US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
Applicability to Title IV Institutions

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule HE-3: FSA compliance requirements

Federal Student Aid requires institutions to comply with the amended Safeguards Rule as programme participation condition.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 77 controls across 64 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

MTCS (Singapore) · 2 controls

  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance

SASB Standards · 2 controls

Bahrain PDPL · 1 control

FedRAMP High · 1 control

  • AC-2 Account Management

FedRAMP Moderate · 1 control

  • AC-2 Account Management
  • UAE-PDPL-Status UAE PDPL status, executive regulations, UAE Data Office guidance evolution

IEEE 7000 · 1 control

ISMAP (Japan) · 1 control

ISO 14001 · 1 control

  • ISO14001-03 Legal and regulatory compliance obligations

ISO 22000 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 45001 · 1 control

ISSB Standards · 1 control

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

Malaysia PDPA 2010 · 1 control

Mauritius DPA · 1 control

Mexico LFPDPPP · 1 control

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-145 · 1 control

  • NISTSP145-1 On-Demand Self-Service and Broad Network Access Characteristics

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NIST190-04 Regulatory compliance for cloud services
  • AC-2 Account Management
  • AC-2 Account Management
  • AC-2 Account Management
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties
  • NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs
  • NZISM-2 Certification and Accreditation (C&A) for Government Systems
  • NGNDPR-8 Annual Data Protection Audit, Penalties, and NDPA Transition

OECD AI Principles · 1 control

  • OECDAI-8 AI Incident Reporting, Regulatory Compliance, Public Reporting, and International Cooperation
  • OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring

PDPA Singapore · 1 control

  • PDPASG-7 Retention Limitation, Do Not Call, Compliance, Complaints

PDPA Thailand · 1 control

  • PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training

POPIA · 1 control

  • POPIASA-8 Information Regulator Cooperation, Complaints, Enforcement
  • NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training

Saudi Arabia PDPL · 1 control

South Korea PIPA · 1 control

  • TCFDREC-1 Governance - Board Oversight, Management Role

Taiwan PDPA · 1 control

Turkey KVKK · 1 control

  • UKAI-2 Sector-Specific Regulator Engagement

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Vietnam PDPD · 1 control

Virginia CDPA · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Applicability to Title IV Institutions

Query this from an agent

The graph holds this control, the 77 it maps to, and the evidence behind each claim, over MCP and REST.