Cohasset Associates Report

MinIO Object Storage: SEC 17a-4(f), FINRA 4511(c) and CFTC 1.31(c)-(d) Compliance Assessment

Download PDF

The Benefit from Cohasset’s Industry Insight and Experience

Core to Cohasset’s practice is its delivery of records management and information governance professional consulting services, education and training. Cohasset’s expert consulting services are tailored to support a multitude of regulated organizations, including those in the financial services industry. Cohasset serves both domestic and multi-national clients, aligning information lifecycle controls with their organizations’ business priorities and facilitating regulatory compliance and risk mitigation, all the while generating measurable business efficiencies.

Cohasset has assessed the spectrum of storage technologies and systems designed to meet the requirements of the Securities and Exchange Commission Rule 17a-4(f), as defined by 1) the No Action Letter in 1993 (allowing broker dealers to use non- rewriteable, non-erasable digital storage media); 2) the issuance of the Rule in 1997; and 3) the Interpretive Release in 2003, which authorizes the use of erasable storage, conditioned on integrated control codes, to prevent premature deletion of records.

Abstract

MinIO Object Storage is an open-source, software-defined, high performance object storage system that is designed for private cloud environments. It runs on industry standard hardware. The Object Lock features are designed to meet securities industry requirements for preserving records in a non-rewriteable, non-erasable format, for objects stored with the Object Lock mode set Compliance.

In this Report, Cohasset Associates, Inc. (Cohasset) assesses the capabilities of MinIO Object Storage (see Section 1.3, MinIO Object Storage Overview and Assessment Scope) relative to:

  • The recording and non-rewriteable, non-erasable storage requirements for electronic records, as specified by:
    • Securities and Exchange Commission (SEC) in 17 CFR § 240.17a- 4(f), which regulates exchange members, brokers or dealers.
    • Financial Industry Regulatory Authority (FINRA) Rule 4511(c), which defers to the format and media requirements of SEC Rule 17a-4(f).
  • The principles-based electronic records requirements of the Commodity Futures Trading Commission (CFTC) in 17 CFR § 1.31(c)- (d), which regulates commodity futures trading.

It is Cohasset’s opinion that MinIO Object Storage, Release 172, when properly configured and when Object Lock mode is set to Compliance, retains records requiring time-based retention, in compliance with the recording and non-rewriteable, non-erasable storage of electronic records of SEC Rule 17a-4(f) and FINRA Rule 4511(c). Additionally, the assessed capabilities of MinIO Object Storage meet the principles-based requirements of CFTC Rule 1.31(c)-(d).

1 2 3 4 5 6 7

You are using Internet Explorer version 11 or lower. Due to security issues and lack of support for web standards, it is highly recommended that you upgrade to a modern browser.