FTC GLBA Safeguards Rule (16 CFR Part 314)
FTC Safeguards Rule: 9 Safeguard Elements - Access, Encryption, MFA, Disposal, Change, Monitoring, Pen Test (314.4(c))

FTC GLBA Safeguards Rule (16 CFR Part 314) FTC-Safeguards-9-Elements: 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))

16 CFR 314.4(c)(1-9) the 9 SPECIFIC SAFEGUARD ELEMENTS (added by 2021 amendments). (1) ACCESS CONTROLS - place access controls + limit access to authorized users + role-based + least-privilege + periodic review + revoke access promptly upon termination/role change; (2) DATA INVENTORY AND CLASSIFICATION - identify + manage data + personnel + devices + systems + facilities that enable the institution to achieve its purposes in accordance with their relative importance to business objectives + risk strategy; (3) ENCRYPTION of customer information held or transmitted by the institution both at REST and in TRANSIT over external networks - if encryption is infeasible + the Qualified Individual may approve compensating controls in writing; (4) SECURE DEVELOPMENT PRACTICES for in-house developed applications used to transmit + access + store customer information; (5) MULTI-FACTOR AUTHENTICATION (MFA) for any individual accessing any information system that contains customer information - except where the Qualified Individual approves alternative compensating controls equivalent or more secure than MFA; (6) SECURE DISPOSAL of customer information no later than 2 YEARS after the last date the information is used in connection with the provision of a product or service to the customer except where information is reasonably necessary for business or legal purposes or where targeted disposal is not reasonably feasible; (7) CHANGE MANAGEMENT PROCEDURES with documented procedures for changes to information systems; (8) MONITORING AND LOGGING of the activity of authorized users + detecting unauthorized access or use of, or tampering with, customer information by such users; (9) CONTINUOUS MONITORING OR ANNUAL PENETRATION TESTING + SEMIANNUAL VULNERABILITY ASSESSMENTS (or annual penetration testing with quarterly vulnerability assessments per the institution risk + complexity).

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.