Security

Maintaining a Safe, Secure Marketplace

MIC Clearing House LTD ensures the physical and digital security of its markets, clearing houses, and data through industry-leading security technology and processes. MIC’s Information Security Department consists of diverse and skilled teams that work to protect confidential data from unauthorized access, misuse, disclosure, destruction, modification or disruption.

Policies

MIC Clearing House LTD maintains detailed information security policies. Employees are required to complete security awareness training upon hire and annually thereafter. The security awareness training modules require employees to read and provide acknowledgement of the corporate information security policy. The policies are for official use only and are reviewed at least quarterly by MIC Senior Management.

Application Security

MIC employs a dedicated Application Security team which defines and enforces mandatory best-practice secure software development.  The Application Security team maintains a policy which details these practices and works closely with MIC Development teams.

Incident Management

MIC Operations maintains an Incident Management program to handle any incident with operational impact — security or otherwise. It is MIC policy to notify customers of any confirmed material breaches of customer data.

Business Continuity Planning / Disaster Recovery

Geographically-diverse “like for like” Disaster Recovery datacenters are maintained and governed by an enterprise wide policy. Per policy, all MIC core procedures, systems and operational tasks are: duplicable in recovery facilities, exercised at least annually, documented in comprehensive Disaster Recovery (DR), Business Continuity (BCP) and Incident Response Plans, and ensure infrastructure is recoverable.

Testing and Audit

MIC Internal Audit and Information Security Assurance regularly conducts tests utilizing various methods to verify compliance with written polices and to assess vulnerabilities. In addition, MIC teams support examinations from multiple regulatory bodies, and commission independent penetration tests.

A rigorous Service Organization Control (SOC) audit is performed annually to produce independent verification and testing of MIC controls for external parties and auditors that rely on MIC. The scope of this report is evaluated each year and tailored in response to customer feedback and business developments.

Inquiries into Information Security Program

Due to the number of requests received from regulators, members, customers of subsidiaries, and other stakeholders, MIC does not respond to individual inquiries or questionnaires from customers regarding the security of MIC systems. Further, to protect the security and integrity of MIC environments, it is company policy that we do not share information related to internal policies and procedures with third parties.

For questions about this procedure please contact the MIC via your account representative.