§242.1007. Requirements for service bureaus. — Inbound Citations
17 C.F.R. § 242.1007
Statutory Authority
Cited by 3 regulations in release Current.
Citations to 17 C.F.R. § 242.1007 as a whole
-
For purposes of Regulation SCI (§§ 242.1000 through 242.1007), the following definitions shall apply:
-
(9) Each competing consolidator that is not required to comply with the requirements of §§ 242.1000 through 242.1007 regarding systems compliance and integrity (Regulation SCI) shall comply with the following:(i) For purposes of this paragraph (d)(9), the following definitions shall apply:Systems disruption means an event in a competing consolidator's systems involved in the collection and consolidation of consolidated market data, and dissemination of consolidated market data products, that disrupts, or significantly degrades, the normal operation of such systems.Systems intrusion means any unauthorized entry into a competing consolidator's systems involved in the collection and consolidation of consolidated market data, and dissemination of consolidated market data products.(A) (1) Establish, maintain, and enforce written policies and procedures reasonably designed to ensure: That its systems involved in the collection and consolidation of consolidated market data, and dissemination of consolidated market data products have levels of capacity, integrity, resiliency, availability, and security adequate to maintain the competing consolidator's operational capability and promote the maintenance of fair and orderly markets; and the prompt, accurate, and reliable dissemination of consolidated market data products.(2) Such policies and procedures shall be deemed to be reasonably designed if they are consistent with current industry standards, which shall be comprised of information technology practices that are widely available to information technology professionals in the financial sector and issued by an authoritative body that is a U.S. governmental entity or agency, association of U.S. governmental entities or agencies, or widely recognized organization. Compliance with such current industry standards, however, shall not be the exclusive means to comply with the requirements of this paragraph (d)(9)(ii)(A);(B) Periodically review the effectiveness of the policies and procedures required by paragraph (d)(9)(ii)(A) of this section, and take prompt action to remedy deficiencies in such policies and procedures; and(C) Establish, maintain, and enforce reasonably designed written policies and procedures that include the criteria for identifying responsible personnel, the designation and documentation of responsible personnel, and escalation procedures to quickly inform responsible personnel of potential systems disruptions and systems intrusions; and periodically review the effectiveness of the policies and procedures, and take prompt action to remedy deficiencies.(A) Upon responsible personnel having a reasonable basis to conclude that a systems disruption or systems intrusion has occurred, begin to take appropriate corrective action which shall include, at a minimum, mitigating potential harm to investors and market integrity resulting from the event and devoting adequate resources to remedy the event as soon as reasonably practicable.(B) Promptly upon responsible personnel having a reasonable basis to conclude that a systems disruption (other than a system disruption that has had, or the competing consolidator reasonably estimates would have, no or a de minimis impact on the competing consolidator's operations or on market participants) has occurred, publicly disseminate information relating to the event (including the system(s) affected and a summary description); when known, promptly publicly disseminate additional information relating to the event (including a detailed description, an assessment of those potentially affected, a description of the progress of corrective action and when the event has been or is expected to be resolved); and until resolved, provide regular updates with respect to such information.(C) Concurrent with public dissemination of information relating to a systems disruption pursuant to paragraph (d)(9)(iii)(B) of this section, or promptly upon responsible personnel having a reasonable basis to conclude that a systems intrusion (other than a system intrusion that has had, or the competing consolidator reasonably estimates would have, no or a de minimis impact on the competing consolidator's operations or on market participants) has occurred, provide the Commission notification and, until resolved, updates of such event. Notifications required pursuant to this paragraph (d)(9)(iii)(C) shall include information relating to the event (including the system(s) affected and a summary description); when known, additional information relating to the event (including a detailed description, an assessment of those potentially affected, a description of the progress of corrective action and when the event has been or is expected to be resolved); and until resolved, regular updates with respect to such information. Notifications relating to systems disruptions and systems intrusions pursuant to this paragraph (d)(9)(iii)(C) shall be submitted to the Commission on Form CC.(iv) Participate in the industry- or sector-wide coordinated testing of business recovery and disaster recovery plans required of SCI entities pursuant to § 242.1004(c).
-
Form SCI shall be used to file notices and reports as required by Regulation SCI (§§ 242.1000 through 242.1007).