FTC-Safeguards-2024-2025-Status | 2024-2025 Implementation Status, FTC Enforcement Actions and Anticipated Amendments | 0 |
FTC-Safeguards-9-Elements | 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) | 209 |
FTC-Safeguards-AI-SBOM-Pipeline | AI Use, SBOM, Supply Chain and 2024-2025 Emerging Areas | 0 |
FTC-Safeguards-Coord-Banking-SEC-Higher-Ed | Coordination with Banking Agencies, SEC, Higher Education Safeguards and Insurance | 0 |
FTC-Safeguards-Crosswalk-NIST-ISO-SOC | Crosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 2 | 0 |
FTC-Safeguards-EffectiveDate-Small-Institution | Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6) | 36 |
FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification | Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) | 142 |
FTC-Safeguards-Program-Qualified-Individual | Comprehensive Information Security Program + Qualified Individual (16 CFR 314.3, 314.4(a)) | 9 |
FTC-Safeguards-Risk-Assessment | Written Risk Assessment (16 CFR 314.4(b)) | 46 |
FTC-Safeguards-Scope-Defs | Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) | 230 |
FTC-Safeguards-ServiceProvider-Evaluation | Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) | 110 |
314.1 | 314.1 Purpose and scope | 0 |
314.2 | 314.2 Definitions | 0 |
314.3(a) | 314.3(a) Comprehensive written information security program | 0 |
314.4(a) | 314.4(a) Qualified Individual | 0 |
314.4(b) | 314.4(b) Risk assessment | 0 |
314.4(b)(1) | 314.4(b)(1) Written risk assessment | 0 |
314.4(b)(2) | 314.4(b)(2) Periodic reassessment of risks | 0 |
314.4(c) | 314.4(c) Safeguards to control the identified risks | 0 |
314.4(c)(1) | 314.4(c)(1) Access controls | 0 |
314.4(c)(2) | 314.4(c)(2) Inventory of data, personnel, devices, systems and facilities | 0 |
314.4(c)(3) | 314.4(c)(3) Encryption in transit and at rest | 0 |
314.4(c)(4) | 314.4(c)(4) Secure development practices | 0 |
314.4(c)(5) | 314.4(c)(5) Multi-factor authentication | 0 |
314.4(c)(6) | 314.4(c)(6) Secure disposal and retention review | 0 |
314.4(c)(7) | 314.4(c)(7) Change management | 0 |
314.4(c)(8) | 314.4(c)(8) Monitoring and logging of authorised users | 0 |
314.4(d) | 314.4(d) Testing and monitoring of safeguards | 0 |
314.4(d)(1) | 314.4(d)(1) Regular testing or monitoring of key controls | 0 |
314.4(d)(2) | 314.4(d)(2) Continuous monitoring or annual penetration testing and six-monthly vulnerability assessment | 0 |
314.4(e) | 314.4(e) Personnel | 0 |
314.4(e)(1) | 314.4(e)(1) Security awareness training | 0 |
314.4(e)(2) | 314.4(e)(2) Qualified information security personnel | 0 |
314.4(e)(3) | 314.4(e)(3) Security updates and training for security personnel | 0 |
314.4(e)(4) | 314.4(e)(4) Current knowledge of threats and countermeasures | 0 |
314.4(f) | 314.4(f) Service provider oversight | 0 |
314.4(f)(1) | 314.4(f)(1) Selection and retention of capable service providers | 0 |
314.4(f)(2) | 314.4(f)(2) Contractual safeguards | 0 |
314.4(f)(3) | 314.4(f)(3) Periodic assessment of service providers | 0 |
314.4(g) | 314.4(g) Evaluation and adjustment of the program | 0 |
314.4(h) | 314.4(h) Written incident response plan | 0 |
314.4(i) | 314.4(i) Annual written report to the board | 0 |
314.4(j) | 314.4(j) Notification of security events to the FTC | 0 |
314.4(j)(1) | 314.4(j)(1) Notice to the FTC within 30 days of a notification event affecting 500 or more consumers | 0 |
314.4(j)(2) | 314.4(j)(2) Discovery rule for notification events | 0 |
314.5 | 314.5 Effective date | 0 |
314.6 | 314.6 Exceptions | 0 |