<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Harvard Law School Forum on Corporate Governance</title>
	<atom:link href="https://corpgov.law.harvard.edu/2016/01/02/cftcs-proposed-rules-on-cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://corpgov.law.harvard.edu</link>
	<description>The leading online blog in the fields of corporate governance and financial regulation.</description>
	<lastBuildDate>Mon, 18 May 2026 13:57:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.5.8</generator>

<image>
	<url>https://corpgov.law.harvard.edu/wp-content/uploads/2024/02/cropped-photography-4-e1706898544564-1-32x32.png</url>
	<title>CFTC&#8217;s Proposed Rules on Cybersecurity &#8211; The Harvard Law School Forum on Corporate Governance</title>
	<link>https://corpgov.law.harvard.edu</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CFTC&#8217;s Proposed Rules on Cybersecurity</title>
		<link>https://corpgov.law.harvard.edu/2016/01/02/cftcs-proposed-rules-on-cybersecurity/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cftcs-proposed-rules-on-cybersecurity</link>
		<comments>https://corpgov.law.harvard.edu/2016/01/02/cftcs-proposed-rules-on-cybersecurity/#comments</comments>
		<pubDate>Sat, 02 Jan 2016 14:51:04 +0000</pubDate>
<!-- 		<dc:creator><![CDATA[]]></dc:creator> -->
				<category><![CDATA[Accounting & Disclosure]]></category>
		<category><![CDATA[Banking & Financial Institutions]]></category>
		<category><![CDATA[Derivatives]]></category>
		<category><![CDATA[Legislative & Regulatory Developments]]></category>
		<category><![CDATA[Practitioner Publications]]></category>
		<category><![CDATA[Securities Regulation]]></category>
		<category><![CDATA[Accounting]]></category>
		<category><![CDATA[Audits]]></category>
		<category><![CDATA[CFTC]]></category>
		<category><![CDATA[Clearing houses]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Financial institutions]]></category>
		<category><![CDATA[Recovery & resolution plans]]></category>
		<category><![CDATA[Risk]]></category>
		<category><![CDATA[Risk assessment]]></category>
		<category><![CDATA[Risk oversight]]></category>
		<category><![CDATA[Securities regulation]]></category>
		<category><![CDATA[Swaps]]></category>
		<category><![CDATA[Swaps entities]]></category>

		<guid isPermaLink="false">https://corpgov.law.harvard.edu/?p=72241?d=20160102095207EST</guid>
		<description><![CDATA[Last week, the Commodity Futures Trading Commission (CFTC) proposed cybersecurity regulations for electronic trading platforms, clearing organizations, and data repositories. Most importantly, the proposal calls for five types of systems testing, the most impactful of which is the requirement that organizations test key controls (e.g., access to sensitive data or procedures that control changes to [&#8230;]]]></description>
				<content:encoded><![CDATA[<hgroup><em>Posted by Dan Ryan, PricewaterhouseCoopers LLP, on Saturday, January 2, 2016 </em><div class='e_n' style='background:#F8F8F8;padding:10px;margin-top:5px;margin-bottom:10px;text-indent:2.5em;'><strong style='margin-left:-2.5em;'>Editor's Note: </strong> <p style="margin:0; display:inline;">Dan Ryan is Leader of the Financial Services Advisory Practice at PricewaterhouseCoopers LLP. This post is based on a PwC publication by Mr. Ryan, Sean Joyce, Joseph Nocera, Jeff Lavine, Didier Lavion, and Armen Meyer.</p>
</div></hgroup><p>Last week, the Commodity Futures Trading Commission (CFTC) proposed cybersecurity regulations for electronic trading platforms, clearing organizations, and data repositories. Most importantly, the proposal calls for five types of systems testing, the most impactful of which is the requirement that organizations test key controls (e.g., access to sensitive data or procedures that control changes to critical systems).</p>
<p>Guidance from other regulators thus far has come in the form of examination guidelines or self-assessment tools rather than regulations. <a href="https://corpgov.law.harvard.edu/2016/01/02/cftcs-proposed-rules-on-cybersecurity/#1">[1]</a><a name="1b"></a> The CFTC’s proposal would be the first cybersecurity regulation, and some other regulators are likely to follow suit. <a href="https://corpgov.law.harvard.edu/2016/01/02/cftcs-proposed-rules-on-cybersecurity/#2">[2]</a><a name="2b"></a></p>
<p> <a href="https://corpgov.law.harvard.edu/2016/01/02/cftcs-proposed-rules-on-cybersecurity/#more-72241" class="more-link"><span aria-label="Continue reading CFTC&#8217;s Proposed Rules on Cybersecurity">(more&hellip;)</span></a></p>
]]></content:encoded>
			<wfw:commentRss>https://corpgov.law.harvard.edu/2016/01/02/cftcs-proposed-rules-on-cybersecurity/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
