FTC GLBA Safeguards Rule (16 CFR Part 314)
FTC Safeguards Rule: Effective Date, Small Institution Exemption and 2024-2025 Pipeline (314.5, 314.6, Coordination)

FTC GLBA Safeguards Rule (16 CFR Part 314) FTC-Safeguards-EffectiveDate-Small-Institution: Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)

16 CFR 314.5 + 314.6. EFFECTIVE DATE (314.5): the FTC Safeguards Rule as amended in 2021 is in effect since 9 January 2022 + with January 2023 for elements requiring additional time (Qualified Individual + risk assessment + the 9 safeguard elements + continuous monitoring/pen test + incident response plan + Board reporting); the 2023 FTC NOTIFICATION REQUIREMENT (314.4(j)) became effective 13 May 2024. SMALL INSTITUTION EXEMPTION (314.6): financial institutions maintaining customer information concerning FEWER THAN 5,000 CONSUMERS qualify for SIMPLIFIED COMPLIANCE - they need not comply with all the detailed requirements but MUST: (a) DEVELOP + maintain a WRITTEN INFORMATION SECURITY PROGRAM addressing the standards of 314.3; (b) DESIGNATE A QUALIFIED INDIVIDUAL; (c) CONDUCT a WRITTEN RISK ASSESSMENT covering the 314.4(b) criteria; (d) DESIGN + IMPLEMENT SAFEGUARDS to control the risks identified; (e) OVERSEE SERVICE PROVIDERS; (f) EVALUATE + ADJUST the program. Small institutions are EXEMPT from 314.4(c)(1)-(9) detailed elements + 314.4(d)(1)(B) periodic assessment of service providers + 314.4(g)(5) annual penetration testing/semiannual vuln assessments + 314.4(h)(1)-(7) detailed IRP elements + 314.4(i) Qualified Individual annual Board reporting; but should still implement reasonable + appropriate safeguards. INTERAGENCY COORDINATION: with federal banking agencies (OCC + FRB + FDIC + NCUA) + SEC + CFPB + state insurance + state AGs + interagency Cyber Risk Self-Assessment Tool (CIRT-Tool). SECTORAL: with HIPAA (for health-related GLBA-covered) + FERPA (Higher Education Safeguards Rule) + CCPA/CPRA + state privacy laws + EU GDPR (where US institution serves EU customers).

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 73 controls across 37 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy

ISO/IEC 29134:2023 · 3 controls

  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-40 Mandatory Minimum Classification of Material Service Providers
  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities
  • BB-DPA-22 Sections 70-75 - Commissioner Functions

ISO/IEC 27014:2020 · 2 controls

  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

India DPDP Act · 1 control

  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

South Korea PIPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in FTC Safeguards Rule: Effective Date, Small Institution Exemption and 2024-2025 Pipeline (314.5, 314.6, Coordination)

Query this from an agent

The graph holds this control, the 73 it maps to, and the evidence behind each claim, over MCP and REST.