United States (FTC-jurisdiction financial institutions)

FTC GLBA Safeguards Rule (16 CFR Part 314)

47 controls. 298 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

47 controls 298 frameworks share controls with it United States (FTC-jurisdiction financial institutions) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
FTC-Safeguards-2024-2025-Status2024-2025 Implementation Status, FTC Enforcement Actions and Anticipated Amendments0
FTC-Safeguards-9-Elements9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))209
FTC-Safeguards-AI-SBOM-PipelineAI Use, SBOM, Supply Chain and 2024-2025 Emerging Areas0
FTC-Safeguards-Coord-Banking-SEC-Higher-EdCoordination with Banking Agencies, SEC, Higher Education Safeguards and Insurance0
FTC-Safeguards-Crosswalk-NIST-ISO-SOCCrosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 20
FTC-Safeguards-EffectiveDate-Small-InstitutionEffective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)36
FTC-Safeguards-IR-Plan-BoardReporting-FTC-NotificationWritten Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))142
FTC-Safeguards-Program-Qualified-IndividualComprehensive Information Security Program + Qualified Individual (16 CFR 314.3, 314.4(a))9
FTC-Safeguards-Risk-AssessmentWritten Risk Assessment (16 CFR 314.4(b))46
FTC-Safeguards-Scope-DefsScope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)230
FTC-Safeguards-ServiceProvider-EvaluationService Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))110
314.1314.1 Purpose and scope0
314.2314.2 Definitions0
314.3(a)314.3(a) Comprehensive written information security program0
314.4(a)314.4(a) Qualified Individual0
314.4(b)314.4(b) Risk assessment0
314.4(b)(1)314.4(b)(1) Written risk assessment0
314.4(b)(2)314.4(b)(2) Periodic reassessment of risks0
314.4(c)314.4(c) Safeguards to control the identified risks0
314.4(c)(1)314.4(c)(1) Access controls0
314.4(c)(2)314.4(c)(2) Inventory of data, personnel, devices, systems and facilities0
314.4(c)(3)314.4(c)(3) Encryption in transit and at rest0
314.4(c)(4)314.4(c)(4) Secure development practices0
314.4(c)(5)314.4(c)(5) Multi-factor authentication0
314.4(c)(6)314.4(c)(6) Secure disposal and retention review0
314.4(c)(7)314.4(c)(7) Change management0
314.4(c)(8)314.4(c)(8) Monitoring and logging of authorised users0
314.4(d)314.4(d) Testing and monitoring of safeguards0
314.4(d)(1)314.4(d)(1) Regular testing or monitoring of key controls0
314.4(d)(2)314.4(d)(2) Continuous monitoring or annual penetration testing and six-monthly vulnerability assessment0
314.4(e)314.4(e) Personnel0
314.4(e)(1)314.4(e)(1) Security awareness training0
314.4(e)(2)314.4(e)(2) Qualified information security personnel0
314.4(e)(3)314.4(e)(3) Security updates and training for security personnel0
314.4(e)(4)314.4(e)(4) Current knowledge of threats and countermeasures0
314.4(f)314.4(f) Service provider oversight0
314.4(f)(1)314.4(f)(1) Selection and retention of capable service providers0
314.4(f)(2)314.4(f)(2) Contractual safeguards0
314.4(f)(3)314.4(f)(3) Periodic assessment of service providers0
314.4(g)314.4(g) Evaluation and adjustment of the program0
314.4(h)314.4(h) Written incident response plan0
314.4(i)314.4(i) Annual written report to the board0
314.4(j)314.4(j) Notification of security events to the FTC0
314.4(j)(1)314.4(j)(1) Notice to the FTC within 30 days of a notification event affecting 500 or more consumers0
314.4(j)(2)314.4(j)(2) Discovery rule for notification events0
314.5314.5 Effective date0
314.6314.6 Exceptions0

Tell me when FTC GLBA Safeguards Rule (16 CFR Part 314) files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Multi-framework reporting + crosswalks
  • Multi-framework alignment + crosswalk
  • Multi-framework crosswalk + compliance
  • Cross-border supervisory engagement
  • Voluntary standards adoption
  • ESRS + ISSB + GRI aligned disclosures
  • Annual review records
  • Asset prioritization scoring model
  • Criticality ratings stored in CMDB
  • Resource allocation justification per tier

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for FTC GLBA Safeguards Rule (16 CFR Part 314), drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition