Skip to main content
Image coming soon

CFTC System Safeguards Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
CFTC System Safeguards · 17 CFR 37 38 39 49 · Evidence & Implementation Kit
Meet CFTC system safeguards, without turning 17 CFR into a controls program yourself.
Every system safeguards obligation handed to you as an adopt-ready control, from the program of risk analysis and oversight and information security through business continuity and the required testing to incident notification, with the evidence a CFTC examiner examines.
Exam-ready in a weekend, not a quarter.

Here is the honest situation. If you run a Swap Execution Facility, Designated Contract Market, Derivatives Clearing Organization or Swap Data Repository, the CFTC requires a program of risk analysis and oversight across information security, business continuity, capacity and systems operations; a disaster recovery capability with a next-business-day recovery objective and geographic diversity; annual and independent testing including vulnerability, penetration, controls, incident-response and enterprise technology risk assessments; and prompt notification of cyber incidents and BCDR activation. Building and evidencing that program is a major effort, and a registered entity that cannot show its testing or its next-day recovery is exactly where registered entities fall short.

This Kit removes that build. It is every CFTC system safeguards obligation written as an adopt-ready control you personalize in a weekend, with the evidence a CFTC examiner examines.

What you get, the moment you buy

35
Obligations as adopt-ready controls. Every system safeguards obligation, from the risk-oversight program and information security through business continuity, capacity, the five required test types and vendor oversight to incident notification, written so you personalize and apply it.
35
Evidence-they-examine checklists. For each control, exactly what a CFTC examiner examines, plus where registered entities fall short, so you close the gap first.
1
System Safeguards Control Matrix, pre-built. Every obligation in a working spreadsheet, ready to record status, owner and evidence location.
1
Gap & Readiness Assessment. Score each obligation and the workbook returns your readiness as a single percentage, and exactly what to fix next.

Grounded in the CFTC system safeguards rules (17 CFR 37.1401, 38.1050 to 38.1051, 39.18 and 49.24), with the program of risk analysis and oversight, the next-business-day recovery objective, geographic diversity, the required test types and prompt incident notification to CFTC staff called out. Editable Word and Excel files.

The five required tests are where exams focus
The CFTC does not just ask you to have controls, it requires vulnerability testing, penetration testing with independence, controls testing, security incident response plan testing and an enterprise technology risk assessment, at risk-based frequencies. Missing or stale testing is the classic finding. This Kit builds each test type as a control with the evidence, so the exam focus is covered.

What one control looks like

This is the program of risk analysis and oversight, the backbone of the system safeguards rules. All 35 are built to this depth.

CFTCSS-1 Establish enterprise system safeguards program RISK OVERSIGHT
Put this control in place

Establish and maintain a written program of risk analysis and oversight that identifies and minimizes sources of operational and security risk across the automated systems of [your registered entity name], with governance approval, an assigned accountable executive, defined scope, and annual review, so that the program addresses each enumerated system safeguards category required under the regulations.

Regulatory note.

Map each program section explicitly to the six enumerated categories so examiners can trace coverage quickly.

Evidence a CFTC examiner examines
  • Board or committee approval minutes for the safeguards program
  • Current written program of risk analysis and oversight document
  • Organization chart naming the accountable system safeguards executive
  • Annual review sign-off record with dated approvals
Common finding they raise: Entities often maintain scattered policies without a single governing program document approved at the appropriate governance level.

Why this is not another template pack

  • The evidence is the point. A safeguard you cannot evidence is an exam finding. This tells you what a CFTC examiner examines and where registered entities fall short, for every obligation.
  • Testing and next-day recovery built in. The five required test types, the next-business-day recovery objective and geographic diversity are written into the controls, the requirements examiners focus on.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. System safeguards align with the NIST CSF, FFIEC and SEC Reg SCI, so this work feeds your wider operational resilience program.

Who buys this

SEFs, DCMs, DCOs and SDRs, and the technology risk, security and compliance leads who own system safeguards, plus consultants preparing for a CFTC exam. Whether it is a first program or an exam readiness pass, you save weeks and walk in with the program, testing and evidence structured.

By the end of the weekend you will have
✓  An adopt-ready control for all 35 obligations
✓  A completed system safeguards control matrix
✓  The evidence a CFTC examiner examines
✓  Your five required test types defined
✓  A readiness percentage and a fix list
✓  The common exam findings designed out

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Which entities does it cover? SEFs (Part 37), DCMs (Part 38), DCOs (Part 39) and SDRs (Part 49). The controls note the entity-specific duties.

What is the recovery objective? No later than the next business day, with geographic diversity of resources. Both are built as controls.

Does it cover the required testing? Yes. Vulnerability, penetration with independence, controls, incident-response-plan and enterprise technology risk assessment testing are each their own control.

What if it is not for me? A 30-day money-back guarantee.

Do not walk into a CFTC exam with stale testing.
Every system safeguards obligation is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and be exam-ready this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com