Proposed Amendments to the National Market System Plan Governing the Consolidated Audit Trail To Enhance Data Security
Federal RegisterOct 16, 2020
Ask Donna
What actually matters in this document.
Text
SECURITIES AND EXCHANGE COMMISSION
[Release No. 34-89632; File No. S7-10-20]
RIN 3235-AM62
Proposed Amendments to the National Market System Plan Governing the Consolidated Audit Trail To Enhance Data Security
AGENCY:
Securities and Exchange Commission.
ACTION:
Proposed amendments to national market system plan.
SUMMARY:
The Securities and Exchange Commission is proposing amendments to the national market system plan governing the consolidated audit trail. The proposed amendments are designed to enhance the security of the consolidated audit trail.
DATES:
Comments should be received on or before November 30, 2020.
ADDRESSES:
Comments may be submitted by any of the following methods:
Electronic Comments
• Use the Commission's internet comment form (
http://www.sec.gov/rules/proposed.shtml
); or
• Send an email to
rule-comments@sec.gov.
Please include File No. S7-10-20 on the subject line.
Paper Comments
• Send paper comments to Secretary, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-1090.
All submissions should refer to File No. S7-10-20. This file number should be included on the subject line if email is used. To help us process and review your comments more efficiently, please use only one method. The Commission will post all comments on the Commission's internet website (
http://www.sec.gov/rules/proposed.shtml
). Comments are also available for website viewing and printing in the Commission's Public Reference Room, 100 F Street NE, Washington, DC 20549 on official business days between the hours of 10:00 a.m. and 3:00 p.m. All comments received will be posted without change. Persons submitting comments are cautioned that the Commission does not redact or edit personal identifying information from comment submissions. You should submit only information that you wish to make available publicly.
Studies, memoranda, or other substantive items may be added by the Commission or staff to the comment file during this rulemaking. A notification of the inclusion in the comment file of any such materials will be made available on the Commission's website. To ensure direct electronic receipt of such notifications, sign up through the “Stay Connected” option at
www.sec.gov
to receive notifications by email.
FOR FURTHER INFORMATION CONTACT:
Erika Berg, Special Counsel, at (202) 551-5925, Jennifer Colihan, Special Counsel, at (202) 551-5642, Rebekah Liu, Special Counsel, at (202) 551-5665, Susan Poklemba, Special Counsel, at (202) 551-3360, Andrew Sherman, Special Counsel, at (202) 551-7255, Gita Subramaniam, Attorney Advisor, at (202) 551-5793, or Eugene Lee, Attorney Advisor, at (202) 551-5884, Division of Trading and Markets, Securities and Exchange Commission, 100 F Street NE, Washington, DC 20549-7010.
SUPPLEMENTARY INFORMATION:
The Commission is proposing amendments to the CAT NMS Plan.
TABLE OF CONTENTS
I. Background
II. Description of Proposed Amendments
A. Comprehensive Information Security Program
B. Security Working Group
C. Secure Analytical Workspaces
1. Provision of SAW Accounts
2. Data Access and Extraction Policies and Procedures
3. Security Controls, Policies, and Procedures for SAWs
4. Implementation and Operational Requirements for SAWs
5. Exceptions to the SAW Usage Requirements
D. Online Targeted Query Tool and Logging of Access and Extraction
E. CAT Customer and Account Attributes
1. Adopt Revised Industry Member Reporting Requirements
2. Establish a Process for Creating Customer-ID(s) in Light of Revised Reporting Requirements
3. Plan Processor Functionality To Support the Creation of Customer-ID(s)
4. Reporting Transformed Value
5. Data Availability Requirements
6. Customer and Account Attributes in CAIS and Transformed Values
7. Customer-ID Tracking
8. Error Resolution for Customer Data
9. CAT Reporter Support and CAT Help Desk
F. Customer Identifying Systems Workflow
1. Application of Existing Plan Requirements to Customer and Account Attributes and the Customer Identifying Systems
2. Defining the Customer Identifying Systems Workflow and the General Requirements for Accessing Customer Identifying Systems
3. Introduction to Manual and Programmatic Access
4. Manual CAIS Access
5. Manual CCID Subsystem Access
6. Programmatic Access—Authorization for Programmatic CAIS Access and Programmatic CCID Subsystem
7. Programmatic CAIS Access
8. Programmatic CCID Subsystem Access
G. Participants' Data Confidentiality Policies
1. Data Confidentiality Policies
2. Access to CAT Data and Information Barriers
3. Additional Policies Relating to Access and Use of CAT Data and Customer and Account Attributes
4. Approval, Publication, Review and Annual Examinations of Compliance
H. Regulator & Plan Processor Access
1. Regulatory Use of CAT Data
2. Access to CAT Data
I. Secure Connectivity & Data Storage
J. Breach Management Policies and Procedures
K. Firm Designated ID and Allocation Reports
L. Appendix C of the CAT NMS Plan
M. Proposed Implementation
1. Proposed 90-Day Implementation Period
2. Proposed 120-Day Implementation Period
3. Proposed 180-Day Implementation Period
N. Application of the Proposed Amendments to Commission Staff
III. Paperwork Reduction Act
A. Summary of Collections of Information
1. Evaluation of the CISP
2. Security Working Group
3. SAWs
4. Online Targeted Query Tool and Logging of Access and Extraction
5. CAT Customer and Account Attributes
6. Customer Identifying Systems Workflow
7. Proposed Confidentiality Policies, Procedures and Usage Restrictions
8. Secure Connectivity—“Allow Listing”
9. Breach Management Policies and Procedures
10. Customer Information for Allocation Report Firm Designated IDs
B. Proposed Use of Information
1. Evaluation of the CISP
2. Security Working Group
3. SAWs
4. Online Targeted Query Tool and Logging of Access and Extraction
5. CAT Customer and Account Attributes
6. Customer Identifying Systems Workflow
7. Proposed Confidentiality Policies, Procedures and Usage Restrictions
8. Secure Connectivity—“Allow Listing”
9. Breach Management Policies and Procedures
10. Customer Information for Allocation Report Firm Designated IDs
C. Respondents
1. National Securities Exchanges and National Securities Associations
2. Members of National Securities Exchanges and National Securities Association
D. Total Initial and Annual Reporting and Recordkeeping Burdens
1. Evaluation of the CISP
2. Security Working Group
3. SAWs
4. Online Targeted Query Tool and Logging of Access and Extraction
5. CAT Customer and Account Attributes
6. Customer Identifying Systems Workflow
7. Proposed Confidentiality Policies, Procedures and Usage Restrictions
8. Secure Connectivity—“Allow Listing”
9. Breach Management Policies and Procedures
10. Customer Information for Allocation Report Firm Designated IDs
E. Collection of Information is Mandatory
F. Confidentiality of Responses to Collection of Information
G. Retention Period for Recordkeeping Requirements
H. Request for Comments
IV. Economic Analysis
A. Analysis of Baseline, Costs and Benefits
1. CISP
2. Security Working Group
3. Secure Analytical Workspaces
4. OTQT and Logging
5. CAT Customer and Account Attributes
6. Customer Identifying Systems Workflow
7. Participants' Data Confidentiality Policies
8. Regulator & Plan Processor Access
9. Secure Connectivity
10. Breach Management Policies and Procedures
11. Firm Designated ID and Allocation Reports
B. Impact on Efficiency, Competition, and Capital Formation
1. Baseline for Efficiency, Competition and Capital Formation in the Market for Regulatory Services
2. Efficiency
3. Competition
4. Capital Formation
C. Alternatives
1. Private Contracting for Analytic Environments
2. Not Allowing for Exceptions to the SAW Use Requirement
3. Alternative Download Size Limits for the Online Targeted Query Tool
4. Allowing Access to Customer Identifying Systems From Excepted Environments
D. Request for Comment on the Economic Analysis
V. Consideration of Impact on the Economy
VI. Regulatory Flexibility Act Certification
VI. Statutory Authority and Text of the Proposed Amendments to the CAT NMS Plan
I. Background
In July 2012, the Securities and Exchange Commission (the “Commission”) adopted Rule 613 of Regulation NMS, which required national securities exchanges and national securities associations (the “Participants”)
1
to jointly develop and submit to the Commission a national market system plan to create, implement, and maintain a consolidated audit trail (the “CAT”).
2
The goal of Rule 613 was to create a modernized audit trail system that would provide regulators with more timely access to a sufficiently comprehensive set of trading data, thus enabling regulators to more efficiently and effectively reconstruct market events, monitor market behavior, and investigate misconduct. On November 15, 2016, the Commission approved the national market system plan required by Rule 613 (the “CAT NMS Plan”).
3
1
The Participants include BOX Exchange LLC, Cboe BYX Exchange, Inc., Cboe BZX Exchange, Inc., Cboe C2 Exchange, Inc., Cboe EDGA Exchange, Inc., Cboe EDGX Exchange, Inc., Cboe Exchange, Inc., Financial Industry Regulatory Authority, Inc., Investors' Exchange LLC, Long-Term Stock Exchange, Inc., MEMX LLC, Miami International Securities Exchange LLC, MIAX Emerald, LLC, MIAX PEARL, LLC, Nasdaq BX, Inc., Nasdaq GEMX, LLC, Nasdaq ISE, LLC, Nasdaq MRX, LLC, Nasdaq PHLX LLC, The Nasdaq Stock Market LLC, New York Stock Exchange LLC, NYSE American LLC, NYSE Arca, Inc., NYSE Chicago, Inc., and NYSE National, Inc.
2
See
Securities Exchange Act Release No. 67457 (July 18, 2012), 77 FR 45722 (August 1, 2012) (“Rule 613 Adopting Release”).
3
Securities Exchange Act Release No. 78318 (November 15, 2016), 81 FR 84696, (November 23, 2016) (“CAT NMS Plan Approval Order”). The CAT NMS Plan is Exhibit A to the CAT NMS Plan Approval Order.
See
CAT NMS Plan Approval Order, at 84943-85034. The CAT NMS Plan functions as the limited liability company agreement of the jointly owned limited liability company formed under Delaware state law through which the Participants conduct the activities of the CAT (the “Company”). Each Participant is a member of the Company and jointly owns the Company on an equal basis. The Participants submitted to the Commission a proposed amendment to the CAT NMS Plan on August 29, 2019, which they designated as effective on filing. Under the amendment, the limited liability company agreement of a new limited liability company named Consolidated Audit Trail, LLC serves as the CAT NMS Plan, replacing in its entirety the CAT NMS Plan.
See
Securities Exchange Act Release No. 87149 (September 27, 2019), 84 FR 52905 (October 3, 2019).
The security and confidentiality of CAT Data
4
has been—and continues to be—a top priority of the Commission. The CAT NMS Plan approved by the Commission already sets forth a number of requirements regarding the security and confidentiality of CAT Data. The CAT NMS Plan states, for example, that the Plan Processor
5
shall be responsible for the security and confidentiality of all CAT Data received and reported to the Central Repository.
6
In furtherance of this directive, the CAT NMS Plan requires the Plan Processor to develop and maintain an information security program for the Central Repository. The Plan Processor must have appropriate solutions and controls in place to address data confidentiality and security during all communication between CAT Reporters,
7
Data Submitters,
8
and the Plan Processor; data extraction, manipulation, and transformation; data loading to and from the Central Repository; and data maintenance by the CAT System.
9
The CAT NMS Plan also sets forth minimum data security requirements for CAT that the Plan Processor must meet, including requirements governing connectivity and data transfer, data encryption, data storage, data access, breach management, data requirements for personally identifiable information (“PII”),
10
and applicable data security industry standards.
11
CAT Data reported to and retained in the Central Repository is thus subject to what the Commission believes are stringent security policies, procedures, standards, and controls. Nevertheless, the Commission believes that it can and should take additional steps to further protect the security and confidentiality of CAT Data. Therefore, the Commission proposes to amend the CAT NMS Plan to enhance the security of the CAT and the protections afforded to CAT Data.
4
“CAT Data” is a defined term under the CAT NMS Plan and means “data derived from Participant Data, Industry Member Data, SIP Data, and such other data as the Operating Committee may designate as ‘CAT Data' from time to time.”
See
CAT NMS Plan,
supra
note 3, at Section 1.1.
5
“Plan Processor” is a defined term under the CAT NMS Plan and means “the Initial Plan Processor or any other Person selected by the Operating Committee pursuant to SEC Rule 613 and Sections 4.3(b)(i) and 6.1, and with regard to the Initial Plan Processor, the Selection Plan, to perform the CAT processing functions required by SEC Rule 613 and set forth in this Agreement.”
See id.
6
See id.
at Section 6.5(f)(i). “Central Repository” is a defined term under the CAT NMS Plan and means “the repository responsible for the receipt, consolidation, and retention of all information reported to the CAT pursuant to SEC Rule 613 and this Agreement.”
See id.
7
“CAT Reporter” is a defined term under the CAT NMS Plan and means “each national securities exchange, national securities association and Industry Member that is required to record and report information to the Central Repository pursuant to SEC Rule 613(c).”
See id.
8
“Data Submitter” is a defined term under the CAT NMS Plan and means “national securities exchanges, national securities associations, broker-dealers, the SIPs for the CQS, CTA, UTP and Plan for Reporting of Consolidated Options Last Sale Reports and Quotation Information (“
OPRA”
) Plans, and certain other vendors or appropriate third parties.”
See id.
at Appendix C, Section A(1)(a).
9
See id.
at Appendix D, Section 4.1. “CAT System” is a defined term in the CAT NMS Plan and means “all data processing equipment, communications facilities, and other facilities, including equipment, utilized by the Company or any third parties acting on the Company's behalf in connection with operation of the CAT and any related information or relevant systems pursuant to [the CAT LLC Agreement].”
See
CAT NMS Plan,
supra
note 3, at Section 1.1.
10
“PII” is a defined term under the CAT NMS Plan and means “personally identifiable information, including a social security number or tax identifier number or similar information; Customer Identifying Information and Customer Account Information.”
See id.
at Section 1.1.
11
See id.
at Section 6.12;
see also
id.
at Appendix D, Section 4.
Specifically, the Commission proposes to amend the CAT NMS Plan to: (1) Define the scope of the current
information security program; (2) require the Operating Committee
12
to establish and maintain a security-focused working group; (3) require the Plan Processor to create secure analytical workspaces, direct Participants to use such workspaces to access and analyze PII and CAT Data obtained through the user-defined direct query and bulk extract tools described in Section 6.10(c)(i)(B) of the CAT NMS Plan, set forth requirements for the data extraction, security, implementation, and operational controls that will apply to such workspaces, and provide an exception process that will enable Participants to use the user-defined direct query and bulk extract tools in other environments; (4) limit the amount of CAT Data that can be extracted from the Central Repository outside of a secure analytical workspace through the online targeted query tool described in Section 6.10(c)(i)(A) of the CAT NMS Plan and require the Plan Processor to implement more stringent monitoring controls on such data; (5) impose requirements related to the reporting of certain PII; (6) define the workflow process that should be applied to govern access to customer and account attributes that will still be reported to the Central Repository; (7) modify and supplement existing requirements relating to Participant policies and procedures regarding the confidentiality of CAT Data; (8) refine the existing requirement that CAT Data be used only for regulatory or surveillance purposes; (9) codify existing practices and enhance the security of connectivity to the CAT infrastructure; (10) require the formal cyber incident response plan to incorporate corrective actions and breach notifications; (11) amend reporting requirements relating to Firm Designated IDs and Allocation Reports; and (12) clarify that Appendix C of the CAT NMS Plan has not been updated to reflect subsequent amendments to the CAT NMS Plan. The proposed amendments are discussed in more detail below.
12
“Operating Committee” is a defined term in the CAT NMS Plan and means “means the governing body of the Company designated as such and described in Article IV.”
See id.
at Section 1.1.
II. Description of Proposed Amendments
A. Comprehensive Information Security Program
Section 6.12 of the CAT NMS Plan requires the Plan Processor to develop and maintain an information security program for the Central Repository that, at a minimum, meets the security requirements set forth in Section 4 of Appendix D to the CAT NMS Plan.
13
Section 4 of Appendix D sets out information security requirements that cover “all components of the CAT System” and is not limited to the Central Repository.
14
The Commission preliminarily believes that the scope of the information security program referenced in Section 6.12 of the CAT NMS Plan should be more explicitly defined to apply to the CAT System, as well as to the Plan Processor.
13
See id.
at Appendix D, Section 4 (Data Security). In Appendix D, Section 4, the Plan sets out the basic solutions and controls that must be met to ensure the security and confidentiality of CAT Data. Such requirements relate to Connectivity and Data Transfer (Section 4.1.1); Data Encryption (Section 4.1.2); Data storage and Environment (Section 4.1.3); Data Access (Section 4.1.4); Breach Management (Section 4.1.5); PII Data Requirements (Section 4.1.6); and Industry Standards (Section 4.2).
14
See
CAT NMS Plan,
supra
note 3, at Appendix D, Section 4 (“The Plan Processor must provide to the Operating Committee a comprehensive security plan that covers
all components of the CAT System,
including physical assets and personnel . . . .” (emphasis added)).
Accordingly, the Commission proposes to add the term “Comprehensive Information Security Program” (the “CISP”) to Section 1.1 of the CAT NMS Plan and to define this term to mean the “organization-wide and system-specific controls and related policies and procedures required by NIST SP 800-53
15
that address information security for the information and information systems of the Plan Processor and the CAT System, including those provided or managed by an external organization, contractor, or source.” The proposed definition would further state that the CISP will also apply to Secure Analytical Workspaces, new environments within the CAT System to which CAT Data may be downloaded.
16
The Commission also proposes to make corresponding changes to Section 6.12 of the CAT NMS Plan. Specifically, the Commission proposes to rename Section 6.12 as “Comprehensive Information Security Program”
17
and to delete the phrase “for the Central Repository” in Section 6.12.
18
15
See
Security and Privacy Controls for Federal Information Systems and Organizations, NIST Special Publication 800-53 Revision 4, National Institute of Standards and Technology, U.S. Dep't of Commerce (April 2013),
available at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
(“NIST SP 800-53”).
16
See
Part II.C.
infra,
for a discussion of the definition of “Secure Analytical Workspace” and the specific CISP requirements that would apply to such environments under proposed Section 6.13.
17
Similar changes have been made throughout the CAT NMS Plan, at proposed Section 6.2(a)(v)(H), proposed Section 6.5(f)(i)(C), proposed Section 6.6(b)(ii)(B)(3), and proposed Section 4.1 of Appendix D.
18
A similar change has been made at proposed Section 6.5(f)(i)(C) to replace a reference to the Central Repository with a reference to the CAT System.
The Commission preliminarily believes that these proposed amendments are appropriate to set forth all elements of the information security program that must be developed and maintained by the Plan Processor and approved and reviewed at least annually by the Operating Committee.
19
While Section 6.12 of the CAT NMS Plan currently refers to the Central Repository, as noted above, Section 4 of Appendix D refers to information security program requirements that apply more broadly to the entire CAT System
20
and also references the NIST SP 800-53 standard as one that must be followed by the Plan Processor.
21
NIST SP 800-53 defines and recommends security controls, policies, and procedures that should be employed as part of a well-defined risk management process for organizational-level information security programs, including personnel security controls.
22
NIST SP 800-53, which sets forth security and privacy controls for federal information systems and organizations, requires the establishment of information security and risk management due diligence on an organizational level.
23
The CAT NMS Plan's inclusion of NIST SP 800-53 as a relevant industry standard that must be followed to manage data security for information systems therefore requires that the Plan Processor apply its information security program at an organizational level, and not just to the Central Repository. The Commission preliminarily believes the proposed amendments to define the CISP and other corresponding changes should therefore clearly require the information security program to apply to personnel and information systems that support the CAT System.
19
To the extent that the CISP would be made up of multiple policies, procedures, or other documents, the Commission preliminarily believes that the Operating Committee could review each document on an independent or rolling timeline, rather than reviewing all components of the CISP at the same time.
20
See
note 14
supra.
21
See
CAT NMS Plan,
supra
note 3, at Appendix D, Section 4.2.
22
See
NIST SP 800-53, at 1,
supra
note 15.
23
See, e.g., id.
at vi, x-xii.
See also, e.g., id.
at 1 (“The security controls defined in this publication and recommended for use by organizations to satisfy their information security requirements should be employed as part of a well-defined risk management process that supports organizational information security programs.”).
As explained above, the proposed amendments, by referencing NIST SP
800-53 in the definition of the CISP, would amend Section 6.12 of the CAT NMS Plan to explicitly require the information security program to apply broadly at an organizational level—that is, to address specific organizational mission and/or business needs and risk tolerances for all of the information and information systems that support the operations of the Plan Processor and the CAT System, including Secure Analytical Workspaces.
24
The proposed amendments would also explicitly require the information security program to be applied to information systems within the CAT System that are managed or provided by external organizations, contractors, or other sources that the Plan Processor or the Participants may determine that it is necessary to engage to perform functions related to the implementation, operation, or maintenance of the CAT.
25
Appendix D, Section 4.1 of the CAT NMS Plan currently requires a comprehensive security plan, including information security requirements, that covers the entire CAT System, and the CAT System, as currently defined, encompasses the data processing equipment, communications facilities, and other facilities utilized by external parties acting on the Company's behalf in connection with the operation of the CAT.
26
The proposed amendments would consolidate these requirements into one definition and explicitly require that external parties be subject to the CISP if they are providing or managing information or information systems that are within the CAT System. Finally, the proposed amendments would explicitly state that the CISP includes the controls, policies, and procedures required by NIST SP 800-53, including organizational-level controls. As noted above, this is already a requirement under Appendix D, Section 4 of the CAT NMS Plan, which states that NIST SP 800-53 must be followed as part of a comprehensive security plan applying to all components of the CAT System implemented by the Plan Processor.
27
Nevertheless, the Commission preliminarily believes that including an explicit reference to NIST SP 800-53 in the proposed definition of the CISP will reinforce that fact.
24
Under the proposed amendments, Secure Analytical Workspaces would, by definition, be within the CAT System.
See
proposed Section 1.1, “Secure Analytical Workspace.” The inclusion of Secure Analytical Workspaces in the proposed definition of the CISP would therefore not be an expansion, as the current information security program is required to cover the entire CAT System pursuant to Appendix D, Section 4 of the CAT NMS Plan.
25
For example, the Plan Processor engaged an external contractor to implement and operate the component of the CAT known as the Customer and Account Information System (“CAIS”). The Plan Processor also selected an external cloud provider as the host for the CAT System.
26
See
CAT NMS Plan,
supra
note 3, at Section 1.1;
see id.
at Appendix D, Section 4.
27
See id.
at Section 6.12, Appendix D, Section 4.2.
The Commission preliminarily believes that these changes should improve the security of the CAT by defining the scope of the information security program required to be developed and maintained by the Plan Processor to be sufficiently clear and to account for the entire CAT, with accompanying personnel security controls for all Plan Processor staff and relevant personnel from external organizations, contractors or other sources, and for all relevant information systems or environments.
The Commission requests comment on the proposed definition of the CISP and the proposed corresponding changes to the CAT NMS Plan. Specifically, the Commission solicits comment on the following:
1. Is the proposed definition for the CISP necessary? Is it already clear that the information security requirements described in Section 6.12 and Appendix D, Section 4 apply at an organizational level to the Plan Processor, to external parties acting on behalf of the Company to support CAT operations, and to all information systems or environments that are within the CAT System, including Secure Analytical Workspaces? Is it already clear that the information security requirements described in Section 6.12 and Appendix D, Section 4 must incorporate the controls, policies, and procedures required by NIST SP 800-53?
2. Should the proposed definition for the CISP be expanded or modified? Are there other personnel, information systems, organizations, or environments that should be covered by the CISP? If so, please specifically identify those personnel, information systems, organizations, or environments and explain why it would be appropriate to include them in the definition of the CISP.
3. Should additional references in the CAT NMS Plan related to the information security program be conformed to refer to the CISP? Should proposed Section 6.12 refer to any other provisions of the CAT NMS Plan in addition to Section 4 of Appendix D and Section 6.13? If so, please identify those provisions and explain why it would be appropriate to incorporate a reference to such provisions in proposed Section 6.12.
B. Security Working Group
To provide support and additional resources to the Chief Information Security Officer of the Plan Processor (the “CISO”)
28
and the Operating Committee of the CAT NMS Plan, the proposed amendments would require the Operating Committee to establish and maintain a security working group composed of the CISO and the chief information security officer or deputy chief information security officer of each Participant (the “Security Working Group”).
29
Commission staff would be permitted to attend all meetings of the Security Working Group as observers, and the CISO and the Operating Committee would further be allowed to invite other parties to attend specific meetings.
30
The proposed amendments would specify that the purpose of the Security Working Group shall be to advise the CISO and the Operating Committee,
31
including with respect to issues involving: (1) Information technology matters that pertain to the development of the CAT System; (2) the development, maintenance, and application of the CISP; (3) the review and application of the confidentiality policies required by proposed Section 6.5(g); (4) the review and analysis of
third party risk assessments conducted pursuant to Section 5.3 of Appendix D, including the review and analysis of results and corrective actions arising from such assessments; and (5) emerging cybersecurity topics.
32
In addition, the proposed amendments would require the CISO to apprise the Security Working Group of relevant developments and to provide the Security Working Group with all information and materials necessary to fulfill its purpose.
33
28
“Chief Information Security Officer” is a defined term under the CAT NMS Plan and means “the individual then serving (even on a temporary basis) as the Chief Information Security Officer pursuant to Section 4.6, Section 6.1(b), and Section 6.2(b).”
See
CAT NMS Plan,
supra
note 3, at Section 1.1. The CISO is an officer of the Company and has a fiduciary duty to the Company.
See id.
at Section 4.6(a), Section 4.7(c). The CISO, among other things, is responsible for creating and enforcing appropriate policies, procedures, and control structures regarding data security.
See id.
at Section 6.2(b)(i) and 6.2(b)(v).
29
See
proposed Section 4.12(c).
30
See id.
Given the sensitive nature of the issues that would be discussed at meetings of the Security Working Group, the Commission believes that the CISO and the Operating Committee should consider requiring any non-member invitees to sign a non-disclosure agreement or to adhere to some other protocol designed to prevent the release of confidential information regarding the security of the CAT System. Members of the Security Working Group, and any Participant staff that they consult regarding matters before the Security Working Group, would likewise be subject to the confidentiality obligations set forth in Section 9.6 of the CAT NMS Plan.
See, e.g.,
CAT NMS Plan,
supra
note 3, at Section 9.6(a) (stating that information disclosed by or on behalf of the Company or a Participant to the Company or any other Participant (the “Receiving Party”) shall be maintained by the Receiving Party in confidence with the same degree of care it holds its own confidential information and disclosed to its Representatives on a need-to-know basis and only to those of such Representatives who have agreed to abide by the non-disclosure and non-use provisions of Section 9.6).
31
The proposed amendments would clearly state that the CISO shall continue to report directly to the Operating Committee in accordance with Section 6.2(b)(iii) of the CAT NMS Plan.
See
proposed Section 4.12(c).
32
See id.
33
See id.
With respect to this provision, the Commission does not preliminarily believe that members of the Security Working Group would need access to CAT Data to fulfill their function. Nonetheless, because members of the Security Working Group would not be considered “Regulatory Staff” under the proposed amendments described in Part II.G.2.a., Security Working Group members would only be able to gain access to CAT Data by following the policies set forth in proposed Section 6.5(g)(i)(E).
The Commission preliminarily believes it is appropriate to require the Operating Committee to formally establish and maintain a Security Working Group.
34
Although a group has already been established by the Operating Committee to discuss the security of the CAT,
35
the Commission preliminarily believes it is important to require the formation of a Security Working Group with a defined set of participants and a defined purpose. The proposed amendments, for example, would require that each Participant's chief information security officer or deputy chief information security officer be a member of the Security Working Group; other security and regulatory experts would not fulfill the requirements of the proposed amendments.
36
The Commission preliminarily believes these membership requirements are appropriate, because the chief information security officer and deputy chief information security officer of each Participant are the parties that are most likely to have general expertise with assessing organizational-level security issues for complex information systems. Moreover, because the Central Repository is a facility of each Participant,
37
the Commission preliminarily believes that the chief information security officer and deputy chief information security officer of each Participant are likely to have specific expertise with assessing organizational-level and system-specific security issues for the CAT System, as well as an interest in making sure that the CAT System and CAT Data are sufficiently protected. The Commission therefore preliminarily believes that requiring the membership of each Participant's chief information security officer or deputy chief information security officer in the Security Working Group should help to provide effective oversight of CAT security issues.
34
See id.
The Commission proposes a conforming change to the title of this section to make it clear that section will apply to both subcommittees and working groups.
35
See
CAT Security Overview: Safeguarding Data Reported to CAT,
available at https://www.catnmsplan.com/wp-content/uploads/2019/08/FINRA-CAT-Security-Approach-Overview_20190828.pdf.
36
See
proposed Section 4.12(c).
37
See, e.g.,
CAT NMS Plan,
supra
note 3, at Appendix C (indicating that the CAT will be a facility of each Participant).
The proposed amendments would permit the CISO and the Operating Committee to invite other parties, including external consultants with expertise in organizational-level or system-specific security or industry representatives, to attend specific meetings. In addition, the proposed amendments would permit Commission observers to attend all meetings. The Commission preliminarily believes these provisions will enable the Security Working Group to obtain a broad spectrum of views and to present such views to the CISO and the Operating Committee on key security issues.
Finally, the proposed amendments would state that the purpose of the group shall be to aid the CISO and the Operating Committee.
38
This is a broad mandate, because the Commission preliminarily believes that the CISO and the Operating Committee would generally benefit from the combined expertise of the Security Working Group on a broad array of matters. To enable the Security Working Group to provide the requisite aid, the proposed amendments would further state that the CISO must apprise the Security Working Group of relevant developments and provide the Security Working Group with all information and materials necessary to fulfill its purpose. This provision is designed to keep the Security Working Group adequately informed about issues that fall within its purview.
38
The list of issues provided in proposed Section 4.12(c) is not exclusive; it may be appropriate for the Security Working Group to aid the CISO with respect to other issues, and the proposed amendments require the involvement of the Security Working Group on other matters.
See, e.g.,
proposed Section 6.13(d)(i)(A) (requiring a Participant seeking an exception from the proposed Secure Analytical Workspace usage requirements to provide the Security Working Group with specified application materials).
The proposed amendments would also require the Security Working Group to aid the CISO and the Operating Committee on certain issues that the Commission preliminarily believes are particularly important. For example, issues involving information technology matters that pertain to the development of the CAT System,
39
the development of the CISP,
40
or emerging cybersecurity topics
41
are likely to present questions of first impression, and it is important that such questions be handled appropriately in the first instance. The Commission preliminarily believes that the involvement of the Security Working Group could be of valuable assistance to the CISO. Similarly, issues involving the maintenance and application of the CISP
42
and the review and application of the confidentiality policies required by proposed Section 6.5(g)
43
relate to two initiatives that would protect the security and confidentiality of CAT Data. These initiatives would control access to and extraction of such data outside the Central Repository and would directly impact how Participants interact with CAT Data within and outside the CAT System.
44
The Commission preliminarily believes that the Security Working Group would be able to provide valuable feedback on these initiatives, which, as explained more fully below, are critical to the security of the CAT because they would govern the development and implementation of the Participants' confidentiality and security policies for handling non-public data generally and CAT Data specifically.
45
The Commission also preliminarily believes that the Security Working Group should aid the CISO in reviewing and analyzing third-party risk assessments conducted pursuant to Section 5.3 of Appendix D, as well as the results and corrective actions arising from such assessments.
46
Given the combined expertise of the Security Working Group, the Commission preliminarily believes that its membership would be uniquely adept at understanding the results, assessing the criticality of findings, prioritizing necessary corrective action, and providing valuable feedback on the plan of action to address any open
issues that might be identified by these assessments.
39
See
proposed Section 4.12(c)(i).
40
See id.
at (c)(ii).
41
See id.
at (c)(v).
42
See id.
at (c)(ii).
43
See id.
at (c)(iii).
44
See
Part II.A.
supra,
for a discussion of the proposed CISP and its importance to CAT security; Part II.C.
infra,
for a discussion of data access and extraction policies that would be applied as part of the proposed CISP.
See also
Part II.G.
infra,
for a discussion of the proposed amendments relating to Participants' data confidentiality policies, which would include restrictions on data access and extraction, and their importance to CAT security.
45
See id.
46
See
proposed Section 4.12(c)(iv).
The Commission requests comment on proposed Section 4.12(c). Specifically, the Commission solicits comment on the following:
4. Should a Security Working Group be formally established and maintained?
5. The proposed amendments require the Security Working Group to be composed of the CISO and the chief information security officer or deputy chief information security officer of each Participant. Do commenters agree that the chief information security officer or deputy chief information security officer of each Participant is likely to be best informed regarding security issues that might affect the CAT? Should any other parties be included as required members of the Security Working Group? If so, please identify these parties and explain why it would be appropriate to include them. For example, should representatives from the Advisory Committee established by Section 4.13 of the CAT NMS Plan be added as required members to the Security Working Group? Should the CISO and the Operating Committee be permitted to invite other parties to attend specific meetings? Should any limitations be placed on the kinds of parties the CISO and the Operating Committee may invite? For example, should the CISO and the Operating Committee be limited to inviting personnel employed by the Participants, because such personnel would already be subject to the confidentiality obligations set forth in Section 9.6 of the CAT NMS Plan for Representatives? If not, should external parties invited by the CISO and the Operating Committee be explicitly required by proposed Section 4.12(c) to sign a non-disclosure agreement or to comply with any other kind of security protocol in order to prevent the disclosure of confidential information regarding the security of the CAT System? If so, please identify the security protocol such parties should comply with and explain why such protocol would be effective.
6. The proposed amendments state that the Security Working Group's purpose is to advise the CISO and the Operating Committee. Is that an appropriate mandate? If not, please identify a mandate that would be appropriate and explain why it is a better mandate for the Security Working Group. Should the Security Working Group advise the Plan Processor or some other party, instead of the CISO and the Operating Committee?
7. Will the proposed amendments keep the Security Working Group apprised of relevant information or developments? Should the proposed amendments require the CISO and/or the Operating Committee to consult the Security Working Group only on certain matters? If so, please identify these matters and explain why it would be appropriate to require the CISO and/or the Operating Committee to consult the Security Working Group only on such matters. Should the proposed amendments require periodic meetings among the CISO, the Operating Committee and the Security Working Group? If so, how often should such meetings occur and why? Should the proposed amendments require the Security Working Group to provide the CISO and/or the Operating Committee with feedback on a regular basis?
8. The proposed amendments include a non-exhaustive list of specific issues that would be within the purview of the Security Working Group. Should this list include any additional matters? Should any of these matters be removed from this list or amended?
C. Secure Analytical Workspaces
The CAT NMS Plan must sufficiently enable regulators to access and extract CAT Data in order to achieve specific regulatory purposes. The CAT NMS Plan currently describes various means by which regulators may access and extract CAT Data. Section 6.5(c) of the CAT NMS Plan, for example, requires the Plan Processor to provide regulators access to the Central Repository for regulatory and oversight purposes and to create a method of accessing CAT Data that enables complex searching and report generation. Section 6.10(c) of the CAT NMS Plan specifies two methods of regulator access: (1) An online targeted query tool with predefined selection criteria to choose from; and (2) user-defined direct queries and bulk extracts of data via a query tool or language allowing querying of all available attributes and data sources.
47
The CAT NMS Plan also specifies how regulators may download the results obtained in response to these queries. For example, with respect to the online targeted query tool, the CAT NMS Plan provides that, “[o]nce query results are available for download, users are to be given the total file size of the result set and an option to download the results in a single or multiple file(s). Users that select the multiple file option will be required to define the maximum file size of the downloadable files. The application will then provide users with the ability to download the files. This functionality is provided to address limitations of end-user network environment[s] that may occur when downloading large files.”
48
With respect to the user-defined direct queries and bulk extracts of data, the CAT NMS Plan provides that “[t]he Central Repository must provide for direct queries, bulk extraction, and download of data for all regulatory users. Both the user-defined direct queries and bulk extracts will be used by regulators to deliver large sets of data that can then be used in internal surveillance or market analysis applications.”
49
47
See
CAT NMS Plan,
supra
note 3, at Section 6.10(c)(i);
see also id.
at Appendix D, Section 8.1 through Section 8.2. Section 6.10(c) also requires the Plan Processor to reasonably assist regulatory staff with queries, to submit queries on behalf of regulatory staff (including regulatory staff of Participants) as reasonably requested, and to maintain a help desk to assist regulatory staff with questions about the content and structure of CAT Data.
Id.
at Section 6.10(c)(iv) through (vi).
48
See id.,
at Appendix D, Section 8.1.1.
49
See id.,
at Appendix D, Section 8.2.
To better protect CAT Data, the Commission preliminarily believes that efforts should be taken to minimize the attack surface associated with CAT Data; to maximize security-driven monitoring of CAT Data, both as it is reported to the CAT and as it is accessed and utilized by regulators; and to leverage, wherever possible, security controls and related policies and procedures that are consistent with those that protect the Central Repository.
The Commission preliminarily believes that these objectives can be met by requiring the creation and use of Secure Analytical Workspaces (“SAWs”) that would be part of the CAT System and therefore subject to the CISP.
50
The proposed amendments would define a “Secure Analytical Workspace” as “an analytic environment account that is part of the CAT System, and subject to the Comprehensive Information Security Program, where CAT Data is accessed and analyzed as part of the CAT System pursuant to [proposed] Section 6.13. The Plan Processor shall provide a SAW account for each Participant that implements all common technical security controls required by the Comprehensive Information Security Program.”
51
The Commission also proposes to add a new Section 6.13 to the CAT NMS Plan to set forth the requirements that would apply to SAWs. The Commission understands that the Participants have recently
authorized the Plan Processor to build similar environments for some of the Participants and that each Participant would be responsible for the implementation of its own security controls.
52
The Commission preliminarily believes that it would be beneficial to require that the Plan Processor provide SAW accounts to be used by all Participants in certain circumstances and to formally codify the functionality available in and the security controls applicable to SAWs. The Commission preliminarily believes that this approach will best enable the implementation of the SAWs with a consistent and sufficient level of security.
50
In addition, the Commission also preliminarily believes that certain limitations on the downloading capabilities of the online targeted query tool will help to achieve these objectives.
See
Part II.D.
infra,
for a discussion of these proposed limitations.
51
See
proposed Section 1.1, “Secure Analytical Workspace.”
52
See
Letter from Michael Simon, CAT NMS Plan Operating Committee Chair, to Hon. Jay Clayton, Chairman, Commission, dated November 27, 2019, at 4-5,
available at https://www.catnmsplan.com/sites/default/files/2020-02/Simon-Letter-SIFMA-%28Final%29.pdf
(“Simon Letter”).
Accordingly, the Commission is proposing amendments to the CAT NMS Plan that will specify: (1) The provision of the SAW accounts; (2) data access and extraction policies and procedures, including SAW usage requirements; (3) security controls, policies, and procedures for SAWs; (4) implementation and operational requirements for SAWs; and (5) exceptions to the SAW usage requirements. These proposed amendments are discussed in further detail below.
1. Provision of SAW Accounts
The proposed amendments would require each Participant to use a SAW for certain purposes,
53
but the proposed definition of “Secure Analytical Workspace” and proposed Section 6.1(d)(v) make it clear that Participants would not build their own SAWs within the CAT System or implement the technical security controls required by the CISP. Rather, the proposed amendments state that the “Plan Processor shall provide a SAW account for each Participant that implements all common technical security controls required by the Comprehensive Information Security Program.”
54
53
See
Part II.C.2.
infra,
for a discussion of the SAW usage requirements.
54
See
proposed Section 1.1, “Secure Analytical Workspaces.”
See also
proposed Section 6.1(d)(v) (stating that the Plan Processor shall “provide Secure Analytical Workspaces in accordance with Section 6.13”). The Central Repository, as a facility of each of the Participants, is an SCI entity and the CAT System is an SCI system, and thus it must comply with Regulation SCI.
See
CAT NMS Plan Approval Order,
supra
note 3, at 84758;
see also
17 CFR 242.1000 (definition of “SCI system” and “SCI entity”). Because the CAT systems, including the Central Repository, are operated on behalf of the Participants by the Plan Processor, the Participants are responsible for having in place processes and requirements to ensure that they are able to satisfy the requirements of Regulation SCI for the CAT systems operated by the Plan Processor on their behalf.
See also
Securities Exchange Act Release No. 73639 (November 19, 2014), 79 FR 72251, 72276 (December 5, 2014) (“Regulation SCI Adopting Release”). The CAT NMS Plan states that data security standards of the CAT System shall, at a minimum, satisfy all applicable regulations regarding database security, including provisions of Regulation SCI. The Plan Processor thus must establish, maintain, and enforce written policies and procedures reasonably designed to ensure that the CAT System has levels of capacity, integrity, resiliency, availability, and security adequate to maintain its operational capability to comply with Regulation SCI.
See
CAT NMS Plan Approval Order,
supra
note 3, at 84758-59; CAT NMS Plan,
supra
note 3, at Section 6.9(b)(xi)(A).
See also, e.g.,
Letter from Michael J. Simon, Chair, CAT NMS, LLC Operating Committee, to Brent J. Fields, Secretary, Commission, at 1-2, dated April 9, 2019,
available at https://www.sec.gov/divisions/marketreg/rule613-info-notice-of-plan-processor-selection-040919.pdf
(setting forth the material terms of the Plan Processor agreement, which obligate the Plan Processor to perform CAT-related functions and services in a manner that is consistent with and in accordance with the CAT NMS Plan and Commission rules and regulations).
The Commission preliminarily believes that requiring the Plan Processor to provide SAW accounts to the Participants that implement all common technical security controls required by the CISP is the most effective way to achieve a consistent level of security across multiple SAWs and between SAWs.
55
The Commission preliminarily believes that the alternative of allowing each Participant to build its own SAW would inhibit the Plan Processor's ability to control, manage, operate, and maintain the CAT System, which would include the SAWs. By centralizing provision of the SAW accounts with the Plan Processor, the common technical controls associated with the CISP should be built consistently and in a way that newly enables the Plan Processor to conduct consistent and comprehensive monitoring of analytic environments employed by Participants to access and analyze CAT Data—a task the Plan Processor is not currently able to perform.
56
55
See
Part II.C.3.
infra
for a discussion of the common technical security controls that must be required for SAWs by the CISP. The Commission also preliminarily believes that this requirement would enable the Plan Processor to achieve a consistent level of security across the CAT System, as the Central Repository and the SAWs would have common controls that were implemented by the same party.
56
See
Part II.C.4.b.
infra
for a discussion of the monitoring requirements for SAWs.
The Plan Processor is the party most familiar with the existing information security program and would be the party most familiar with the security controls, policies, and procedures that would be required under the proposed CISP. The Commission preliminarily believes this familiarity would enable the Plan Processor to build the required security controls more efficiently and more effectively than if each Participant were responsible for its own SAW account.
57
If each Participant were permitted to build the common security controls for its SAW account without the input or knowledge of the Plan Processor, different Participants might make different (and potentially less secure) decisions about how to implement the information security program or the proposed CISP. These different decisions could, in turn, hamper the Plan Processor's ability to consistently monitor the SAWs, because it would be difficult for the Plan Processor to automate its monitoring protocols or to uniformly monitor SAWs that had been not been uniformly implemented. A lack of consistent monitoring could endanger the overall security of the CAT, because the Plan Processor could be less likely to identify non-compliance with the CISP or with the SAW design specifications.
58
57
See, e.g.,
CAT NMS Plan,
supra
note 3, at Section 6.12 (requiring the Plan Processor to develop and maintain the information security program).
58
See
note 56
supra.
The Commission also preliminarily believes that centralizing provision of the SAW accounts with the Plan Processor is the most efficient approach.
59
Given the size of the CAT database that the Plan Processor already manages in a cloud environment, the Plan Processor is in a position to leverage economies of scale and, possibly, to obtain preferential pricing in establishing SAW accounts with the same cloud provider and in the same cloud environment.
60
Having the Plan Processor be responsible for the provision of all SAW accounts could also make administration of SAW security easier. For example, cloud environments offer features that enable security-related administrative functions to be performed simultaneously and consistently across multiple accounts. Such features could also be leveraged by the Plan Processor to extend its existing information security controls for the Central
Repository across all SAW accounts. Requiring each Participant to independently implement relevant security controls would be comparatively inefficient, needlessly duplicative, and, potentially, less secure.
59
Because SAW accounts are, by definition, part of the CAT System, the Commission preliminarily believes that SAW accounts would likely be built by the same cloud provider and in the same cloud environment as the Central Repository.
60
See
Part IV.C.1.
infra
for a discussion of the potential costs related to each Participant providing its own SAW account. With respect to SAW pricing, the Commission preliminarily believes that the Plan Processor will charge back variable cloud services fees to each Participant in a manner consistent with how current variable fees incurred by the Plan Processor are charged back to the Company.
See
Part IV.A.3.
infra
for further discussion of such pricing and potential fees.
Although the Plan Processor would provide each SAW account, the proposed amendments would still afford the Participants a fair amount of autonomy in the operation of the SAW. The definition of “Secure Analytical Workspace” would make it clear that proposed Section 6.13 would govern the use of the SAWs, and proposed Section 6.13 explicitly states that each Participant would be allowed to provide and use its own choice of software, hardware configurations, and additional data within its SAW, so long as such activities otherwise comply with the CISP.
61
This language would permit the Participants to create whatever analytic environment they prefer within the SAWs. For example, each Participant would be free to choose which hardware configurations inclusive of computing power and storage, analytical tools, and additional content should be available in its SAW. This language also would not prevent the Participants from collectively contracting with a third party, such as the Plan Processor, to provide each SAW with common tools or the infrastructure needed to query and process CAT Data. The Commission therefore preliminarily believes that the proposed amendments give each Participant sufficient flexibility to operate its SAW according to its own preferences, while still ensuring that the SAWs are built and implemented in a consistent and efficient manner.
62
61
See
proposed Section 6.13(c)(iii);
see also
Part II.C.4.b.
infra,
for a discussion of and questions about this provision.
62
The Commission would have the same ability to configure its SAW to migrate third-party or in-house applications, analytical tools, or external data as the Participants.
The Commission requests comment on the proposed requirements for SAWs. Specifically, the Commission solicits comment on the following:
9. Is the proposed definition for Secure Analytical Workspaces sufficient? Should the proposed definition specify that the SAW accounts must be built using the same cloud provider that houses the Central Repository? Is the Commission correct in its belief that SAW accounts would be built in the same environment as the Central Repository because they would be part of the CAT System? If not, should such a requirement be added?
10. Is it possible that Participants might perform tasks in a SAW other than accessing and analyzing CAT Data, such as workflows for generating and handling alerts? Please identify any such tasks with specificity and explain whether the definition should include those tasks. Is it appropriate to characterize SAWs as “part of the CAT System”? Are there alternative definitions of a SAW that would be more appropriate? If so, what are those definitions and why are they appropriate.
11. Is it appropriate for the Plan Processor to provide the SAW accounts? To the extent that the Plan Processor has already been authorized to begin developing and/or implementing analytic environments for the Participants, will the Plan Processor be able to leverage any of this work to build the SAW accounts? If so, please explain what efforts have already been made by the Plan Processor and whether the Plan Processor will be able to leverage any of these efforts to build the SAW accounts. Should each Participant be permitted to provide its own SAW account? Is there a third party who should provide the SAW accounts? If so, please identify that party, explain why it would be appropriate for that party to provide the SAW accounts, and explain why such structure would not inhibit the Plan Processor's ability to control, manage, operate, and maintain the CAT System. Are there alternative structures that the Commission has not explicitly considered here? If so, please explain what these structures are and why they would be more appropriate for SAWs. Is it appropriate for the Plan Processor to implement all common security controls required by the CISP? Would implementation of such controls hamper the Participants' ability to customize their SAWs? Should each Participant be able to implement the common security controls on its own?
12. Should the Plan Processor be required to provide each Participant with a SAW account? Should the proposed amendments explicitly specify that Participants are permitted to share SAW account(s)? If a Participant does not believe it will need to use a SAW account, should the Plan Processor still be required to build a SAW account for that Participant? If not, how and at what point should the Participant inform the Plan Processor that it does not need a SAW account? Should such a Participant be allowed to change its mind if the Participant later determines that it needs to use a SAW account? If so, how long should the Plan Processor be given to build a SAW account for that Participant? Should the Plan Processor be required to provide each Participant with more than one SAW account upon request?
13. Do commenters agree that centralizing provision of the SAW accounts with the Plan Processor is the most effective and efficient way to implement the common technical controls associated with the CISP and to enable the Plan Processor to conduct consistent and comprehensive monitoring of SAWs? If not, please identify any alternative approaches that would be more effective and more efficient.
14. The proposed amendments state that the Participants may provide and use their choice of software, hardware configurations, and additional data within their SAWs, so long as such activities otherwise comply with the CISP. Should the Plan Processor, as the provider of each SAW account, be required to assist with any such activities? If not, do commenters believe that the Participants will be able to provide their own software, hardware configurations, and additional data without the assistance of the Plan Processor? For example, do commenters believe that a Participant would need the Plan Processor to grant special access or other administrative privileges in order to provide such software, hardware configurations, or additional data? Are there any other administrative tasks that the Plan Processor would or should be expected to provide? If so, please identify any such tasks and explain whether the proposed amendments should explicitly address the performance of such tasks.
15. Do commenters believe that the Plan Processor will charge back variable cloud services fees to each Participant for SAWs in a manner consistent with how current variable fees incurred by the Plan Processor are charged back to the Company? If not, how will the Plan Processor charge each Participant for SAW implementation and usage? Should the proposed amendments state how the Plan Processor may charge the Participants for SAW implementation and usage? If so, should each Participant be billed by the Plan Processor for providing a SAW, even if the Participants choose not to use that SAW? How should the Participants be billed for their use of the SAWs?
2. Data Access and Extraction Policies and Procedures
The Commission continues to believe that regulators must be permitted to access and extract CAT Data when such access and extraction is for surveillance and regulatory purposes, but only as long as such access and extraction does not compromise the security of CAT
Data. Proposed Section 6.13(a)(i) would therefore require the CISP to, at a minimum, establish certain data access and extraction policies and procedures.
63
63
Proposed Section 6.13(a) also states explicitly that the CISP shall apply to every Participant's SAW. This is also required by the proposed definition of “Comprehensive Information Security Program.”
See
proposed Section 1.1;
see also
Part II.A.
supra,
for a discussion of the proposed CISP. Similarly, proposed Section 6.12 would make clear that the CISP should include the requirements set forth in proposed Section 6.13.
First, under proposed Section 6.13(a)(i)(A), the CISP must establish policies and procedures that would require Participants to use their SAWs as the only means of accessing and analyzing customer and account data. While the database containing customer and account data would no longer include social security numbers, dates of birth, and/or account numbers for individual retail investors,
64
the unauthorized access and use of the remaining customer and account data—Customer and Account Attributes—could still be damaging. Because Customer and Account Attributes data may currently be accessed outside of the CAT System, the Commission preliminarily believes that the proposed SAW usage requirement would better protect this information by ensuring that it is accessed and analyzed within the CAT System and therefore subject to the security controls, policies, and procedures of the CISP when accessed and analyzed by the Participants.
65
64
See
Securities Exchange Act Release No. 88393 (March 17, 2020), 85 FR 16152 (March 20, 2020) (granting conditional exemptive relief from certain requirements of the CAT NMS Plan, including requirements related to the reporting of PII). With the elimination of social security numbers, dates of birth, and/or account numbers from the CAT, the Commission proposes to eliminate the term “PII” and refer to the remaining customer and account data in the CAT as “Customer and Account Attributes” throughout the CAT NMS Plan.
See
Part II.E.
infra,
for a discussion of this proposed change.
65
The Commission is also proposing amendments to the CAT NMS Plan to define the security requirements of the Customer Identifying Systems Workflow.
See
Part II.F.
infra,
for a discussion of these amendments.
Second, under proposed Section 6.13(a)(i)(B), the CISP must establish policies and procedures that would require the Participants to use their SAWs when accessing and analyzing CAT Data through the user-defined direct query and bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan, unless an exception is granted pursuant to proposed Section 6.13(d).
66
Under the CAT NMS Plan, the online targeted query tool facilitates access to focused, narrowly-defined queries, while the user-defined direct query and bulk extract tools enable the Participants to download much larger sets of data from the Central Repository to external systems that are not required to comply with the information security program described in Section 6.12.
67
The user-defined direct query and bulk extract tools therefore have a greater impact on the attack surface of the CAT. The Commission preliminarily believes that the proposed SAW usage restrictions will keep more CAT Data within the CAT System and subject to the CISP, while still providing the Participants with the flexibility of performing focused searches outside of the SAW through the online targeted query tool.
68
66
See
Part II.C.5.a.
infra,
for a discussion of the proposed exception process.
67
For example, the online targeted query tool limits searches using a date or time range and only makes certain predetermined fields available to users, whereas the user-defined direct query tool can be used to query all available attributes and data sources without such limitations.
Cf., e.g.,
CAT NMS Plan,
supra
note 3, at Section 6.10(c)(1)(A);
id.
at Section 6.10(c)(1)(B).
68
To further protect CAT Data, the Commission is also proposing amendments to the CAT NMS Plan that would reduce the amount of information that the Participants could extract via the online targeted query tool.
See
Part II.D.
infra,
for a discussion of these proposed amendments.
Third, under proposed Section 6.13(a)(i)(C), the CISP must establish policies and procedures that would require that the Participants only extract from SAWs the minimum amount of CAT Data necessary to achieve a specific surveillance or regulatory purpose.
69
While the proposed amendments require access and analysis of CAT Data within the SAW for Customer and Account Attributes and transaction data accessed with the user-defined direct query or bulk extract tools, the Commission recognizes that it may sometimes be necessary for the Participants to extract CAT Data that is otherwise required to be accessed or analyzed in a SAW to external systems or environments, including those beyond the Participants' control. For example, the Participants might need to extract CAT Data to respond to a court order or to some other regulatory or statutory mandate, to submit a matter to a disciplinary action committee, to file a complaint against a broker-dealer, or to refer an investigation or examination to other regulators like the Commission.
70
The Commission does not wish to unnecessarily constrain the Participants in situations like these, where only a targeted, small amount of CAT Data is needed to achieve a specific surveillance or regulatory purpose. The Commission preliminarily believes that these provisions strike an appropriate balance by maintaining CAT Data largely within the CAT System, but still enabling limited extraction of data to allow the Participants to comply with their regulatory or statutory obligations.
69
See also
Part II.G. for further discussion of other proposed controls on access to and use of CAT Data, which would, among other things, limit the extraction of CAT Data to the minimum amount of data necessary to achieve a specific regulatory or surveillance purpose, define the staff that would be entitled to access or use CAT Data, and increase the oversight of the Chief Regulatory Officer (or similarly designated head(s) of regulation) of each Participant over access to and use of CAT Data.
70
See also
Part II.N.
infra,
for a discussion of how the proposed amendments would apply to Commission staff. The Commission preliminarily believes that the restrictions set forth in the proposed amendments would still enable the extraction of required data—for example, to support discussions with a regulated entity regarding activity that raises concerns, to file a complaint against a regulated entity, or to support an investigation or examination of a regulated entity.
Fourth, under proposed Section 6.13(a)(i)(D), the CISP must establish policies and procedures that would require that secure file sharing capability provided by the Plan Processor be the only mechanism for extracting CAT Data from SAWs. Because file-based sharing systems have the ability to track file size and recipients, the Commission preliminarily believes that requiring the use of file-based sharing will help the Plan Processor to monitor for non-compliant use of the SAWs. The Commission further preliminarily believes that requiring the use of a secure file sharing capability will better protect CAT Data by enabling confidential transmission of data between authorized users. Finally, the Commission preliminarily believes that it is appropriate for the Plan Processor to provide this capability. As the party responsible for developing and maintaining the CISP, the Plan Processor is in the best position to determine which file-based sharing system will fit the security needs of the CAT System. Requiring that the Plan Processor provide one universally-used secure file-based sharing system may also reduce the administrative burdens and security risks that might arise if each Participant developed and used a different file-based sharing capability to extract CAT Data out of its SAWs.
Finally, the CAT NMS Plan currently states that the Chief Compliance Officer
71
(the “CCO”) shall oversee the
regular written assessment of the Plan Processor's performance that is required to be provided to the Commission and that this assessment shall include an evaluation of the existing information security program “to ensure that the program is consistent with the highest industry standards for the protection of data.”
72
In addition to replacing the reference to the “information security program” with a reference to the proposed “Comprehensive Information Security Program,” the proposed amendments would require the CCO, in collaboration with the CISO, to include in this evaluation a review of the quantity and type of CAT Data extracted from the CAT System to assess the security risk of permitting such CAT Data to be extracted
73
and to identify any appropriate corrective measures.
74
The Commission preliminarily believes that these proposed requirements will facilitate Commission oversight of the security risks posed by the extraction of CAT Data. The proposed review should enable a thorough assessment of security risks to CAT Data and whether changes to the current security measures are appropriate.
71
“Chief Compliance Officer” is a defined term in the CAT NMS Plan and means “the individual then serving (even on a temporary basis) as the Chief Compliance Officer pursuant to Section 4.6, Section 6.1(b), and Section 6.2(a).”
See
CAT NMS Plan,
supra
note 3, at Section 1.1. The CCO is an officer of the Company and has a fiduciary duty to the Company.
See id.
at Section 4.6(a), Section 4.7(c).
72
See id.
at Section 6.6(b)(i)(B), Section 6.6(b)(ii)(B)(3). The CAT NMS Plan requires the written assessment of the Plan Processor's performance to be provided to the Commission annually or more frequently in connection with any review of the Plan Processor's performance under the CAT NMS Plan pursuant to Section 6.1(n).
See id.
at Section 6.6(b)(i)(A).
73
The Commission believes that such an evaluation could be performed using metrics associated with aggregated data. For example, the Plan Processor could review the amount of data that each Participant extracted on a monthly basis and analyze extraction trends for each Participant to identify any anomalies or to compare the amount of data extracted from the CAT against the amount of data ingested into the CAT.
74
See
proposed Section 6.6(b)(ii)(B)(3). The proposed amendments do not limit this review to CAT Data extracted from SAWs; the proposed review should also include CAT Data extracted using other methods, like the online targeted query tool. These requirements are also enshrined in proposed Section 6.2.
See also
proposed Section 6.2(a)(v)(T) (requiring the CCO to determine, pursuant to Section 6.6(b)(ii)(B)(3), to review CAT Data that has been extracted from the CAT System to assess the security risk of allowing such CAT Data to be extracted); proposed Section 6.2(b)(x) (requiring the CISO to determine, pursuant to Section 6.6(b)(ii)(B)(3), to review CAT Data that has been extracted from the CAT System to assess the security risk of allowing such CAT Data to be extracted).
The Commission requests comment on the proposed data access and extraction policies and procedures. Specifically, the Commission solicits comment on the following:
16. Is it appropriate to require the CISP to establish data access and extraction policies and procedures? Should the proposed amendments specify each component that should be included in the data access and extraction policies and procedures? If so, please describe what components should be included and explain why those components would be appropriate. For example, should the proposed amendments specify that the data access and extraction policies and procedures should establish which data will be provided to Participants in the form of data extraction logs, how the proposed confidentiality policies described in Part II.G. should apply to SAW usage, or when data extraction should be permissible? Is CAT Data sufficiently protected by the current terms of the CAT NMS Plan? If so, please explain how the current protection is adequate.
17. The proposed amendments require the CISP to establish policies and procedures that require the Participants to use SAWs as the only means of accessing and analyzing Customer and Account Attributes. Should Participants be allowed to analyze Customer and Account Attributes data outside of a SAW?
18. The proposed amendments require the CISP to establish policies and procedures that require Participants to use SAWs when accessing and analyzing CAT Data through the user-defined direct query and bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2, unless granted an exemption pursuant to proposed Section 6.13(d). Would it be more effective to limit the number of records that could be returned by these search tools? If so, please explain how those tools should be limited and explain why those limitations are appropriate. Should the proposed amendments also require the Participants to use SAWs when accessing and analyzing CAT Data retrieved through the online targeted query tool described in Section 6.10(c)(i)(A)? Should the proposed amendments require that all CAT Data be accessed and analyzed in a SAW, regardless of how it was retrieved?
19. The proposed amendments require the CISP to establish policies and procedures directing the Participants to extract only the minimum amount of CAT Data necessary to achieve a specific surveillance or regulatory purpose. Should the Commission revise this requirement to specifically limit the number of records, the size of the data that may be extracted, or the file types permitted for extraction in support of a specific surveillance or regulatory purpose? If so, what should the Commission specify as the number of records or the size of the data? For example, should the number of records be limited to 200,000 rows, the size of the data that may be extracted be limited to 1 gigabyte, or the file types permitted for extracted be limited to Excel spreadsheets? Please identify any appropriate limitations, explain why those limitations would be appropriate, and describe how regulatory use cases requiring the extraction of data from the SAW would be fully supported. Should the CISP be allowed to establish a more permissive policy governing the extraction of CAT Data from the SAWs? If so, please identify any conditions that should be placed on the extraction of CAT Data from the SAWs and explain why they are appropriate.
20. Should the proposed amendments require the application of additional security controls, policies, or procedures for data that is extracted from a SAW or that is extracted directly from the Central Repository by Participants into a non-SAW environment that has not been granted an exception pursuant to proposed Section 6.13(d)—
i.e.,
data extracted using the online targeted query tool? Or do existing rules and regulations under the Exchange Act, like Regulation SCI, sufficiently protect CAT Data that would be extracted from a SAW or from the Central Repository?
21. The proposed amendments require the CISP to establish policies and procedures that state that secure file sharing capability provided by the Plan Processor shall be the only mechanism for extracting CAT Data from the SAW. Do commenters understand what is meant by “secure file sharing” or should the Commission specify criteria that should be used to assess whether a system provides “secure file sharing capability”? What criteria would evaluate whether a system provides “secure file sharing capability”? Should a different method of extraction be permitted? If so, please identify that method of extraction and explain why it would be appropriate. Is it clear what the Commission means by “secure file sharing capability”? Please explain what commenters understand this term to mean and whether it is appropriate for the Commission to add more detail to the proposed amendments. Should a different party provide the secure file sharing capability? If so, please identify that party and explain why that party would be a more appropriate choice. Should the proposed amendments be more specific about what kind of capability must be provided by the Plan Processor? If so, please explain what kinds of details would be helpful.
22. The proposed amendments require the CCO, in collaboration with
the CISO, to include, in the regular written assessment of the Plan Processor's performance that is required to be provided to the Commission, a review of the quantity and type of CAT Data extracted from the CAT System to assess the security risk of permitting such extraction. This review must also identify any appropriate corrective measures. Is it appropriate to require this review to be included in the regular written assessment of the Plan Processor's performance that is required to be provided to the Commission? Is there a better vehicle for communicating this information to the Commission? If so, please identify that vehicle and explain why it would be a more appropriate way of communicating this information to the Commission. Should the Commission receive this information more often than it would receive the regular written assessment of the Plan Processor's performance? If so, how often should the Commission receive this information and through what means should such information should be communicated? Is there any other information that should be included in this review? If so, please identify such information and explain why it would be appropriate to include such information in the review.
3. Security Controls, Policies, and Procedures for SAWs
To protect the security of the SAWs, the Commission preliminarily believes that it is appropriate to require the CISP to set forth the security controls, policies, and procedures that must apply to the SAWs. The Plan Processor already must adhere to the NIST Risk Management Framework and implement the security controls identified in National Institute of Standards and Technology's Special Publication 800-53 to protect CAT Data that is reported to and retained at the Central Repository.
75
To promote the consistent treatment of CAT Data that might be downloaded to SAWs, the proposed amendments would state that the CISP must establish security controls, policies, and procedures for SAWs that require all NIST SP 800-53 security controls and associated policies and procedures required by the CISP to apply to the Participants' SAWs.
76
75
See, e.g.,
CAT NMS Plan,
supra
note 3, at Appendix D, Section 4.2 (setting forth a non-exhaustive list of applicable industry standards, including NIST SP 800-53).
See also id.
at Appendix D, Section 5.3 (“The Plan Processor must conduct third party risk assessments at regular intervals to verify that security controls implemented are in accordance with NIST SP 800-53.”).
See also
NIST SP 800-53,
supra
note 15, at 7-8 (explaining how NIST SP 800-53 implements the NIST Risk Management Framework).
76
See
proposed Section 6.13(a)(ii).
The proposed amendments would also require the CISP to establish security controls, policies, and procedures that would specify that certain security controls, policies, and procedures must be applied to SAWs by the Plan Processor and that such security controls, policies, and procedures must be common to both the SAWs and the Central Repository in accordance with Section 2.4 of NIST SP 800-53, unless technologically or organizationally not possible.
77
Common security controls, policies, and procedures would be required for at least the following NIST SP 800-53 control families: Audit and accountability, security assessment and authorization, configuration management, incident response, system and communications protection, and system and information integrity.
78
77
See
proposed Section 6.13(a)(ii)(A).
See
NIST SP 800-53,
supra
note 15, at Section 2.4 (explaining what common controls are and how they should be implemented).
78
See
proposed Section 6.13(a)(ii)(A).
The NIST SP 800-53 control families specifically identified by the proposed amendments are core families that would enable the Plan Processor to better monitor the security of the SAWs.
79
For example, requiring that audit and accountability,
80
security assessment and authorization,
81
incident response,
82
and systems and information integrity
83
controls, policies, and procedures be “common” in accordance with Section 2.4 of NIST SP 800-53 would facilitate consistent monitoring of systems and personnel and associated analysis across the CAT System, including the generation and review of activity logs, identification of potential anomalies or attacks, incident-specific monitoring and notification, analysis of security-related infrastructure and possible system vulnerabilities, and uniform issuance of security alerts. In addition, by requiring that security assessment and authorization controls, policies, and procedures be “common” in accordance with Section 2.4 of NIST SP 800-53, the proposed amendments would include security assessments of the SAWs as part of the overall risk assessment of the CAT System; risks would be tracked and escalated in the same way. Common configuration management
84
and system and communication protection
85
controls, policies, and procedures would centralize the management of crucial infrastructure, so that each SAW would operate according to the same parameters as the rest of the CAT System and thereby enable the Plan Processor to conduct the above-described monitoring more efficiently.
79
Although the proposed amendments would require the Plan Processor to monitor the SAWs to verify that relevant security controls, policies, and procedures are being followed, the proposed amendments would not permit the Plan Processor to monitor analytical activities taking place within the SAWs, including analytical activities that may take place within any SAW provided for the Commission's use.
See
Part II.C.4.b.
infra
for further discussion of the monitoring requirements;
see also
Part II.N.
infra
for further discussion regarding the application of the proposed amendments to Commission staff.
80
See
NIST SP 800-53,
supra
note 15, at Appendix F-AU
81
See id.
at Appendix F-CA.
82
See id.
at Appendix F-IR.
83
See id.
at Appendix F-SI.
84
See id.
at Appendix F-CM.
85
See id.
at Appendix F-SC.
The Commission preliminarily believes that it is appropriate for all NIST SP 800-53 security controls, policies, and procedures required by the CISP to apply to the SAWs; the same set of control families, policies, and procedures should apply when CAT Data is accessed and downloaded to a SAW. In addition, the Commission preliminarily believes that it is appropriate to further require common implementation for NIST SP 800-53 control families that relate to critical monitoring functions, unless technologically or organizationally not possible. By requiring the CISP to establish common security controls, policies, and procedures for these NIST SP 800-53 control families, the proposed amendments would establish security protections for SAWs that are harmonized to the greatest extent possible with the security protections of the Central Repository. The security of the SAWs should therefore be robust.
86
Moreover, the Commission preliminarily believes that the proposed amendments would facilitate the efficient implementation of the SAWs by specifying that the Plan Processor will be responsible for implementing the common security controls, policies, and procedures. If each Participant were allowed to implement the common security controls, policies, and procedures, different Participants might
make different (and potentially less secure or less efficient) implementation choices. As the party who would be the most familiar with the CISP, the Plan Processor can more efficiently implement these common security controls, policies, and procedures
87
and is the best situated to verify that such security controls, policies, and procedures are implemented consistently.
86
By contrast, if the proposed amendments were not adopted, the Participants would be allowed to build these analytical environments with their own security measures. Although the CAT NMS Plan requires the CISO to review the Participants' information security policies and procedures related to any such analytical environments to ensure that such policies and procedures are comparable to the information security policies and procedures that are applicable to the Central Repository, the proposed amendments will promote uniformity, which the Commission preliminarily believes is more likely to protect CAT Data for the reasons discussed above.
See
CAT NMS Plan,
supra
note 3, at Section 6.2(b)(vii).
87
See
Part II.C.1.
supra
(explaining why it is more efficient for the Plan Processor to implement and administer relevant security controls).
The Commission recognizes, however, that common implementation will likely not be feasible for all of the NIST SP 800-53 security controls, policies, and procedures required by the CISP. Accordingly, proposed Section 6.13(a)(ii)(B) would permit the security controls, policies, and procedures established by the CISP to indicate that implementation of NIST SP 800-53 security controls, policies, and procedures required by the CISP may be done in a SAW-specific way and by either the Plan Processor or each Participant.
88
The Commission emphasizes, however, that “SAW-specific” does not mean that each Participant may independently select or assess the NIST SP 800-53 security controls, policies, and procedures that should apply for its SAWs. Rather, this provision would still require the CISP to provide the basis for the NIST SP 800-53 security controls, policies, and procedures that should be applied to SAWs, but allow that the implementation of controls, policies, and procedures may be different for each SAW. The Commission preliminarily believes this provision would provide an appropriate level of control to the Plan Processor while permitting SAW-specific implementation of the security controls, policies, and procedures that would apply to SAWs, as SAWs would have different functional and technical requirements from the Central Repository and may therefore require tailored implementation of controls.
88
It may also be technologically or organizationally impossible to commonly implement all of the security controls, policies, and procedures identified by proposed Section 6.13(a)(ii)(A), in which case proposed Section 6.13(a)(ii)(B) would control how the security controls, policies, and procedures established by the CISP for SAWs address such implementation.
The Commission requests comment on the proposed security controls, policies, and procedures requirements. Specifically, the Commission solicits comment on the following:
23. The proposed amendments require the CISP to establish security controls, policies, and procedures such that all NIST SP 800-53 security controls and associated policies and procedures required by the CISP apply to the SAWs. Should the CISP be required to establish security controls, policies, and procedures to implement any other industry standard for SAWs? If so, please identify the relevant industry standard(s) and explain why it would be appropriate to require the CISP to establish security controls, policies, and procedures to implement that standard(s). Should the CISP be required to implement additional NIST SP 800-53 security controls, policies, or procedures for SAWs, including security controls, policies, and procedures that would protect the boundary of each SAW from other SAWs and/or other components of the CAT System? If so, please identify those security controls, policies, or procedures and explain why they should be implemented for SAWs. Should the SAWs be required to implement all security controls, policies, and procedures required by the CISP? If not, please identify the security controls, policies, and procedures that might be required by the CISP (if adopted) that should not be applied to SAWs and explain why excluding such security controls, policies, or procedures would be appropriate.
24. Unless technologically or organizationally not possible, the proposed amendments require the CISP to establish controls, policies, and procedures that require the following NIST SP 800-53 control families to be implemented by the Plan Processor and to be common to both the SAWs and the Central Repository: Audit and accountability, security assessment and authorization, configuration management, incident response, system and communications protection, and system and information integrity. Are there technological, organizational, or other impediments to requiring common implementation for the specified control families? Should the security controls, policies, and procedures for other NIST SP 800-53 control families be commonly implemented for the SAWs and the Central Repository? If so, please identify these control families and explain why it would be appropriate to require common implementation. Is it appropriate to require that the common security controls be implemented by the Plan Processor? Is there another party that should implement the common security controls? If so, please identify that party and explain why it would be more appropriate for that party to implement the common security controls.
25. The proposed amendments require the CISP to establish security controls, policies, and procedures such that SAW-specific security controls, policies, and procedures are implemented to cover any NIST SP 800-53 security controls for which common controls, policies, and procedures are not possible. Should the proposed amendments provide this flexibility? Does providing this flexibility endanger the security of the SAWs?
4. Implementation and Operational Requirements for SAWs
To further the security of the CAT System, the Commission preliminarily believes it is important that the SAWs be implemented and operated consistently and in accordance with the CISP.
a. Implementation Requirements for SAWs
Proposed Section 6.13(b)(i) would require the Plan Processor to develop, maintain, and make available to the Participants detailed design specifications for the technical implementation of the access, monitoring,
89
and other controls required for SAWs by the CISP.
90
Proposed Section 6.13(b)(ii) would further require the Plan Processor to notify the Operating Committee that each Participant's SAW has achieved compliance with the detailed design specifications issued by the Plan Processor pursuant to proposed Section 6.13(b)(i) before such SAW may connect to the Central Repository.
89
In addition to the controls, policies, and procedures that specifically relate to or require monitoring, monitoring of security controls is part of the general risk management framework established by NIST SP 800-53.
See, e.g.,
NIST SP 800-53,
supra
note 15, at 8. Detailed design specifications implementing the NIST SP 800-53 controls required by the CISP should therefore detail how the Plan Processor will perform such monitoring and give the Plan Processor sufficient access to the SAWs to conduct such monitoring.
90
See
Part II.A.1. and Part II.C.2.-3.
supra,
for a discussion of the CISP. The Commission preliminarily believes that the Plan Processor could make these detailed design specifications available to the Participants in a number of formats, including by making available a reference SAW account for the Participants to review and analyze.
The Commission preliminarily believes that it is appropriate to require the Plan Processor to develop and maintain detailed design specifications for the technical implementation of the CISP controls. As the party responsible for maintaining data security across the CAT System and for providing the SAWs, the Plan Processor would have the most information regarding the security requirements that are
applicable to SAWs.
91
The Commission preliminarily believes that it would be appropriate for the Plan Processor to share this information with the Participants through detailed design specifications,
92
because releasing such information through detailed design specifications would help the Participants to more precisely understand how they would be able to use and provision their SAWs, what information they would be required to share with the Plan Processor to enable the NIST SP 800-53 access and monitoring controls that are applicable to SAWs, and how the security parameters of the SAWs might impact their existing surveillance protocols.
93
Requiring the Plan Processor to make available detailed design specifications for SAWs may thus increase the likelihood that Participants provision their SAWs with hardware, software, and data that complies with the CISP. Moreover, the development of detailed design specifications would also provide the Plan Processor with uniform criteria with which to evaluate and validate SAWs, which the Commission preliminarily believes should make the notification process required by proposed Section 6.13(b)(ii) more efficient for the Plan Processor and more fair for the Participants.
91
See
Part II.A, Part II.C.1.
supra
92
As public disclosure of these detailed design specifications could raise security concerns, the Commission believes that the Plan Processor and the Participants generally should keep these detailed design specifications confidential.
93
The Commission emphasizes that these detailed design specifications need only implement the access, monitoring, and other controls required by the CISP. Each Participant will have the flexibility to otherwise design the analytic capabilities of its own SAW and to provision it with its own hardware, software, and other data, so long as such activities comply with the CISP.
See
proposed Section 6.13(c)(iii);
see also
Part II.C.4.b.
infra,
for a discussion of the flexibility afforded to the Participants by the proposed amendments.
The security of the CAT is critically important, and the Commission preliminarily believes that it would be prudent to confirm that the detailed design specifications have been implemented properly before permitting any Participant to use its SAW to access CAT Data. Accordingly, the Commission preliminarily believes it is appropriate to require the Plan Processor to evaluate each Participant's SAW and notify the Operating Committee that each Participant's SAW has achieved compliance with the detailed design specifications required by proposed Section 6.13(b)(i) before that SAW may connect to the Central Repository. The Commission preliminarily believes that such an evaluation would establish that the access, monitoring, and other technical controls required for SAWs by the CISP have been implemented properly. The Commission preliminarily believes that SAWs that comply with these detailed design specifications should be sufficiently secure, because those detailed design specifications must implement the full battery of technical controls associated with the CISP, including all required NIST SP 800-53 security controls.
94
The Plan Processor is not only knowledgeable about NIST SP 800-53 security controls, but is also responsible for developing the CISP and the detailed design specifications that would be used to implement the CISP controls.
95
In addition, the Plan Processor would have access, through the CISO, to the collective knowledge and experience of the Security Working Group.
96
For these reasons, the Commission further preliminarily believes that the Plan Processor is best situated to determine whether each Participant's SAW has achieved compliance with such detailed design specifications. Finally, the Commission believes it is appropriate to require that the Plan Processor notify the Operating Committee, that each Participant's SAW has achieved compliance with the detailed design specifications before that SAW may connect to the Central Repository, as this requirement would enable the Operating Committee to better oversee the Plan Processor and the security of the CAT.
94
See
proposed Section 6.13(b)(i); proposed Section 6.13(a)(ii).
See also
Part II.A.1. and Part II.C.2.-3.
supra,
for a discussion of the requirements of the CISP.
95
See
proposed Section 6.13(b)(i).
96
See
Part II.B.
supra
for a discussion of the proposed Security Working Group.
The Commission requests comment on proposed Section 6.13(b). Specifically, the Commission solicits comment on the following:
26. Do commenters agree that development and maintenance of detailed design specifications for the technical implementation of the CISP will enable the consistent, efficient, and secure implementation of SAWs?
27. The proposed amendments require the Plan Processor to develop and maintain detailed design specifications for the technical implementation of the access, monitoring, and other controls required for SAWs by the CISP. Should a different party develop and maintain these detailed design specifications? If so, please identify the party that should develop and maintain these detailed design specifications and explain why. Should the detailed design specifications be subject to review by the Operating Committee, the Security Working Group, or some other entity? If so, please explain why and provide a detailed explanation of what such review process should entail.
28. Should the proposed amendments specify the nature of the monitoring required by NIST SP 800-53 controls? Should the proposed amendments specify that monitoring should be continuous? If so, please explain how that term should be defined and why such definition would be appropriate. Should the proposed amendments indicate whether manual or automated processes (or both) should be used by the Plan Processor and whether automated support tools should be used? Should the proposed amendments explicitly state that the NIST SP 800-53 controls, policies, and procedures require the Participants to give the Plan Processor sufficient access to SAWs in order to enable the monitoring inherently required by such NIST SP 800-53 controls, policies, and procedures? If so, please explain what details should be included in the proposed amendments.
29. The proposed amendments do not specify how the detailed design specifications should be provided by the Plan Processor. Should the proposed amendments require the Plan Processor to provide a reference SAW account? If a specific format should be used, please identify the format that the detailed design specifications should be provided in and explain why that format is appropriate.
30. The proposed amendments require the Plan Processor to notify the Operating Committee that each Participant's SAW has achieved compliance with the detailed design specifications required by Section 6.13(b)(ii) before that SAW may connect to the Central Repository. Is the Plan Processor the appropriate party to make this determination? If not, what other party should make this determination and why? Is evaluation against some benchmark appropriate in order to safeguard the security of CAT Data? Should the SAWs be allowed to connect to the Central Repository without any evaluation process? Are the detailed design specifications required by Section 6.13(b)(ii) an appropriate benchmark? If it is not an appropriate benchmark, please identify what benchmark would be appropriate and explain why. Is it appropriate for the Plan Processor to notify a third party? Should the Operating Committee receive the notification? Should any other parties receive the notification? If so, please identify the parties and
explain why it would be appropriate to provide the notification to these parties.
b. Operation of the SAWs
Proposed Section 6.13(c) would set forth requirements for the Plan Processor and the Participants that are designed to promote compliance with the CISP. First, proposed Section 6.13(c)(i) would require the Plan Processor to monitor each Participant's SAW in accordance with the detailed design specifications developed pursuant to proposed Section 6.13(b)(i), for compliance with the CISP and the detailed designs specifications only, and to notify the Participant of any identified non-compliance with the CISP or the detailed design specifications.
97
Second, proposed Section 6.13(c)(ii) would require the Participants to comply with the CISP, to comply with the detailed design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i), and to promptly remediate any non-compliance identified.
98
97
The proposed amendments would require the Participant to comply with the CISP and the detailed design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i).
See
proposed Section 6.13(c)(ii). If adopted, these requirements would be part of the CAT NMS Plan. Any non-compliance by a Participant with the proposed amendments would constitute non-compliance with the CAT NMS Plan and Rule 613(h)(1) and would also be a systems compliance issue, as defined in Regulation SCI, by such Participant (each Participant being an SCI entity).
See
17 CFR 242.613(h)(1) (requiring Participants to comply with the provisions of the CAT NMS Plan); 17 CFR 242.608(c) (“Each self-regulatory organization shall comply with the terms of any effective national market system plan of which it is a sponsor or a participant.”).
See also
17 CFR 242.1000 (defining “systems compliance issue” as “an event at an SCI entity that has caused any SCI system of such entity to operate in a manner that does not comply with the [Exchange] Act and the rules and regulations thereunder,” defining “SCI event” to include “systems compliance issues,” and defining “SCI entity” to include self-regulatory organizations like the Participants); 17 CFR 242.1002 (setting forth the notification and recordkeeping obligations related to SCI events).
98
This provision would require each Participant to remedy any non-compliance promptly, whether such non-compliance was identified by the Participant or by the Plan Processor.
The Commission preliminarily believes that these requirements will facilitate compliance with the CISP and, therefore, the overall security of the CAT. Requiring the Plan Processor to monitor each Participant's SAW in accordance with the detailed design specifications developed pursuant to proposed Section 6.13(b)(i) should enable the Plan Processor to conduct such monitoring consistently and efficiently across SAWs. It should also help the Plan Processor to identify and to escalate any non-compliance events, threats, and/or vulnerabilities as soon as possible, thus reducing the potentially harmful effects of these matters. Likewise, requiring the Plan Processor to notify the Participant of any identified non-compliance will likely speed remediation of such non-compliance by the Participant and thereby better protect the security of the SAW in question. The Commission also preliminarily believes it is appropriate to limit the scope of the Plan Processor's monitoring to compliance with the CISP and the detailed design specifications developed by the Plan Processor pursuant to Section 6.13(b)(i). The Commission preliminarily believes that this limitation would make it clear that analytical activities in the SAW would not be subject to third-party monitoring, without hampering the ability of the Plan Processor to adequately protect the security of each SAW.
99
99
Similarly, any SAW operated by the Commission would only be subject to monitoring for compliance with the CISP and with the detailed design specifications developed by the Plan Processor pursuant to Section 6.13(b)(i).
See
Part II.N.
infra
for further discussion regarding how the proposed amendments would apply to Commission staff.
The Commission also preliminarily believes it is appropriate to set forth the Participants' obligations to comply with the CISP, as well as the detailed design specifications developed by the Plan Processor pursuant to Section 6.13(b)(i), and to require the Participants to promptly remediate any identified non-compliance.
100
100
Determining whether remediation is prompt may depend on the facts and circumstances surrounding the non-compliance event. The Commission understands that the Plan Processor has developed a risk management policy that outlines appropriate timeframes for remediation based on the risks associated with the non-compliance event, and the Commission preliminarily believes that referring to this policy may be one way of determining whether remediation is prompt under the proposed amendments.
Such compliance is important, but the Commission does not wish to unnecessarily constrain the Participants from employing tools or importing external data that might support or enhance the utility of the SAWs. As noted above, the CISP and the detailed design specifications would only dictate that SAWs comply with certain security requirements; the Participants would still be responsible for building the internal architecture of their SAWs, for providing the analytical tools to be used in their SAWs, and for importing any desired external data into their SAWs. Accordingly, proposed Section 6.13(c)(iii) would explicitly state that the Participants may provide and use their choice of software, hardware, and additional data within their SAWs, so long as such activities otherwise comply with the CISP and the detailed design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i). The Commission preliminarily believes that this provision would provide the Participants with sufficient flexibility in and control over the use of their SAWs, while still maintaining the security of the SAWs and the CAT Data that may be contained therein.
101
101
The Commission would have the same flexibility in and control over the use of its SAW.
See
Part II.N.
infra
for further discussion regarding the application of the proposed amendments to Commission staff. The proposed amendments would not prevent the importation of existing third-party or in-house applications or analytical tools into the SAWs, the migration of external data into the SAWs, or the configuration of the internal architecture of the SAWs.
The Commission requests comment on proposed Section 6.13(c). Specifically, the Commission solicits comment on the following:
31. The proposed amendments would require the Plan Processor to monitor each Participant's SAW in accordance with the detailed design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i). Instead of specifying that such monitoring should be conducted in accordance with the detailed design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i), should the proposed amendments specify the nature of the access and monitoring required by relevant NIST 800-53 controls? Should the proposed amendments specify the nature of the monitoring required by NIST SP 800-53 controls? Should the proposed amendments specify that monitoring should be continuous? If so, please explain how that term should be defined and why such definition would be appropriate. If not, please explain how often such monitoring should be conducted and explain why. Should the proposed amendments indicate whether manual or automated processes (or both) should be used by the Plan Processor and whether automated support tools should be used?
32. The proposed amendments would restrict the Plan Processor to monitoring SAWs for compliance with the CISP and with the detailed design specifications developed pursuant to Section 6.13(b)(i). Is this an appropriate limitation?
33. Is the Plan Processor the right party to monitor each Participant's SAW for compliance with the CISP and with the detailed design specifications developed pursuant to Section 6.13(b)(i)? If a different party should
conduct this monitoring, please identify that party and explain why it would be a more appropriate choice. Is there a different set of standards that should control the monitoring process? If so, please identify that set of standards and explain why it is a more appropriate choice.
34. The proposed amendments would require the Plan Processor to notify the Participant of any identified non-compliance with the CISP or the detailed design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i). Should a different party notify the Participant of any identified non-compliance? If so, please identify that party and explain why it would be appropriate for them to provide the notification. Are there any additional parties that the Plan Processor should notify of any identified non-compliance—for example, the Security Working Group or the Operating Committee? If so, please identify the party or parties that should also be notified, explain why such notification would be appropriate, and explain whether such notification would raise any confidentiality, security, or competitive concerns.
35. The proposed amendments would specify that the Participants must comply with the CISP and the detailed design specifications developed pursuant to Section 6.13(b)(i). Should the proposed amendments specify that the Participants must comply with any other security protocols or industry standards? If so, please identify these security protocols or industry standards and explain why it would be appropriate to require the Participants to comply with them.
36. Should the proposed amendments specify a process to govern the resolution of potential disputes regarding non-compliance identified by the Plan Processor? For example, should the proposed amendments permit Participants to appeal to the Operating Committee? If such an appeal process should be included in the proposed amendments, please identify all aspects of that appeal process in detail and explain why those measures would be appropriate. How long should a Participant be given to make such an appeal and what materials should be provided to the Operating Committee? Would it be appropriate to require a Participant to appeal the determination to the Operating Committee within 30 days? Is 30 days enough time for a Participant to prepare an appeal? How long should the Operating Committee have to issue a final determination? Would 30 days be sufficient? Should the final determination be required to include a written explanation from the Operating Committee supporting its finding? Once the final determination has been issued, how long should the Participant be given to remediate any non-compliance that is confirmed by the Operating Committee's determination? Should Participants who are appealing to the Operating Committee be permitted to continue to connect to the Central Repository while such an appeal is pending?
37. Is it appropriate to require the Participants to promptly remediate any identified non-compliance or should another standard be used? Should the proposed amendments specify what would qualify as “prompt” remediation? If so, please explain what amount of time should be specified and explain why that amount of time is sufficient. Would it be appropriate for the proposed amendments to refer specifically to the risk management policy developed by the Plan Processor for appropriate remediation timeframes? Is there another policy that provides remediation timeframes that would be more appropriate for these purposes? If so, please identify that policy and explain why it would be a better benchmark.
38. The proposed amendments clarify that the Participants may provide and use their choice of software, hardware, and additional data within the SAWs, so long as such activities otherwise comply with the CISP. Is it appropriate to provide Participants with this level of flexibility in and control over their use of the SAWs?
39. The proposed amendments do not require the Plan Processor to customize each SAW account for Participant use. Should the proposed amendments require the Plan Processor to provide each Participant with a SAW that already has certain analytic capabilities or internal architecture built into it? If so, please explain why that would be more appropriate and identify what analytic capabilities or internal architecture the Plan Processor should provide. Should the Plan Processor be required to take specific and individual instructions from each Participant as to how each SAW should be built? Should the proposed amendments specify that each SAW should be of a certain size and/or capable of supporting a certain amount of data? If so, please explain what parameters would be appropriate.
5. Exceptions to the SAW Usage Requirements
As explained above, the Commission preliminarily believes that the CAT NMS Plan should be amended to better protect CAT Data accessed via the user-defined direct query or bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan, as the current CAT NMS Plan does not limit the download capabilities associated with these tools.
102
The Commission, however, recognizes that some Participants may have a reasonable basis for not using a SAW to access CAT Data via the user-defined direct query or bulk extract tools and may have built a sufficiently secure non-SAW environment in which these tools may be employed. The Commission therefore proposes to add provisions to the CAT NMS Plan that would set forth a process by which Participants may be granted an exception from the requirement in proposed Section 6.13(a)(i)(B) of the CAT NMS Plan to use a SAW to access CAT Data through the user-defined direct query and bulk extract tools.
103
The Commission also proposes to add provisions to the CAT NMS Plan that would set forth implementation and operational requirements for any non-SAW environments granted such an exception.
102
See also
Part II.C.
supra.
103
Only transactional data can be accessed through the user-defined direct query and bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan. Therefore, the proposed exception process would not permit the Participants to access Customer and Account Attributes data in a non-SAW environment.
a. Exception Process for Non-SAW Environments
The proposed amendments would permit a Participant to be granted an exception to employ the user-defined direct query and bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan in a non-SAW environment. Proposed Section 6.13(d)(i)(A) would require the Participant requesting the exception to provide the Plan Processor's CISO, the CCO, the members of the Security Working Group (and their designees), and Commission observers of the Security Working Group with various application materials. First, the Participant would be required to provide a security assessment of the non-SAW environment, conducted within the prior twelve months by a named, independent third party security assessor,
104
that (a) demonstrates the extent to which the non-SAW environment complies with the NIST SP 800-53 security controls and associated
policies and procedures required by the CISP pursuant to Section 6.13(a)(ii), (b) explains whether and how the Participant's security and privacy controls mitigate the risks associated with extracting CAT Data to the non-SAW environment through the user-defined direct query or bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan, and (c) includes a Plan of Action and Milestones document detailing the status and schedule of any corrective actions recommended by the assessment.
105
Second, the Participant would be required to provide detailed design specifications for the non-SAW environment demonstrating: (a) The extent to which the non-SAW environment's design specifications adhere to the design specifications developed by the Plan Processor for SAWs pursuant to proposed Section 6.13(b)(i), and (b) that the design specifications will enable the operational requirements set forth for non-SAW environments in proposed Section 6.13(d)(iii), which include, among other things, Plan Processor monitoring.
106
104
For the purposes of the proposed amendments, affiliates of a Participant would not be considered “independent third party security assessors.”
105
See
proposed Section 6.13(d)(i)(A)(1). NIST SP 800-53 defines a Plan of Action and Milestones document as a “document that identifies tasks needing to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones.”
See
NIST SP 800-53,
supra
note 15, at B-16.
106
See
proposed Section 6.13(d)(i)(A)(2).
See also
proposed Section 6.13(d)(iii); Part II.C.5.b.
infra,
for a discussion of the operational requirements that must be enabled by the design specifications for a non-SAW environment.
Proposed Section 6.13(d)(i)(B) would then require the CISO and the CCO to simultaneously notify the Operating Committee and the requesting Participant of their determination within 60 days of receipt of these application materials. Under the proposed amendments, the CCO and CISO may jointly grant an exception if they determine, in accordance with policies and procedures developed by the Plan Processor, that the residual risks
107
identified in the security assessment or detailed design specifications provided by the requesting Participant do not exceed the risk tolerance levels set forth in the risk management strategy developed by the Plan Processor for the CAT System pursuant to NIST SP 800-53.
108
This standard effectively subjects each non-SAW environment to the same risk management policy as the CAT System itself, as the Commission preliminarily believes that the Participant applying for the exception should demonstrate that the CAT Data in its non-SAW environments will be protected in a similar manner as CAT Data within the CAT System.
107
By “residual risks,” the Commission means any risks that are associated with the absence of a security control or the deficiency of a security control, as evaluated by the required security assessment.
108
See
proposed Section 6.13(d)(i)(B)(1). NIST SP 800-53 requires the Plan Processor to develop an organization-wide risk management strategy that includes, among other things, “an unambiguous expression of the risk tolerance for the organization . . . .”
See
NIST SP 800-53,
supra
note 15, at Appendix G-6 (providing supplemental guidance for the PM-9 control).
If the exception is granted or denied, the proposed amendments would require the CISO and the CCO to provide the requesting Participant
109
with a detailed written explanation setting forth the reasons for that determination. For applications that are denied, the proposed amendments would further require the CISO and the CCO to specifically identify the deficiencies that must be remedied before an exception could be granted.
110
109
See
proposed Section 6.13(d)(i)(B)(1).
110
See
proposed Section 6.13(d)(i)(B)(2). Denied Participants would be permitted to re-apply for an exception, after remedying the deficiencies identified by the CISO and the CCO, by submitting a new security assessment that complies with the requirements of proposed Section 6.13(d)(i)(A)(1) and up-to-date versions of the materials specified in proposed Section 6.13(d)(i)(A)(2).
See
proposed Section 6.13(d)(i)(C).
The proposed amendments state that continuance of any exceptions that are granted is dependent upon an annual review process.
111
To continue an exception, the proposed amendments would require the requesting Participant to provide a new security assessment that complies with the requirements of proposed Section 6.13(d)(i)(A)(1) and up-to-date versions of the materials required by proposed Section 6.13(d)(i)(A)(2) to the CISO, the CCO, the members of the Security Working Group (and their designees), and Commission observers of the Security Working Group at least once a year, as measured from the date that the initial application materials were submitted.
112
Exceptions would be revoked by the CISO and the CCO for Participants who do not submit these application materials on time, in accordance with remediation timeframes developed by the Plan Processor.
113
Such Participants would be required to cease using their non-SAW environments to access CAT Data through the user-defined direct query and bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan.
114
111
See
proposed Section 6.13(d)(ii).
112
See
proposed Section 6.13(d)(ii)(A).
113
See id.
The Commission understands that the Plan Processor has developed a risk management policy that outlines appropriate timeframes for remediation based on the risks presented by a non-compliance event, and the Commission preliminarily believes that referring to this policy would be an appropriate method for determining what timeframe is appropriate for revoking a Participant's exception.
114
See
proposed Section 6.13(d)(ii)(C).
Within 60 days of receipt of these updated application materials, the CISO and the CCO would then be required to simultaneously notify the Operating Committee and the requesting Participant of their determination.
115
The proposed amendments would require the CISO and the CCO to make this determination using the same criteria, and issue that determination following the same process, set forth for initial exceptions.
116
Participants that receive a determination granting a continuance would be required to repeat this process annually; participants that receive a determination denying a continuance would be required by the CISO and the CCO to cease using the user-defined direct query and bulk extract tools to access CAT Data in their non-SAW environments in accordance with the remediation timeframes developed by the Plan Processor.
117
115
See
proposed Section 6.13(d)(ii)(B).
See also
proposed Section 6.2(a)(v)(S) (requiring the CCO to determine, pursuant to Section 6.13(d), whether a Participant should be granted an exception from Section 6.13(a)(i)(B) and, if applicable, whether such exception should be continued); proposed Section 6.2(b)(ix) (requiring the CISO to determine, pursuant to Section 6.13(d), whether a Participant should be granted an exception from Section 6.13(a)(i)(B) and, if applicable, whether such exception should be continued).
116
See
proposed Section 6.13(d)(ii)(B). Likewise, denied Participants would be permitted to re-apply following the same process that was outlined above for initial exceptions.
See
proposed Section 6.13(d)(ii)(C);
see also
note 110
supra.
117
See
proposed Section 6.13(d)(ii)(A); proposed Section 6.13(d)(ii)(C).
See also
note 113
supra.
Denied Participants would be permitted to re-apply for an exception, after remedying the deficiencies identified by the CISO and the CCO, by submitting new and updated versions of the application materials that have been prepared within twelve months of the date of submission.
See
proposed Section 6.13(d)(ii)(C).
The proposed exception process is designed to help improve the security of CAT Data while allowing the Participants some flexibility in how they access CAT Data. Participants may have reasons for needing to use a non-SAW environment to access CAT Data, including, for example, reduction of burdensome costs and/or operational complexity. The Commission therefore preliminarily believes it is appropriate to provide the Participants with the option to use non-SAW environments, if that can be accomplished in a manner that will not compromise the overall security of CAT Data. To that end, the proposed exception process would not
permit the Participants to access Customer and Account Attributes data in a non-SAW environment; only transactional data is retrievable through the user-defined direct query or bulk extract tools described by Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan.
118
Non-SAW environments meeting the requirements outlined above may provide a sufficient level of security for all CAT Data, but it is of paramount importance that access to Customer and Account Attributes data is guarded by the highest possible level of protection. Because the Commission preliminarily believes that such protection is only available through the use of a SAW environment and through the proposed limitations on the extraction of Customer and Account Attributes data from a SAW environment,
119
the proposed exception process would not apply to Customer and Account Attributes data.
118
See, e.g.,
CAT NMS Plan,
supra
note 3, at Appendix D, Section 4.1.6 (“PII data must not be included in the result set(s) from online or direct query tools, reports or bulk data extraction. Instead, results will display existing non-PII unique identifiers (
e.g.,
Customer-ID or Firm Designated ID).”).
119
See
Part II.C.2.
supra
for additional discussion of these proposed limitations.
With respect to the specific features of the proposed exception process, the Commission preliminarily believes it is appropriate to require Participants seeking an exception to provide the CISO and the CCO with the proposed application materials, because such materials should provide critical information to the parties responsible for deciding whether to grant an exception.
120
The proposed requirement that the Participant produce a security assessment conducted within the last twelve months by an independent and named third party should give these decision-makers access to up-to-date, accurate, and unbiased information about the security and privacy controls put in place for the relevant non-SAW environment, including reliable information about risk mitigation measures and recommended corrective actions.
121
The Commission also preliminarily believes that it is appropriate, as part of this security assessment, to require the requesting Participant to demonstrate the extent to which the non-SAW environment complies with the NIST SP 800-53 security controls and associated policies and procedures required by the CISP pursuant to proposed Section 6.13(a)(ii), to explain whether and how the Participant's security and privacy controls mitigate the risks associated with extracting CAT Data to the non-SAW environment, and to include a Plan of Action and Milestones document detailing the status and schedule of any recommended corrective actions.
122
The CAT NMS Plan requires the Plan Processor to perform similar security assessments to verify and validate the security of the CAT System,
123
so the Commission preliminarily believes that it is reasonable to require a Participant seeking to export CAT Data outside of the CAT System to demonstrate a similar level of due diligence and a similar level of security as would be required for SAWs pursuant to proposed Section 6.13(a)(ii). The Commission also preliminarily believes that this information will help the CISO and the CCO to determine whether the non-SAW environment is sufficiently secure to be granted an exception from the SAW usage requirements set forth in proposed Section 6.13(a)(i)(B).
124
120
Certain aspects of the proposed amendments put the burden of proof on the requesting Participant. For example, in its application, the Participant would be required to demonstrate that the non-SAW environment complies with the NIST SP 800-53 security controls required by the CISP pursuant to proposed Section 6.13(a)(ii) and that the design specifications enable the operational requirements for non-SAW environments. The Commission preliminarily believes that this is the most appropriate and efficient approach; the party seeking an exception from the security requirements of the CAT should be required to bear the burden of demonstrating that such an exception is justified, and the requesting Participant will be better situated to marshal evidence to prove that its systems are secure than would be the CISO, the CCO, or the Security Working Group.
121
See
proposed Section 6.13(d)(i)(A)(1).
122
See id.
123
See
CAT NMS Plan,
supra
note 3, at Appendix D, Section 5.3 (“The Plan Processor must conduct third party risk assessments at regular intervals to verify that security controls implemented are in accordance with NIST SP 800-53.”).
124
See
proposed Section 6.13(d)(i)(B)(1).
Similarly, the Commission preliminarily believes that it is appropriate to require the requesting Participant to provide detailed design specifications for its non-SAW environment that demonstrate the extent of adherence to the SAW design specifications developed by the Plan Processor pursuant to Section 6.13(b)(i). The detailed design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i) would implement the access, monitoring, and other technical controls of the CISP that are applicable to SAWs. Requiring Participants seeking an exception to the SAW usage requirements to demonstrate whether the design specifications for their non-SAW environment adhere to the SAW design specifications would therefore provide the CISO and the CCO with specific technical information regarding the security capabilities of the non-SAW environment and may therefore prove more informative than the review of the Participant's information security policies for comparability that is currently required by Section 6.2(b)(vii) of the CAT NMS Plan. The Commission further preliminarily believes that it is appropriate to require the requesting Participant to demonstrate that the design specifications will enable the proposed operational requirements for non-SAW environments.
125
This information would help the CISO and the CCO to assess the security-related infrastructure of the non-SAW environment and whether the non-SAW environment would support the required non-SAW operations.
126
125
See
note 106
supra.
126
See
proposed Section 6.13(d)(iii).
The Commission preliminarily believes that it is also appropriate for the members of the Security Working Group (and their designees) and Commission observers of the Security Working Group to receive the above-described application materials.
127
Although the Security Working Group is not a decision-maker under the proposed amendments, the Commission preliminarily believes that it would be in the public interest to enable both the decision-makers and the members of the Security Working Group (and their designees)—a body of information security experts that would be specifically established to assess and protect the security of the CAT—to review any application materials. Given the expertise of its members, which would include the chief or deputy chief information security officer for each Participant, the Security Working Group may be able to provide valuable feedback to the CISO and the CCO regarding any request for an exception to the SAW usage requirements.
128
Moreover, by providing the application materials to the Commission observers of the Security Working Group, the Commission preliminarily believes that
the proposed amendments will better facilitate Commission oversight of the security of CAT Data.
127
See
proposed Section 6.13(d)(i)(A). The proposed amendments specifically limit the distribution of the application materials to members of the Security Working Group and their designees so that the confidentiality obligations of Section 9.6 of the CAT NMS Plan will apply to protect the sensitive information contained in the application materials.
See
note 30
supra.
128
The Commission does not preliminarily believe that competitive relationships between the Participants would affect how individual members of the Security Working Group review the application materials and advise the CISO and the CCO, because each Participant has an overriding interest in the security of the CAT.
See
CAT NMS Plan,
supra
note 3, at Appendix C (indicating that the CAT will be a facility of each Participant);
see also
Part IV.A.2.
infra
for further discussion of this concern.
The Commission preliminarily believes, however, that only the CISO and the CCO should be the decision-makers regarding any requested exceptions. Not only are the CISO and the CCO fiduciaries to the Plan Processor and to the Company,
129
but they also have the most experience, knowledge, and expertise regarding the overall operation of the CAT, the state of the CAT's security, and compliance with the CAT NMS Plan. These two officers are likely to be the best situated to identify any issues that may be raised by applications for exceptions from the SAW usage requirements. As the decision-makers, the CISO and the CCO would ultimately be responsible under the proposed amendments for determining whether an exception from the SAW usage requirements may be granted.
129
See
CAT NMS Plan,
supra
note 3, at Section 4.6(a), Section 4.7(c). In addition, to the extent that competitive relationships between the Participants may affect how individual members of the Security Working Group review the application materials and advise the CISO and the CCO, the Commission preliminarily believes that identifying the CISO and the CCO as the decision-makers will protect against any such bias in the review process.
See
Part IV.A.2.
infra
for further discussion of the Security Working Group.
The proposed amendments state that the CISO and the CCO must simultaneously notify the Operating Committee and the requesting Participant of their determination within 60 days of receiving the above-described application materials.
130
The Commission preliminarily believes that the proposed 60-day review period provides the CISO and the CCO with sufficient time to examine, analyze, and investigate the application materials. Moreover, the Commission preliminarily believes that this limitation should also provide the requesting Participant with some amount of certainty regarding the length of the review period and the date by which a determination will be issued, which could be useful for planning purposes.
131
130
See
proposed Section 6.13(d)(i)(B).
131
Participants that choose to rely solely on a non-SAW environment for certain surveillance or regulatory functions may not be able to perform those functions unless and until an exception is granted; therefore, placing a time limit on the review period may help these Participants to stage their resources appropriately.
The proposed amendments also specify that an exception may only be granted if the CISO and the CCO determine, in accordance with policies developed by the Plan Processor, that the residual risks identified in the security assessment or detailed design specifications provided by the requesting Participant do not exceed the risk tolerance levels set forth in the risk management strategy developed by the Plan Processor for the CAT System pursuant to NIST SP 800-53.
132
The Commission preliminarily believes that it is appropriate to identify the conditions under which an exception from the SAW usage requirements may be granted. By making it clear that an exception may only be granted if an objective standard is met or exceeded, the proposed amendments should facilitate a consistent and fair decision-making process.
133
132
See
proposed Section 6.13(d)(i)(B)(1).
133
Similarly, the Commission believes that requiring the CISO and the CCO to reach their determination in accordance with policies developed by the Plan Processor will facilitate a consistent and fair decision-making process.
See id.
Furthermore, the Commission preliminarily believes that is it appropriate to require the CISO and the CCO to determine, in accordance with policies developed by the Plan Processor, that the residual risks identified in the security assessment or detailed design specifications provided by the requesting Participant do not exceed the risk tolerance levels set forth in the risk management strategy developed by the Plan Processor for the CAT System pursuant to NIST SP 800-53. This criterion would prohibit granting an exception to non-SAW environments that are not sufficiently secure to house CAT Data.
As noted above, the Commission preliminarily believes that it is important that the review by the CISO and the CCO be consistent and fair, and transparency will advance both objectives. The proposed amendments therefore include measures designed to protect the transparency of the review process. First, the CISO and the CCO would be required to simultaneously notify both the requesting Participant and the Operating Committee of their determination.
134
This requirement is designed to provide the Operating Committee with the most up-to-date information about non-SAW environments that house CAT Data. Second, the CISO and the CCO would be required to provide the Participant with a detailed written explanation setting forth the reasons for their determination and, for denied Participants, specifically identifying the deficiencies that must be remedied before an exception could be granted.
135
The Commission preliminarily believes that this kind of feedback could be quite valuable—not only because it should require the CISO and the CCO to thoroughly review an application and to identify and articulate any deficiencies, but also because it should provide denied Participants with the information needed to effectively bring their non-SAW environments into compliance with the proposed standards.
136
134
See
proposed Section 6.13(d)(i)(B)(1)-(2). The Commission preliminarily believes that the Advisory Committee generally should be notified when the Operating Committee is notified.
135
See
proposed Section 6.13(d)(i)(B)(2).
136
See
proposed Section 6.13(d)(i)(C). The Commission does not believe that a formal appeals process is appropriate or necessary. However, the Commission preliminarily believes that a denied Participant should not be barred from re-applying for an exception from the SAW usage requirements set forth in proposed Section 6.13(a)(i)(B) if a Participant is able to remediate the issues identified by the CISO and the CCO.
For exceptions that are granted, the proposed amendments would require the requesting Participant to seek a continuance of this exception by initiating an annual review process through the submission of a new security assessment that complies with the requirements of proposed Section 6.13(d)(i)(A)(1) and up-to-date application materials at least once a year, as measured from the date that the initial application materials were submitted. Participants that fail to submit updated application materials on time would have their exceptions revoked in accordance with the remediation timelines developed by the Plan Processor, and the proposed amendments would require such Participants to cease using their non-SAW environments to access CAT Data through the user-defined direct query or bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan.
These proposed requirements essentially would impose an annual term on any exception granted by the CISO and the CCO. The Commission preliminarily believes that this limitation is appropriate. Technology and security concerns are constantly and rapidly evolving, and the conditions that might justify the initial grant of an exception from the proposed SAW usage requirements may no longer be in place at the end of an annual term.
137
Accordingly, the Commission
preliminarily believes that it is appropriate to require a requesting Participant to provide a new security assessment and up-to-date design specifications for the non-SAW environment. Updated design specifications may adequately capture any technical changes made to a non-SAW environment over the course of a year, but the Commission preliminarily believes that a more in-depth approach is needed with respect to the required security assessment. Requiring the requesting Participant to provide a new security assessment that complies with the requirements of proposed Section 6.13(d)(i)(A)(1)—as opposed to an updated version of the security assessment provided with the initial application—would better identify and describe any risks presented by a non-SAW environment, based on the current security control implementation of the Participant.
137
This annual term is also consistent with existing requirements in the CAT NMS Plan that the Plan Processor's performance be evaluated on at least an annual basis.
See
CAT NMS Plan,
supra
note 3, at Section 6.6(b). The Commission preliminarily believes it is reasonable to require a Participant seeking to export CAT Data outside of the CAT System to be evaluated with a similar frequency.
For similar reasons, the Commission preliminarily believes that the proposed continuance process is appropriate. The proposed continuance process is substantially identical to the proposed process for initial exceptions; it requires that the requesting Participant submit a new security assessment that complies with the requirements of proposed Section 6.13(d)(i)(A)(1) and up-to-date versions of the materials required by proposed Section 6.13(d)(i)(A)(2) to the CISO, the CCO, the members of the Security Working Group (and their designees), and Commission observers of the Security Working Group and that the CCO and CISO notify the Operating Committee and the requesting Participant of their determination, using the same criteria and process outlined for the initial exception process, within 60 days of receiving those application materials. The Commission preliminarily does not believe that it is appropriate to lighten the requirements for the continuance process. To best protect the CAT and CAT Data, Participants seeking a continued exception to the SAW usage requirements should not be allowed to meet a lesser standard for continuance than was required for the initial exception.
138
Because technology and security concerns are constantly evolving, as noted above, the Commission preliminarily believes it is crucial to implement a continuance process that emphasizes regular and consistent reevaluation of the security of non-SAW environments.
138
For similar reasons, the Commission believes it is appropriate to require denied Participants to re-apply by submitting a new security assessment that complies with the requirements of proposed Section 6.13(d)(i)(A)(1) and up-to-date materials that comply with the requirements of proposed Section 6.13(d)(i)(A)(2) and by subjecting their non-SAW environments to the same review processes used for initial evaluations.
Finally, and for the same reasons expressed above, the Commission preliminarily believes it is appropriate for the proposed amendments to cut off access to the user-defined direct query and bulk extract tools if a Participant is denied a continuance or fails to submit updated application materials in a timely manner. Participants should not be indefinitely allowed to continue to access large amounts of CAT Data outside the security perimeter of the CAT without an affirmative determination that their systems are secure enough to adequately protect that information. However, the Commission preliminarily believes that the risks involved with permitting a Participant to continue using a non-SAW environment, after its exception has lapsed and while transitioning into a SAW, will likely depend on the facts and circumstances related to that particular Participant and the way it uses the non-SAW environment. Immediate revocation of access to CAT Data may be appropriate in some situations, particularly where a significant risk is posed to CAT Data, but a long transition period may be more appropriate in other situations. Requiring an exception to be revoked by the CISO and the CCO in accordance with remediation timeframes developed by the Plan Processor would allow the CISO and the CCO to take into account any relevant facts and circumstances and to craft an appropriate response to the presented risks.
The Commission requests comment on the proposed exception process. Specifically, the Commission solicits comment on the following:
40. Should Participants be permitted to seek an exception from the requirement in proposed Section 6.13(a)(i)(B) to use a SAW to access CAT Data through the user-defined direct query and bulk extract tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan? Should Participants only be able to employ user-defined direct query and bulk extract tools in connection with a SAW?
41. As noted above, Customer and Account Attributes data is not available through the user-defined direct query and bulk extraction tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan. Therefore, the proposed amendments would not permit any Participants to access Customer and Account Attributes in a non-SAW environment via the exceptions process. Should Participants be allowed to access Customer and Account Attributes data in a non-SAW environment approved by the CISO and the CCO? If so, please explain under what circumstances such access should be allowed and what limits, if any, should be applied.
42. The proposed amendments would require the requesting Participant to submit to CISO, the CCO, the members of the Security Working Group (and their designees), and Commission observers of the Security Working Group the following materials: (1) A security assessment of the non-SAW environment, conducted within the last twelve months by a named, independent third party security assessor, that: (a) Demonstrates the extent to which the non-SAW environment complies with the NIST SP 800-53 security controls and associated policies and procedures required by the CISP pursuant to proposed Section 6.13(a)(ii), (b) explains whether and how the Participant's security and privacy controls mitigate the risks associated with exporting CAT Data to the non-SAW environment through the user-defined direct query or bulk extraction tools, and (c) includes a Plan of Action and Milestones document detailing the status and schedule of any corrective actions recommended by the assessment; and (2) detailed design specifications for the non-SAW environment demonstrating (a) the extent to which the non-SAW environment's design specifications adhere to the design specifications developed by the Plan Processor for SAWs pursuant to proposed Section 6.13(b)(i), and (b) that the design specifications will enable the operational requirements set forth for non-SAW environments in proposed Section 6.13(d)(iii).
a. Is it appropriate to require that the requesting Participant submit a security assessment of the non-SAW environment that has been conducted by a named, independent third party security assessor within the last twelve months? Should the Commission require that a more recent security assessment be submitted or permit a less recent security assessment to be submitted? If so, how recent should the security assessment be? Please explain. Would the security assessment be as reliable if the Commission eliminated the requirement that it be conducted by a named, independent third party security assessor?
b. Is it appropriate to require that the proposed security assessment demonstrate the extent to which the non-SAW environment complies with
the NIST SP 800-53 security controls and associated policies and procedures required by the CISP established pursuant to proposed Section 6.13(a)(ii)? Would a different set of security and privacy controls be more appropriate? If so, please identify that set of security and privacy controls and explain in detail why that standard would be a better benchmark. Would it be more appropriate to require the non-SAW environment to demonstrate compliance with the security and privacy controls described in NIST SP-800-53 for low, moderate, and high baselines, as described in NIST SP 800-53? If so, please indicate which benchmark would be more appropriate and explain why.
c. Is it appropriate to require that the proposed security assessment explain whether and how the Participant's security and privacy controls mitigate the risks associated with exporting CAT Data to the non-SAW environment through the user-defined direct query or bulk extraction tools described in Section 6.10(c)(i)(B) and Appendix D, Section 8.2 of the CAT NMS Plan?
d. Is it appropriate to require that the proposed security assessment include a Plan of Action and Milestones document detailing the status and schedule of any recommended corrective actions?
e. Are there any other items that should be included in the security assessment, including any items that would assist the CISO and the CCO to determine whether the non-SAW environment is sufficiently secure to be granted an exception from the SAW usage requirements set forth in proposed Section 6.13(a)(i)(B)? Please identify these items and explain why they should be included.
f. Is it appropriate to require that the requesting Participant provide detailed design specifications for its non-SAW environment that demonstrate the extent of adherence to the SAW design specifications developed by the Plan Processor pursuant to proposed Section 6.13(b)(i)? Is a different set of design specifications a better benchmark by which to judge the non-SAW environment's operational capabilities? If so, please identify that set of design specifications and explain why it is more appropriate. The proposed amendments also require that the requesting Participant demonstrate that the submitted design specifications will enable the proposed operational requirements for non-SAW environments under proposed Section 6.13(d)(iii). Is this an appropriate requirement?
g. Is it appropriate to require that the proposed application materials be submitted to the CISO, the CCO, the members of the Security Working Group (and their designees), and Commission observers of the Security Working Group? Should any different or additional parties receive the proposed application materials? If so, please identify those parties and explain why they should receive the proposed application materials. Does the inclusion of the members of the Security Working Group and their designees raise any confidentiality, security, or competitive concerns? If so, please identify such concerns and explain whether the benefits of including the Security Working Group nevertheless justify providing the members of the Security Working Group and their designees with the required application materials.
43. The proposed amendments state that the CISO and the CCO must notify the Operating Committee and the requesting Participant of their determination regarding an exception (or a continuance) within 60 days of receiving the application materials described in proposed Section 6.13(d)(i)(A).
a. Is it appropriate to require that the CISO and the CCO make this determination? If it is not appropriate to require the CISO and the CCO to make this determination, which party or parties should be required to make this determination? Please explain why those parties would be appropriate decision-makers.
b. Is it appropriate that the CISO and the CCO simultaneously notify the Operating Committee and the requesting Participant of their determination? Should the Participant be notified before the Operating Committee? If so, how long should the CISO and the CCO be required to wait before notifying the Operating Committee? Are there any different or additional parties that should receive the determination? If so, please identify those parties and explain why it would be appropriate for them to receive the determination issued by the CISO and the CCO. For example, should the proposed amendments require notification of the Advisory Committee, even though the Advisory Committee is likely to be informed of these determinations in regular meetings of the Operating Committee? Would notification of the Advisory Committee raise any security or confidentiality concerns, such that these matters should only be addressed in executive sessions of the Operating Committee? Should the rule specify that any issues related to exceptions should only be discussed in executive sessions of the Operating Committee? Does a Participant's application for an exception create circumstances in which it would be appropriate to exclude non-Participants from discussion of such applications? Should the Participants be required to submit requests to enter into an executive session of the Operating Committee on a written agenda, along with a clearly stated rationale for each matter to be discussed? If so, should each such request have to be approved by a majority vote of the Operating Committee?
c. Is it appropriate to require the CISO and the CCO to make their determination within 60 days of receiving the application materials? If a different review period would be more appropriate, please state how much time the CISO and the CCO should have to review the application materials and explain why that amount of time would be more appropriate.
d. Should the proposed amendments include provisions allowing the C
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.