR 37, 38, 39, 49) have?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) has 21 controls organised across 4 domains. The largest domains are CFTC System Safeguards: Risk Analysis and Oversight Program (8 controls), CFTC System Safeguards: Cybersecurity Testing (6 controls), CFTC System Safeguards: Business Continuity and Disaster Recovery (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does CFTC System Safeguards (17 CFR 37, 38, 39, 49) map to?

CFTC System Safeguards (17 CFR 37, 38, 39, 49) maps to 9 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (43% coverage), SOC 2 (38% coverage), NIST SP 800-53 Rev 5 (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance?

Start your CFTC System Safeguards (17 CFR 37, 38, 39, 49) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CFTC System Safeguards (17 CFR 37, 38, 39, 49) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 21 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required