FTC GLBA Safeguards Rule (16 CFR Part 314)
FTC Safeguards Rule: Written Risk Assessment (314.4(b))

FTC GLBA Safeguards Rule (16 CFR Part 314) FTC-Safeguards-Risk-Assessment: Written Risk Assessment (16 CFR 314.4(b))

16 CFR 314.4(b) risk assessment. REQUIREMENT: financial institution must conduct a WRITTEN RISK ASSESSMENT to identify reasonably foreseeable internal + external risks to the security + confidentiality + integrity of customer information that could result in unauthorized disclosure + misuse + alteration + destruction + or other compromise. RISK ASSESSMENT CONTENTS (314.4(b)(1-4)): (1) CRITERIA for the evaluation + categorization of identified security risks or threats facing the institution; (2) CRITERIA for the assessment of confidentiality + integrity + availability of the institution information systems + customer information including the adequacy of existing controls in the context of identified risks or threats; (3) REQUIREMENTS that the safeguards (the 9 elements at 314.4(c) + 314.4(d-j)) be assessed in light of the risk assessment + adjusted accordingly. FREQUENCY: at least every ANNUAL year + after material changes to operations or services + after security events + after relevant regulatory developments. METHODOLOGY: typically aligned with NIST SP 800-30 + ISO 31000 + COSO ERM + integrated with enterprise risk management.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 91 controls across 47 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 4.3.1 Risk Assessment and Impact Analysis
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

ISO/IEC 27031:2011 · 3 controls

ISO/IEC 29134:2023 · 3 controls

API 1164 · 2 controls

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience

ISO/IEC 27014:2020 · 2 controls

  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • CRM-1 AML/CFT Compliance
  • CRM-4 Business Risk Assessment
  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • ASD37-20 Multi-factor authentication (Essential)

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

COBIT 2019 · 1 control

  • CAT-D5-4 Resilience planning and testing

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

India DPDP Act · 1 control

  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

South Korea PIPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 91 it maps to, and the evidence behind each claim, over MCP and REST.