US Accountability Body Criticizes SEC Infosec Approach

In its findings summary, the GAO said that the SEC did not adequately protect its system boundaries from intrusion, and failed to consistently authenticate users, monitor network activity, implement proper authorization procedures for sensitive data and restrict access at physical locations. Damningly, the GAO also found that the SEC did not properly segregate its development and production environments, with accounts for the former live on the latter's servers. The GAO also noted that despite the SEC had put a disaster recovery and contingency plan in place, this did not include a critical system.
"[The] SEC continues to make progress in improving information security controls over its key financial systems," the GAO report summarizes. "However, information security control weaknesses in a key financial system's production environment may jeopardize the confidentiality, integrity, and availability of information residing in and processed by the system. These included deficiencies in [the] SEC's controls over access control, configuration management, segregation of duties, and contingency and disaster recovery planning. In addition, [the] SEC did not consistently provide adequate contractor oversight and implement an effective risk management process during the migration of an important financial system to its new location."
The report recommends that the SEC increases its oversight of contractors, and institute a proper risk management program. A separate document, which was not widely distributed, makes 49 specific suggestions.
In its comments, the SEC acknowledged issues with the oversight of contractors and the wider criticisms made in the report, but said that once weaknesses were identified with server configurations, they were immediately rectified.
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: https://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Trading Tech
Etrading wins UK bond tape, R3 debuts new lab, TNS buys Radianz, and more
The Waters Cooler: The Swiss release an LLM, overnight trading strays further from reach, and the private markets frenzy continues in this week’s news roundup.
Fintech powering LSEG’s AI Alerts dissolves
ModuleQ, a partner and investment of Refinitiv and then LSEG since 2018, was dissolved last week after it ran out of funding.
Halftime review: How top banks and asset managers are tackling projects beyond AI
Waters Wrap: Anthony highlights eight projects that aren’t centered around AI at some of the largest banks and asset managers.
Speakerbus goes bust, Broadridge buys Signal, banks mandate cyber training, and more
The Waters Cooler: The Federal Reserve is reserved on GenAI, FloQast partners with Deloitte Australia, UBS invests in Domino Data Lab, and more in this week’s roundup.
Speakerbus ceases operations amid financial turmoil
Sources say customers were recently notified that the trader voice vendor was preparing to file for administration and would no longer be operational.
SS&C withdraws SEC application for clearing exemption
The fintech had been granted exemption in 2015 for SSCNet, a global trade network, that allowed it to provide matching and ETC services.
Standard Chartered CDO on AI, CAT on life support, Paxos files for clearing status, and more
The Waters Cooler: FIX updates MMT, a Finnish datacenter hangs in the balance, and partnerships galore in this week’s news roundup.
CAT on life support after appeals court ruling
Ahead of a comprehensive review promised by the SEC, lawyers believe that the recent overturn of the Consolidated Audit Trail’s funding order could herald its demise.