FTC GLBA Safeguards Rule (16 CFR Part 314)
FTC Safeguards Rule: 9 Safeguard Elements - Access, Encryption, MFA, Disposal, Change, Monitoring, Pen Test (314.4(c))

FTC GLBA Safeguards Rule (16 CFR Part 314) FTC-Safeguards-9-Elements: 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

16 CFR 314.4(c)(1-9) the 9 SPECIFIC SAFEGUARD ELEMENTS (added by 2021 amendments). (1) ACCESS CONTROLS - place access controls + limit access to authorized users + role-based + least-privilege + periodic review + revoke access promptly upon termination/role change; (2) DATA INVENTORY AND CLASSIFICATION - identify + manage data + personnel + devices + systems + facilities that enable the institution to achieve its purposes in accordance with their relative importance to business objectives + risk strategy; (3) ENCRYPTION of customer information held or transmitted by the institution both at REST and in TRANSIT over external networks - if encryption is infeasible + the Qualified Individual may approve compensating controls in writing; (4) SECURE DEVELOPMENT PRACTICES for in-house developed applications used to transmit + access + store customer information; (5) MULTI-FACTOR AUTHENTICATION (MFA) for any individual accessing any information system that contains customer information - except where the Qualified Individual approves alternative compensating controls equivalent or more secure than MFA; (6) SECURE DISPOSAL of customer information no later than 2 YEARS after the last date the information is used in connection with the provision of a product or service to the customer except where information is reasonably necessary for business or legal purposes or where targeted disposal is not reasonably feasible; (7) CHANGE MANAGEMENT PROCEDURES with documented procedures for changes to information systems; (8) MONITORING AND LOGGING of the activity of authorized users + detecting unauthorized access or use of, or tampering with, customer information by such users; (9) CONTINUOUS MONITORING OR ANNUAL PENETRATION TESTING + SEMIANNUAL VULNERABILITY ASSESSMENTS (or annual penetration testing with quarterly vulnerability assessments per the institution risk + complexity).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 700 controls across 210 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 12 controls

ISO 13485 · 9 controls

ISO 27043 · 9 controls

ISO 27799 · 9 controls

ISO/SAE 21434 · 9 controls

BSI IT-Grundschutz · 8 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • BSI-24 Configuration change control
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • CH-FADP-13 Right to object and request blocking
  • CH-FADP-15 Cooperation with the FDPIC
  • CH-FADP-18 Sector specific rules
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

ISO 27018 · 7 controls

ISO/IEC 27011:2024 · 7 controls

ISO 27017 · 6 controls

MARS-E · 6 controls

NIST SP 800-190 · 6 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections
  • NDPA-6 Reasonable Security Practices and Incident Response
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles
  • NG-NDPA-4 Data Subject Rights and Automated Decision-Making
  • NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

Bahrain PDPL · 5 controls

ISO/IEC 27400:2022 · 5 controls

NIST SP 800-144 · 5 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-3 Data Classification, Handling, and Sovereignty
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access
  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration
  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

OWASP ASVS · 5 controls

OWASP Top 10:2025 · 5 controls

  • OWASPTOP10-1 A01:2025 Broken Access Control
  • OWASPTOP10-2 A02:2025 Cryptographic Failures and Secret Management
  • OWASPTOP10-4 A04:2025 Insecure Design and Business Logic (incl. A11 API Abuse)
  • OWASPTOP10-7 A07:2025 Identification and Authentication Failures
  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures

Saudi Arabia PDPL · 5 controls

South Korea ISMS-P · 5 controls

API 1164 · 4 controls

  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)
  • ASD37-27 Outbound data loss prevention (Very Good)

IEC 62443 · 4 controls

ISO 27019 · 4 controls

India DPDP Act · 4 controls

Indonesia PDP Law · 4 controls

MDS2 (Medical Device) · 4 controls

MITRE ATT&CK · 4 controls

MTCS (Singapore) · 4 controls

Mauritius DPA · 4 controls

Mexico LFPDPPP · 4 controls

  • PQC-2 FIPS 203 ML-KEM Implementation - Module-Lattice Key-Encapsulation Mechanism
  • PQC-5 Cryptographic Inventory and PQC Migration Roadmap
  • PQC-7 FIPS Validated Modules, HSM Readiness, and Algorithm Validation
  • PQC-8 Implementation Requirements - RNG, Side-Channel, Key Management, Operations, Incident Response
  • NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 1800-32 · 4 controls

  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-5 OT Configuration Management, Patching, Vulnerability Management, and Malware Protection
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NJDPA-6 Reasonable Data Security and Incident Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-7 Logging, Monitoring, Incident Response, and Denial-of-Service Resilience
  • ORANWG11-8 Supply Chain, Secure Development Lifecycle, Privacy, Multi-Vendor Trust

OWASP MASVS · 4 controls

  • OREGONCPA-4 Universal Opt-Out, Targeted Advertising, Profiling
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

APPI · 3 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A31 Provision of Personally Referable Information
  • APPI-A34 Request for Correction, Addition or Deletion
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority

GDPR · 3 controls

  • 62351-14 Cyber security event logging
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management

ISMAP (Japan) · 3 controls

ISO 19011 · 3 controls

  • 6.5 Preparing and Distributing Audit Report
  • 6.7 Conducting Audit Follow-up
  • ISO19011-18 Innovation and change management

ISO/IEC 27010:2015 · 3 controls

Malaysia PDPA 2010 · 3 controls

  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.PS-06 Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle

NIST SP 800-123 · 3 controls

  • NISTSP123-3 Authentication, Access Control, and Account Management
  • NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates
  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 3 controls

  • NISTSP137-4 Security Status Reporting and Risk Score Aggregation
  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring
  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-145 · 3 controls

  • NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management
  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 3 controls

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • NISTSP146-6 Cloud Security and Privacy Recommendations
  • NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability

NIST SP 800-61 · 3 controls

  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence
  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 3 controls

  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators
  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers
  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-66 · 3 controls

  • NISTSP66-2 Workforce Security, Information Access Management, and Awareness Training
  • NISTSP66-5 Physical Safeguards: Facility Access, Workstation Use and Security, Device and Media Controls
  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 3 controls

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework
  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase
  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 3 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NHPA-6 Reasonable Data Security and Breach Response
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • OWASPAPI-1 Broken Object Level Authorization (BOLA) and BFLA
  • OWASPAPI-2 Broken Authentication and Token Management
  • OWASPAPI-6 Security Misconfiguration and Secure API Design
  • DSOMM-2 Implementation Practices, Secure Coding, and Threat Modelling
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

OpenSSF Scorecard · 3 controls

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • OSSFSC-7 Webhook Authentication, Contributors Diversity, Aggregate Score

PDPA Singapore · 3 controls

  • PDPASG-1 Accountability, Records, DPO Appointment, and Training
  • PDPASG-4 Children's Data, DPIA, and Privacy by Design
  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 3 controls

  • PDPATH-4 DPIA, Privacy by Design, Children's Data
  • PDPATH-5 Security Measures and Data Protection
  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 3 controls

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation
  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • POPIASA-7 Information Officer, Records of Processing, Notification, Training
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Peru DPL · 3 controls

  • PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions
  • PERU-4 Children's Data, Privacy Impact, Sensitive Categories
  • PERU-7 DPO, Records, Retention, Marketing, Training
  • AUPRV-1 APP 1 Open and Transparent Management + Privacy Management Framework
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 3 controls

  • NZPRV-2 IPP 5 Storage and Security of Personal Information
  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design
  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training
  • SSAE18-CC3.4 CC3.4 - COSO Principle 9: Change Management
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-CC8.1 CC8.1 - Infrastructure and Software Change Management
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • SBD-DEV-05 Secure Software Development Framework
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection
  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-4 Section 4 - Principles Relating to Processing
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

IEEE 1686 · 2 controls

ISO 20000-1 · 2 controls

ITIL 4 · 2 controls

LGPD · 2 controls

Liechtenstein DPA · 2 controls

MITRE D3FEND · 2 controls

  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security
  • NIS2I-6 Access Control, Asset Management, and Physical Security
  • NISTSP115-2 Review Techniques - Documentation, Logs, Rulesets, Configurations
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 2 controls

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit
  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OWASPLLM-1 Prompt Injection and System Prompt Leakage (LLM01 + LLM07)
  • OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02)
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment

PCI P2PE · 2 controls

PCI PIN Security · 2 controls

PCI SSF · 2 controls

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 2 controls

  • PAKPDPB-6 Cross-Border Transfer and Data Localization
  • PAKPDPB-7 NCPDP, Registration, Records, Processor Contracts, DPO
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • PSPF24-4 Physical Security

Qatar DPL · 2 controls

  • QATAR-5 Security of Processing
  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • RUSPD-2 Lawful Basis, Consent, Notice
  • RUSPD-4 Special Categories, Biometric Data

SASB Standards · 2 controls

  • SASB-1 Business Model + Innovation (BMI)
  • SASB-BMI-5 Physical Impacts of Climate Change

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

SOC 2 · 2 controls

  • SOC2-CC6.3 Role-based access and least privilege are enforced
  • SOC2-CC8.1 Change management processes are in place

Turkey KVKK · 2 controls

Vietnam PDPD · 2 controls

  • PMF-SP.3 Security Testing and Monitoring

FIDO2 / WebAuthn · 1 control

GHG Protocol · 1 control

GLBA · 1 control

HITECH Act · 1 control

HKMA SPM · 1 control

IEEE 7000 · 1 control

ISO 26000:2010 · 1 control

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO 30401 · 1 control

ISO 37001 · 1 control

ISO 37301 · 1 control

ISO 55001 · 1 control

ISO 9001 · 1 control

  • ISO9001-18 Cl. 6.3 Planning of changes - innovation and change management for the quality management system

ISO/IEC 23894:2023 · 1 control

Japan AI Guidelines · 1 control

  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTSP34-3 Preventive Controls and Recovery Strategies: Backup, Alternate Sites, Equipment
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGOB-3 API Security Standards, mTLS, and Encryption

OECD AI Principles · 1 control

  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working
  • PICSGMP-4 Chapter 4: Documentation - System, Record-Keeping, Data Integrity
  • PARAGUAY-5 Security of Processing, Data Integrity, Information Security
  • RCEPEC-1 Online Personal Information Protection (12.13)

SWIFT CSCF · 1 control

  • STUDPRV-2 Data Subject Rights for Students and Parents
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • W3CVCDM-4 Accessibility, Internationalization, Security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 700 it maps to, and the evidence behind each claim, over MCP and REST.