Policies
Identity and Access Management (IAM)
IT Compliance Documents
Data Protection
Lucky Dip
100

This policy communicates the principles for ensuring risks to Information Resources and Information Assets are managed in alignment with business goals and in accordance with legal and regulatory requirements and professional standards.

What is the Corporate Information Security Policy?

100

This is how long a Human Account password is valid for.

What is 1 year?

100

This document defines the capabilities necessary to manage information technology and information risk.

What is the IT Policy?

100

This solution is used to monitor, log, and control the transfer of data by Personnel both externally and internally at specific egress points of CME Group infrastructure.

What is the Data Loss Prevention (DLP) program.

100

This is the centralised software platform that helps CME Group manage governance, risk, and compliance (GRC).

What is Archer GRC?

200

This policy defines the Capabilities the CME Group organisation will develop and maintain in order to effectively manage its information technology and information risks.

What is the IT Policy?

200

Must contain at least 3 of 4 of the following types of characters:

  • Upper case letters (A-Z)

  • Lower case letters (a-z)

  • Base 10 Numbers (0-9)

  • Special characters, selected from the following character set:
    ~!@#$%^&*_-+=`|\(){}[]:;"'<>,.?/

What is the password configuration of a Human Account?
200

These documents provide details regarding how the policy-defined capabilities are expected to operate.

What are Functional Standards?

200

This is information available to the general public and/or created with the intention for broad distribution outside the company. This information may be freely disseminated inside and outside the company. 

What is Public data classification?

200

This team provide an independent and objective review of CME Group’s risks and controls. 

What is the Global Assurance (GA) team?

300

This policy outlines the requirements for the use of mobile devices, in order to maintain good security practices and comply with legal and regulatory requirements.

What is the Mobile Device User Responsibility policy?

300

This is how long an intruder lockout duration is set to for a Human Account.

What is 20 minutes?

300

These documents are prescribed technical means and methods supporting Functional Standards or approved architectures.

What are Technical Standards?

300

You would report unauthorised access, whether intentional or unintentional, of Personal Data or CME Group Information to this team.

What is the Cyber Defense Monitoring team?

300

This is a strategic framework that outlines how an organisation delivers value to customers through its products. 

What is the Product operating Model?

400

This policy is designed to ensure legal, responsible, and appropriate use of artificial intelligence systems, including generative artificial intelligence technology.

What is the Artificial Intelligence policy?

400

This type of account password must contain at least 12 characters.

What are Human Accounts?

400

These documents describe a series of work tasks to be followed and associated roles.

What are Process documents?

400

This policy outlines the requirements of the disposal of CME Group Information in accordance with requirements (including retention periods).

What is the Records and Information Management policy?

400

This is a set of processes that are implemented and include requirements related to planning, designing, development, testing, and overall considerations for the life cycle of Information Systems.

What is the System Development Life Cycle (SDLC)?

500

This policy builds on our corporate value of leading with conviction and integrity by setting the tone for a culture of compliance, ethical conduct and accountability, and providing greater detail about the behavior we expect from our colleagues.

What is the Code of Conduct?

500

This type of account password must contain at least 20 characters.

What are Non-Human accounts?

500

The documents provide detailed, prescriptive, instructions on how to carry out certain tasks.

What are Procedure documents?

500

According to CME Group, this is the definition of an office location that presents heightened physical, compliance or information security risks.

What is High Risk Office Location (HROL)?

500

This is how access to CME Group Information should be granted and maintained with the intent of providing only the minimum level of access required.

What is the Principle of Least Privilege?