ARTICLE
14 January 2019

NFA Amends Cybersecurity Requirements

HL
Hogan Lovells Cadwalader

Contributor

Hogan Lovells Cadwalader is a global law firm trusted by clients to deliver on complex, high-stakes matters.

Operating at the intersection of business, finance, and government, we bring an unwavering commitment to client service and the decisive counsel that helps clients achieve exceptional results.

Consistently recognized for innovation across legal services, we combine sharp judgment with deep commercial perspective and intellectual rigor to address critical, cutting-edge challenges.

With 3,100 lawyers worldwide, we offer global scale with strong local insight in the markets that matter most. Our commitment extends beyond client work through pro bono activities, community investment, and responsible business practices.

The NFA amended an Interpretive Notice (the "Notice") on Information Systems Security Program ("ISSP") requirements.
United States Finance and Banking
Hogan Lovells Cadwalader are most popular:
  • within Intellectual Property, Government, Public Sector, Food, Drugs, Healthcare and Life Sciences topic(s)
  • with readers working within the Consumer Industries industries

The NFA amended an Interpretive Notice (the "Notice") on Information Systems Security Program ("ISSP") requirements. The amendments address cybersecurity training obligations, approval of a firm's ISSP, and cybersecurity breach notification. The new amendments become effective on April 1, 2019.

The original Notice, which became effective on March 1, 2016, required NFA member firms - including futures commission merchants, introducing brokers, commodity pool operators and commodity trading advisors - to adopt a written ISSP to address the risk of attacks on, and unauthorized access to, a member firm's information technology systems.

The new amendments to the interpretive guidance:

  • require cybersecurity training for employees upon hiring, at least annually thereafter, and more frequently if circumstances warrant;
  • clarify that the individual who approves a member firm's ISSP should be the senior officer with primary responsibility for information security or another senior official who is a listed principal of the firm and has the authority to supervise the firm's execution of its ISSP; and
  • obligate firms to notify the NFA of each cybersecurity incident that relates to a firm's commodity interest business and that results in any loss of customer funds, any loss of the firm's own capital, or any notification to customers or counterparties under state or federal law.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More