US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
Monitoring

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule USGLBAHIGHER-3: Continuous Monitoring, Testing, Vendor Oversight

Per 314.4(d) + (f): continuous monitoring and testing + service provider oversight + program evaluation and adjustment.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 192 controls across 129 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • FTC-Safeguards-EffectiveDate-Small-Institution Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)
  • FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
  • FTC-Safeguards-Risk-Assessment Written Risk Assessment (16 CFR 314.4(b))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO/IEC 29134:2023 · 4 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure
  • 29134-9.2 Report findings and recommendations
  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight

FISMA · 3 controls

  • FISMA-3554-Agency-Responsibilities Federal Agency Responsibilities (44 USC 3554) - CIO + CISO + Program + Reporting
  • FISMA-CIRCIA-ZTA-EO14028 CIRCIA, Zero Trust Architecture, EO 14028 + 14110 + OMB Memoranda
  • FISMA-NIST-800-53-RMF-800-171-FIPS Operationalisation via NIST 800-53 + 800-37 RMF + 800-171 + FIPS 199 + FIPS 200

IEEE 1686 · 3 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel
  • IEEE1686-Section5.2-5.3-AuditLog-Retention-Export-Monitoring IEEE 1686 Section 5.2 + 5.3 - Audit Trail Records + Retention + Export + Supervisory Monitoring and Control + Network Security Monitoring

ISO/IEC 29147:2018 · 3 controls

  • 29147-5.11 Researcher Safe Harbour and Legal Posture
  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring

MTCS (Singapore) · 3 controls

  • MTCS-Acquisition-Development-Maintenance-Supplier-Vulnerability-DevSecOps-SBOM-SDLC-SCA-API-Container MTCS Acquisition + Development + Maintenance + Supplier + Vulnerability + DevSecOps + SBOM + SDLC + SCA
  • MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles
  • MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM

NIST SP 800-144 · 3 controls

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation
  • NISTSP144-7 Cloud Workload Protection, Containers, Serverless, and Configuration
  • NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance

NIST SP 800-30 · 3 controls

  • NISTSP30-3 Threat Source and Threat Event Identification
  • NISTSP30-4 Vulnerability and Predisposing Condition Identification
  • NISTSP30-6 Risk Determination, Uncertainty, and Sensitivity Analysis
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security

FedRAMP Rev 5 · 2 controls

  • FedRAMP-Boundary Authorization Boundary, SSP, SAR, POA&M documentation
  • FedRAMP-ConMon Continuous Monitoring (ConMon) and Significant Change Requests
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.25_26_27_28_29 UAE Data Office establishment, powers, penalties, complaints (UAE PDPL Articles 25-29)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Enforcement-AG-CurePeriod Enforcement by Florida Department of Legal Affairs + Penalties + 45-Day Cure (Fla. Stat. 501.72, 501.721, 501.722)
  • Sapin2-Pillar3-Risk-Mapping Pillar 3 - Corruption Risk Mapping (Cartographie des Risques)
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • GhCSA-CII-Designation-Plan-Audit-Risk CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment
  • GhCSA-Implementation-Roadmap Implementation Roadmap - Organizational Roles, Tooling and Metrics
  • HKMA-CRAF-Domain1-2-Governance-Identification HKMA C-RAF Domain 1 (Governance) + Domain 2 (Identification) - Cyber Strategy, Risk Management, Asset Management, Threat Assessment
  • HKMA-CRAF-Domain3-4-Protection-Detection HKMA C-RAF Domain 3 (Protection) + Domain 4 (Detection) - Access, Data, Infrastructure, Application, Monitoring, Testing, Threat Intel
  • IATF16949-Clause6-Planning-Risk-Contingency-Objectives-Change IATF 16949 Clause 6 - Planning + Risks and Opportunities + Contingency Plans + Quality Objectives + Change
  • IATF16949-Clause8-Operation-APQP-Design-Production-ControlPlan-SpecialChars IATF 16949 Clause 8 - Operation Planning + APQP + Design + Special Characteristics + Production + Control Plan + Set-Up Verification
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain
  • IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation
  • IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA
  • IRM-Process-Identification-Analysis-Evaluation-Treatment-Monitoring-Review-ISO31000-Aligned IRM Risk Management Process - 5-Stage Cycle + Identification + Analysis (Inherent/Residual) + Evaluation + Treatment (4Ts Tolerate/Treat/Transfer/Terminate) + Monitoring + Review + Communication + Risk Register
  • IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe

ISMAP (Japan) · 2 controls

  • 27557-4.3 Individual impact consideration
  • 27557-6.3 Privacy risk assessment
  • JP-FSA-CYB-Cybersecurity-Exercises-Drills-Annual-Tabletop-Industry-Wide-Exercise-Delta-Wall-FSA-Coordinated-Sector Japan FSA Cybersecurity Exercises + Drills + Annual Tabletop + Industry-Wide Exercise + Delta Wall + FSA Coordinated Sector-Wide + FISC Drills + Cross-Sector Crisis Coordination + International Exercises + Cyber Range
  • JP-FSA-CYB-Security-Monitoring-SOC-Operations-SIEM-EDR-MDR-XDR-24x7-Detection-Alert-Triage Japan FSA Cybersecurity Security Monitoring + SOC 24x7 Operations + SIEM + EDR + MDR + XDR + Detection + Alert Triage + Threat Hunting + Incident Response Integration + Threat Intelligence Integration + UEBA
  • LLOYDS-CI-Risk-Selection-Cyber-Hygiene-Underwriting-Criteria-Pre-Bind-Risk-Engineering-MFA-Backup-EDR Lloyds Cyber Insurance Risk Selection + Hygiene + Pre-Bind Engineering
  • LLOYDS-CI-Systemic-Cyber-Risk-Aggregation-Cyber-Catastrophe-Modelling-Vendor-Use-RDS-Scenario-Testing Lloyds Cyber Insurance Systemic Aggregation + Catastrophe Modelling + RDS
  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-37 · 2 controls

  • NISTSP37-2 RMF Categorize Step: Information and System Categorisation
  • NISTSP37-3 RMF Select Step: Security and Privacy Control Selection
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NISTSP82-6 OT Audit, Monitoring, Anomaly Detection, and OT-Specific SOC
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-5 Information Gathering, Logging, Monitoring, and Incident Response
  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework
  • ORSA-S2 Guidance Manual Section 2: Insurer's assessment of risk exposures
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan
  • CISABD-2 Embrace Radical Transparency and Accountability
  • CISABD-3 Build Organizational Structure and Leadership for Secure Outcomes
  • TSAPIPE-1 Cybersecurity Implementation Plan and Coordinator
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKOPRES-3 Self-Assessment and Board Engagement
  • UKOPRES-4 Incident Management, Lessons Learned, Comms
  • LOPDP-EC-Governance-DPO-ROPA-DPIA-Privacy-by-Design-Training-Articles-46-58-Compliance-Monitoring Ecuador LOPDP Governance + DPO + ROPA + DPIA + Privacy by Design + Training
  • R.16-VATR.Unhosted Unhosted (self-hosted / non-custodial) wallet transfers - 2024 Targeted Update

FDA 21 CFR Part 11 · 1 control

  • Part11.CSV Computer system validation + risk-based approach (21 CFR §11.10(a) + 2003 FDA Scope and Application Guidance + 2023 CSA draft)
  • FSSC-Additional-Requirements-v6 FSSC 22000 Additional Requirements v6 (Food Defense + Food Fraud + Allergen + Environmental + Culture)
  • FERPA-Safeguards-PTAC Data Security Safeguards for PII in Education Records (PTAC Best Practices, SPPO Guidance)
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • IACS-UR-E26-Identify-Plan-Risk-Survey-Documentation IACS UR E26 Identify Goal - Ship Cyber Resilience Plan + CBS Risk Assessment + Survey + Documentation

IEEE 7000 · 1 control

  • IEEE7000-EthicalRisk-Identification-Analysis-Treatment-ValidationOutcomes IEEE 7000 Clauses 8 + 8.1 + 8.2 - Ethical Risk Identification + Analysis + Treatment + Validation of Ethical Outcomes + AI Safety + Robustness + Adversarial Protection
  • 27006-9.4 Surveillance and recertification

ISO/IEC 27011:2024 · 1 control

  • 27011-8.5 Vulnerability and malware management

ISO/IEC 27031:2011 · 1 control

  • 27031-7.2 Resource Requirements

ISO/IEC 27400:2022 · 1 control

  • 27400-6.5 Security monitoring and incident response

India DPDP Act · 1 control

  • INCDPA-SensitiveData-Children-Consent-COPPA-DataProtectionAssessment-DPIA Indiana CDPA Sensitive Data + Consent for Sensitive Categories + Children Under 13 + COPPA Coordination + Data Protection Assessment (DPA) + High-Risk Processing

Indonesia PDP Law · 1 control

Japan AI Guidelines · 1 control

  • JP-AIG-Scope-METI-MIC-AI-Guidelines-Business-v1.0-April2024-Society-5.0-Cabinet-Office-AI-Strategy-Council Japan AI Guidelines Scope + METI/MIC AI Guidelines for Business v1.0 (April 2024) + Society 5.0 + Cabinet Office AI Strategy Council + 10 Principles 2019 Heritage + Education + Literacy + Fair Competition + Innovation Principles

LGPD · 1 control

  • LGPD-BR-Governance-Encarregado-DPO-ROPA-DPIA-Privacy-by-Design-Article-46-50-Codes-of-Conduct Brazil LGPD Governance + Encarregado (DPO) + ROPA + DPIA + Articles 46-50
  • DOM172-Supervisory-Authority-Cooperation-Sanctions-Penalties-Articles-77-79-Awareness-Training-Retention-DPO-Designation Dominican Republic Law 172-13 Supervisory Authority + Sanctions + Articles 77-79 + DPO + Awareness

Liechtenstein DPA · 1 control

MARS-E · 1 control

  • MDS2-Audit-Logging-AUDT-Integrity-IGAU-Cybersecurity-Risk-CYBR-Monitoring MDS2 Audit Controls + AUDT + Integrity + IGAU + Cybersecurity Risk + CYBR + Continuous Monitoring

MITRE ATT&CK · 1 control

MITRE D3FEND · 1 control

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-DPO-Designation-Class-Data-User-Registration-DPIA-Code-Practice-Section-43A-2024-Amendment Malaysia PDPA Governance + DPO Section 43A + Class of Data User Registration + DPIA + Code of Practice

Mauritius DPA · 1 control

  • MU-DPA-Cross-Border-Transfer-Section-36-Adequacy-SCC-BCR-Mauritius-Global-Business-IBC-Financial-Services Mauritius DPA Cross-Border + Section 36 + Adequacy + SCC + BCR + Mauritius Global Business + Financial Services

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Cross-Border-Transfer-Articles-36-37-Reglamento-66-68-Domestic-International-APEC-CBPR-USMCA Mexico LFPDPPP Cross-Border + Articles 36-37 + Reglamento 66 + 68 + Domestic + International + APEC CBPR + USMCA
  • MN-CDPA-Data-Privacy-Assessment-DPIA-Section-325O-07-Sensitive-Targeted-Sale-Profiling-AI-Consumer-Health Minnesota CDPA DPIA + Section 325O.07 + Sensitive + Targeted + Sale + Profiling + AI + Consumer Health
  • MT-CDPA-Data-Protection-Assessment-MCA-30-14-2815-Sensitive-Targeted-Sale-Profiling-AG-Inspection Montana CDPA Data Protection Assessment + MCA 30-14-2815 + Sensitive + Targeted + Sale + Profiling + AG Inspection
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTSP115-3 Target Identification and Analysis - Network Discovery, Port and Service ID, Vuln Scanning

NIST SP 800-122 · 1 control

  • NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance

NIST SP 800-123 · 1 control

  • NISTSP123-5 Server Operations - Patching, Malware, Logging, Backup

NIST SP 800-137 · 1 control

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring

NIST SP 800-39 · 1 control

  • NISTSP39-3 Risk Assessing: Organisation, Mission, and System Level Assessments
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-8 Operational Audit, Session Management, Recovery, and Cross-cutting Controls

NIST SP 800-66 · 1 control

  • NISTSP66-1 Security Management Process: Risk Analysis and Risk Management for ePHI

NIST SP 800-88 · 1 control

  • NISTSP88-7 Verification, Audit, Training, and Environmental/Safety Controls

NIST SP 800-92 · 1 control

  • NISTSP92-5 Log Analysis: Correlation, Baselining, Anomaly Detection, Alerting, Manual Review
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model
  • NHPA-7 Data Protection Assessments and Processor Contracts
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture

OECD AI Principles · 1 control

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection

OWASP ASVS · 1 control

OWASP MASVS · 1 control

  • OWASPMASVS-6 MASVS-CODE: Code Quality, Build Settings, and Updates

OWASP SAMM · 1 control

  • OWASPSAMM-4 Verification: Architecture Assessment, Requirements-Driven Testing, Security Testing
  • OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification

OpenSSF Scorecard · 1 control

  • OSSFSC-2 Dependency Management, Pinning, Updates, Vulnerability Tracking
  • OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices
  • PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning

PDPA Singapore · 1 control

  • PDPASG-4 Children's Data, DPIA, and Privacy by Design

PDPA Thailand · 1 control

  • PDPATH-4 DPIA, Privacy by Design, Children's Data

POPIA · 1 control

  • POPIASA-4 Special Personal Information, Children, Information Quality, Documentation

PTES · 1 control

  • PTESPHASE-4 Vulnerability Analysis
  • NORWAY-4 DPIA, Privacy by Design, Records of Processing
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children

Privacy Act 2020 · 1 control

  • NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design

Qatar DPL · 1 control

  • QATAR-7 DPO, Records, Retention, Marketing, Training
  • SAEIGHT-1 Child Labour and Young Worker Protection
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule

South Korea PIPA · 1 control

  • PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33
  • TEFCAREC-1 Common Agreement Conformance and Onboarding

Taiwan PDPA · 1 control

  • TAIWAN-3 Data Subject Rights
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice

Turkey KVKK · 1 control

  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles
  • UKGDPRREG-3 Controller and Processor (Articles 24-43)
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • UNESCOAI-1 Principles 1-3: Proportionality, Safety, Fairness
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity

Uruguay DPL · 1 control

  • URUGUAY-5 Database Registration with AGESIC URCDP

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 192 it maps to, and the evidence behind each claim, over MCP and REST.