This policy communicates the principles for ensuring risks to Information Resources and Information Assets are managed in alignment with business goals and in accordance with legal and regulatory requirements and professional standards.
What is the Corporate Information Security Policy?
This is how long a Human Account password is valid for.
What is 1 year?
This document defines the capabilities necessary to manage information technology and information risk.
What is the IT Policy?
This solution is used to monitor, log, and control the transfer of data by Personnel both externally and internally at specific egress points of CME Group infrastructure.
What is the Data Loss Prevention (DLP) program.
This is the centralised software platform that helps CME Group manage governance, risk, and compliance (GRC).
What is Archer GRC?
This policy defines the Capabilities the CME Group organisation will develop and maintain in order to effectively manage its information technology and information risks.
What is the IT Policy?
Must contain at least 3 of 4 of the following types of characters:
Upper case letters (A-Z)
Lower case letters (a-z)
Base 10 Numbers (0-9)
Special characters, selected from the following character set:
~!@#$%^&*_-+=`|\(){}[]:;"'<>,.?/
These documents provide details regarding how the policy-defined capabilities are expected to operate.
What are Functional Standards?
This is information available to the general public and/or created with the intention for broad distribution outside the company. This information may be freely disseminated inside and outside the company.
What is Public data classification?
This team provide an independent and objective review of CME Group’s risks and controls.
What is the Global Assurance (GA) team?
This policy outlines the requirements for the use of mobile devices, in order to maintain good security practices and comply with legal and regulatory requirements.
What is the Mobile Device User Responsibility policy?
This is how long an intruder lockout duration is set to for a Human Account.
What is 20 minutes?
These documents are prescribed technical means and methods supporting Functional Standards or approved architectures.
What are Technical Standards?
You would report unauthorised access, whether intentional or unintentional, of Personal Data or CME Group Information to this team.
What is the Cyber Defense Monitoring team?
This is a strategic framework that outlines how an organisation delivers value to customers through its products.
What is the Product operating Model?
This policy is designed to ensure legal, responsible, and appropriate use of artificial intelligence systems, including generative artificial intelligence technology.
What is the Artificial Intelligence policy?
This type of account password must contain at least 12 characters.
What are Human Accounts?
These documents describe a series of work tasks to be followed and associated roles.
What are Process documents?
This policy outlines the requirements of the disposal of CME Group Information in accordance with requirements (including retention periods).
What is the Records and Information Management policy?
This is a set of processes that are implemented and include requirements related to planning, designing, development, testing, and overall considerations for the life cycle of Information Systems.
What is the System Development Life Cycle (SDLC)?
This policy builds on our corporate value of leading with conviction and integrity by setting the tone for a culture of compliance, ethical conduct and accountability, and providing greater detail about the behavior we expect from our colleagues.
What is the Code of Conduct?
This type of account password must contain at least 20 characters.
What are Non-Human accounts?
The documents provide detailed, prescriptive, instructions on how to carry out certain tasks.
What are Procedure documents?
According to CME Group, this is the definition of an office location that presents heightened physical, compliance or information security risks.
What is High Risk Office Location (HROL)?
This is how access to CME Group Information should be granted and maintained with the intent of providing only the minimum level of access required.
What is the Principle of Least Privilege?