Federal Register/Vol. 85, No. 201/Friday, October 16, 2020/Notices
Total Page:16
File Type:pdf, Size:1020Kb
65990 Federal Register / Vol. 85, No. 201 / Friday, October 16, 2020 / Notices SECURITIES AND EXCHANGE the inclusion in the comment file of any 6. Programmatic Access—Authorization for COMMISSION such materials will be made available Programmatic CAIS Access and on the Commission’s website. To ensure Programmatic CCID Subsystem [Release No. 34–89632; File No. S7–10–20] direct electronic receipt of such 7. Programmatic CAIS Access 8. Programmatic CCID Subsystem Access RIN 3235–AM62 notifications, sign up through the ‘‘Stay G. Participants’ Data Confidentiality Connected’’ option at www.sec.gov to Policies Proposed Amendments to the National receive notifications by email. 1. Data Confidentiality Policies Market System Plan Governing the FOR FURTHER INFORMATION CONTACT: 2. Access to CAT Data and Information Consolidated Audit Trail To Enhance Barriers Data Security Erika Berg, Special Counsel, at (202) 3. Additional Policies Relating to Access 551–5925, Jennifer Colihan, Special and Use of CAT Data and Customer and AGENCY: Securities and Exchange Counsel, at (202) 551–5642, Rebekah Account Attributes Commission. Liu, Special Counsel, at (202) 551–5665, 4. Approval, Publication, Review and ACTION: Proposed amendments to Susan Poklemba, Special Counsel, at Annual Examinations of Compliance national market system plan. (202) 551–3360, Andrew Sherman, H. Regulator & Plan Processor Access Special Counsel, at (202) 551–7255, Gita 1. Regulatory Use of CAT Data SUMMARY: The Securities and Exchange Subramaniam, Attorney Advisor, at 2. Access to CAT Data Commission is proposing amendments I. Secure Connectivity & Data Storage (202) 551–5793, or Eugene Lee, Attorney J. Breach Management Policies and to the national market system plan Advisor, at (202) 551–5884, Division of governing the consolidated audit trail. Procedures Trading and Markets, Securities and K. Firm Designated ID and Allocation The proposed amendments are designed Exchange Commission, 100 F Street NE, Reports to enhance the security of the Washington, DC 20549–7010. L. Appendix C of the CAT NMS Plan consolidated audit trail. M. Proposed Implementation SUPPLEMENTARY INFORMATION: The DATES: Comments should be received on 1. Proposed 90-Day Implementation Period Commission is proposing amendments or before November 30, 2020. 2. Proposed 120-Day Implementation to the CAT NMS Plan. Period ADDRESSES: Comments may be TABLE OF CONTENTS 3. Proposed 180-Day Implementation submitted by any of the following Period methods: I. Background N. Application of the Proposed Electronic Comments II. Description of Proposed Amendments Amendments to Commission Staff A. Comprehensive Information Security III. Paperwork Reduction Act • Use the Commission’s internet Program A. Summary of Collections of Information comment form (http://www.sec.gov/ B. Security Working Group 1. Evaluation of the CISP rules/proposed.shtml); or C. Secure Analytical Workspaces 2. Security Working Group • Send an email to rule-comments@ 1. Provision of SAW Accounts 3. SAWs sec.gov. Please include File No. S7–10– 2. Data Access and Extraction Policies and 4. Online Targeted Query Tool and Logging 20 on the subject line. Procedures of Access and Extraction 3. Security Controls, Policies, and 5. CAT Customer and Account Attributes Paper Comments Procedures for SAWs 6. Customer Identifying Systems Workflow • 4. Implementation and Operational 7. Proposed Confidentiality Policies, Send paper comments to Secretary, Requirements for SAWs Procedures and Usage Restrictions Securities and Exchange Commission, 5. Exceptions to the SAW Usage 8. Secure Connectivity—‘‘Allow Listing’’ 100 F Street NE, Washington, DC Requirements 9. Breach Management Policies and 20549–1090. D. Online Targeted Query Tool and Procedures All submissions should refer to File No. Logging of Access and Extraction 10. Customer Information for Allocation S7–10–20. This file number should be E. CAT Customer and Account Attributes Report Firm Designated IDs included on the subject line if email is 1. Adopt Revised Industry Member B. Proposed Use of Information used. To help us process and review Reporting Requirements 1. Evaluation of the CISP 2. Establish a Process for Creating 2. Security Working Group your comments more efficiently, please Customer-ID(s) in Light of Revised 3. SAWs use only one method. The Commission Reporting Requirements 4. Online Targeted Query Tool and Logging will post all comments on the 3. Plan Processor Functionality To Support of Access and Extraction Commission’s internet website (http:// the Creation of Customer-ID(s) 5. CAT Customer and Account Attributes www.sec.gov/rules/proposed.shtml). 4. Reporting Transformed Value 6. Customer Identifying Systems Workflow Comments are also available for website 5. Data Availability Requirements 7. Proposed Confidentiality Policies, viewing and printing in the 6. Customer and Account Attributes in Procedures and Usage Restrictions Commission’s Public Reference Room, CAIS and Transformed Values 8. Secure Connectivity—‘‘Allow Listing’’ 100 F Street NE, Washington, DC 20549 7. Customer-ID Tracking 9. Breach Management Policies and 8. Error Resolution for Customer Data Procedures on official business days between the 9. CAT Reporter Support and CAT Help 10. Customer Information for Allocation hours of 10:00 a.m. and 3:00 p.m. All Desk Report Firm Designated IDs comments received will be posted F. Customer Identifying Systems Workflow C. Respondents without change. Persons submitting 1. Application of Existing Plan 1. National Securities Exchanges and comments are cautioned that the Requirements to Customer and Account National Securities Associations Commission does not redact or edit Attributes and the Customer Identifying 2. Members of National Securities personal identifying information from Systems Exchanges and National Securities comment submissions. You should 2. Defining the Customer Identifying Association submit only information that you wish Systems Workflow and the General D. Total Initial and Annual Reporting and Requirements for Accessing Customer Recordkeeping Burdens to make available publicly. Identifying Systems 1. Evaluation of the CISP Studies, memoranda, or other 3. Introduction to Manual and 2. Security Working Group substantive items may be added by the Programmatic Access 3. SAWs Commission or staff to the comment file 4. Manual CAIS Access 4. Online Targeted Query Tool and Logging during this rulemaking. A notification of 5. Manual CCID Subsystem Access of Access and Extraction VerDate Sep<11>2014 20:55 Oct 15, 2020 Jkt 253001 PO 00000 Frm 00002 Fmt 4701 Sfmt 4703 E:\FR\FM\16OCN2.SGM 16OCN2 jbell on DSKJLSW7X2PROD with NOTICES2 Federal Register / Vol. 85, No. 201 / Friday, October 16, 2020 / Notices 65991 5. CAT Customer and Account Attributes submit to the Commission a national this directive, the CAT NMS Plan 6. Customer Identifying Systems Workflow market system plan to create, requires the Plan Processor to develop 7. Proposed Confidentiality Policies, implement, and maintain a consolidated and maintain an information security Procedures and Usage Restrictions audit trail (the ‘‘CAT’’).2 The goal of program for the Central Repository. The 8. Secure Connectivity—‘‘Allow Listing’’ 9. Breach Management Policies and Rule 613 was to create a modernized Plan Processor must have appropriate Procedures audit trail system that would provide solutions and controls in place to 10. Customer Information for Allocation regulators with more timely access to a address data confidentiality and Report Firm Designated IDs sufficiently comprehensive set of security during all communication E. Collection of Information is Mandatory trading data, thus enabling regulators to between CAT Reporters,7 Data F. Confidentiality of Responses to more efficiently and effectively Submitters,8 and the Plan Processor; Collection of Information reconstruct market events, monitor data extraction, manipulation, and G. Retention Period for Recordkeeping market behavior, and investigate transformation; data loading to and from Requirements misconduct. On November 15, 2016, the the Central Repository; and data H. Request for Comments maintenance by the CAT System.9 The IV. Economic Analysis Commission approved the national A. Analysis of Baseline, Costs and Benefits market system plan required by Rule CAT NMS Plan also sets forth minimum 1. CISP 613 (the ‘‘CAT NMS Plan’’).3 data security requirements for CAT that 2. Security Working Group The security and confidentiality of the Plan Processor must meet, including 3. Secure Analytical Workspaces CAT Data 4 has been—and continues to requirements governing connectivity 4. OTQT and Logging be—a top priority of the Commission. and data transfer, data encryption, data 5. CAT Customer and Account Attributes The CAT NMS Plan approved by the storage, data access, breach 6. Customer Identifying Systems Workflow Commission already sets forth a number management, data requirements for 7. Participants’ Data Confidentiality personally identifiable information Policies of requirements regarding the security 10 and confidentiality of CAT Data. The (‘‘PII’’), and applicable data security 8. Regulator & Plan Processor Access industry standards.11 CAT Data reported 9. Secure Connectivity CAT NMS Plan states, for example, that to and retained in the Central 10. Breach Management Policies and the Plan Processor 5 shall be responsible Procedures for the security and confidentiality of all Repository is thus subject to what the Commission believes are stringent 11. Firm Designated