From: The National Law Review
Michael M. Philipp, Sarah V. Riddell | Morgan, Lewis & Bockius LLP
NFA links NFA’s supervisory requirements with its proposed requirements mandating that NFA Members have information systems security programs.
The National Futures Association (NFA) has proposed cybersecurity requirements that, if adopted, will apply to firms that are NFA Members—a category that includes brokers, swap dealers, futures commission merchants, retail forex dealers, asset managers, and other financial services firms that are registered with the Commodity Futures Trading Commission (CFTC) and members of NFA. NFA’s proposed Interpretive Notice (also referred to in this LawFlash as NFA’s “proposal”) follows guidance issued by other financial services regulators, including the US Securities and Exchange Commission (SEC) and Financial Industry Regulatory Authority (FINRA).[1] NFA’s proposal is nonetheless significant as another indication that regulators are taking cybersecurity threats seriously.
For firms that are not registered with the SEC or members of FINRA, NFA’s proposal may be the first instance in which they will be subject to prescribed cybersecurity standards. NFA states that the proposal is designed to establish general requirements, including the requirement that NFA Members have a written Information Security Systems Program (ISSP). NFA submitted the proposal to the CFTC for its review and approval, and the CFTC has 180 days from August 28 to approve it. To date, the CFTC has not solicited public comment on the proposal.
Leave a Reply