Cybersecurity for IBs, CTAs, and CPOs
The NFA recently adopted an Interpretive Notice titled “Information Systems Security Programs” (Cybersecurity Interpretive Notice). This new NFA policy, which goes into effect March 1, 2016, requires FCMs, IBs, CTAs, CPOs, RFEDs, SDs and MSPs to implement a cybersecurity program in order to meet existing obligations to diligently supervise trading activities. Every registrant will be required to put in place policies and procedures reasonably designed to monitor and mitigate the risks of unauthorized access or attack on its information technology systems and to respond appropriately if such access or attack should occur. The new cybersecurity requirement is in addition to and expands on firms’ current Privacy Policy and Disaster Recovery Policy requirements. In fact, some parts of your cybersecurity policy will likely already be included in those policies. There are three aspects of the cybersecurity requirement that all IBs, CTAs and CPOs must address: Develop a written policy Train your...