Back to Frameworks
United States
v2023
7 domains
12 controls

The Gramm-Leach-Bliley Act (GLBA, also known as the Financial Services Modernization Act of 1999, Public Law 106-102) is a US federal statute enacted 12 November 1999 that imposes privacy + safeguarding + anti-pretexting obligations on FINANCIAL INSTITUTIONS handling nonpublic personal information (NPI). KEY PROVISIONS: (a) SUBCHAPTER I - DISCLOSURE OF NONPUBLIC PERSONAL INFORMATION (15 USC 6801-6809): policy of privacy obligation + safeguarding standard (Sec. 6801); notice + opt-out obligations on disclosure to nonaffiliated third parties (Sec. 6802); annual privacy notice obligation (Sec. 6803); rulemaking authority delegated to Bureau of Consumer Financial Protection (CFPB) + Securities and Exchange Commission (SEC) + Commodity Futures Trading Commission (CFTC) (Sec. 6804); enforcement by federal banking agencies (OCC + Federal Reserve + FDIC + NCUA + OTS) + SEC + CFTC + FTC + State insurance authorities (Sec. 6805); state insurance preemption (Sec. 6806); relation to other Acts (Sec. 6807); study of information sharing (Sec. 6808); definitions (Sec. 6809). (b) SUBCHAPTER II - FRAUDULENT ACCESS TO FINANCIAL INFORMATION (15 USC 6821-6827): PRETEXTING prohibition (Sec. 6821) - obtaining customer information by false pretenses + including phone + internet + impersonation prohibited; administrative enforcement by FTC + federal banking agencies (Sec. 6822); criminal penalties up to 5 years imprisonment or 10 years if aggravated (Sec. 6823); relation to other laws (Sec. 6824); agency guidance (Sec. 6825); reports (Sec. 6826); definitions (Sec. 6827). OPERATIONALISATION: GLBA establishes the statutory umbrella; substantive operational controls are issued by regulators via subordinate rules: (a) FTC Safeguards Rule 16 CFR Part 314 (last major revision 2021 + 2023 breach-notification amendment effective 2024 + further 2024-2025 amendments - verified separately); (b) FTC Privacy Rule 16 CFR Part 313 + model privacy form; (c) SEC Regulation S-P (17 CFR Part 248) - amended March 2024 + effective 2025-2026 with incident-response + breach-notification + 30-day individual notification + supervisory + record-keeping requirements; (d) BANKING-AGENCY RULES (Interagency Guidelines Establishing Standards for Safeguarding Customer Information + Interagency Guidance on Response Programs for Unauthorized Access to Customer Information + Customer Notice) issued by OCC + Federal Reserve + FDIC + NCUA + OTS - see 12 CFR Part 30 + Part 208 + Part 364 + Part 748; (e) NAIC Insurance Data Security Model Law (NAIC #668) adopted by 20+ states; (f) CFPB enforcement under Dodd-Frank for non-bank financial institutions; (g) HIGHER EDUCATION institutions participating in Title IV (FSA - Federal Student Aid) are FTC Safeguards Rule covered + tracked separately as a sectoral application. 2024-2025 PIPELINE: SEC Reg S-P amendments effective 2025-12-03 large + 2026-06-03 small institutions; FTC Safeguards 2024 30-day FTC notification rule effective; CFPB Section 1033 Open Banking Rule (October 2024) imposes additional safeguarding obligations on screen-scrapers; NAIC Model Bulletin on AI 2023; state privacy laws (CCPA + state DP laws) coordinate. ENGAGEMENT: GLBA is the statutory umbrella - cross-mapping to substantive controls + auditor evidence should target the subordinate FTC Safeguards Rule + FTC Privacy Rule + SEC Reg S-P + banking-agency rule frameworks.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

GLBA: 2024-2025 Pipeline, Coordination and Cross-Mapping to Subordinate Substantive Rules

4 controls
Controls in the GLBA: 2024-2025 Pipeline, Coordination and Cross-Mapping to Subordinate Substantive Rules domain of GLBA4 controls
CodeTitle
GLBA-2024-2025-Pipeline-Section-1033-AIGLBA 2024-2025 Pipeline - SEC Reg S-P, CFPB Section 1033, NAIC AI Bulletin
GLBA-Coordination-FCRA-HIPAA-CCPA-SectoralGLBA Coordination with FCRA, ECOA, HIPAA, CCPA, State Privacy Laws and Sectoral Frameworks
GLBA-Crosswalk-Subordinate-Substantive-RulesGLBA Crosswalk to FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P, Interagency Guidelines, NAIC Model Law
GLBA-Status-FTC-CFPB-SEC-NAIC-EnforcementGLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions

GLBA: Operationalisation through FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P

2 controls
Controls in the GLBA: Operationalisation through FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P domain of GLBA2 controls
CodeTitle
GLBA-Implementation-Roadmap-ExaminationGLBA Implementation Roadmap, Examination Readiness, Roles and Tooling
GLBA-Subordinate-Rules-OperationalisationGLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines

GLBA: Rulemaking Authority - CFPB, SEC, CFTC, Federal Banking Agencies, FTC, NAIC

1 controls
Controls in the GLBA: Rulemaking Authority - CFPB, SEC, CFTC, Federal Banking Agencies, FTC, NAIC domain of GLBA1 controls
CodeTitle
GLBA-Sec6804-6805-Rulemaking-EnforcementGLBA Section 6804-6805 - Rulemaking Authority and Enforcement Mechanism

GLBA: Sectoral Application - Banking, Securities, Insurance, Non-Bank, Higher Education

1 controls
Controls in the GLBA: Sectoral Application - Banking, Securities, Insurance, Non-Bank, Higher Education domain of GLBA1 controls
CodeTitle
GLBA-Sectoral-Higher-Ed-Insurance-BankingGLBA Sectoral Application: Banking, Securities, Insurance, Non-Bank, Higher Education

GLBA: Statutory Scope, Definitions and Coverage of Financial Institutions

1 controls
Controls in the GLBA: Statutory Scope, Definitions and Coverage of Financial Institutions domain of GLBA1 controls
CodeTitle
GLBA-Scope-FinancialInstitution-NPI-DefsGLBA Scope, Financial Institution + Nonpublic Personal Information Definitions

GLBA: Subchapter I (15 USC 6801-6809) Privacy and Safeguarding Obligations

2 controls
Controls in the GLBA: Subchapter I (15 USC 6801-6809) Privacy and Safeguarding Obligations domain of GLBA2 controls
CodeTitle
GLBA-Sec6801-PolicyDuty-SafeguardingStandardGLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard
GLBA-Sec6802-6803-Disclosure-Notice-OptOutGLBA Section 6802-6803 - Disclosure Limits, Privacy Notice and Opt-Out

GLBA: Subchapter II (15 USC 6821-6827) Pretexting Prohibition and Criminal Penalties

1 controls
Controls in the GLBA: Subchapter II (15 USC 6821-6827) Pretexting Prohibition and Criminal Penalties domain of GLBA1 controls
CodeTitle
GLBA-Sec6821-Pretexting-Prohibition-CriminalGLBA Section 6821 + 6823 - Pretexting Prohibition and Criminal Penalties

Your Compliance Coverage

If you comply with GLBA, you already cover:

Maps to 153 other frameworks

12 total controls
HKMA Cyber Resilience Assessment Framework (C-RAF)
4 source controls mapped|3 target controls covered
33%
APRA CPS 234
4 source controls mapped|16 target controls covered
33%
AWS Well-Architected Security Pillar
4 source controls mapped|7 target controls covered
33%
Annex 11 to EU GMP - Computerised Systems
4 source controls mapped|6 target controls covered
33%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
4 source controls mapped|12 target controls covered
33%
Protective Security Policy Framework (PSPF) Release 2024
4 source controls mapped|4 target controls covered
33%
OWASP DevSecOps Maturity Model (DSOMM)
4 source controls mapped|7 target controls covered
33%
FFIEC IT Examination Handbook
4 source controls mapped|15 target controls covered
33%
FTC GLBA Safeguards Rule (16 CFR Part 314)
4 source controls mapped|3 target controls covered
33%
NIST AI Risk Management Framework (AI RMF 1.0)
4 source controls mapped|4 target controls covered
33%
ISO/IEC 27400:2022
4 source controls mapped|7 target controls covered
33%
ASIS SPC.1-2009 - Organizational Resilience Standard
4 source controls mapped|5 target controls covered
33%
OWASP Top 10:2025
4 source controls mapped|4 target controls covered
33%
Azure Security Benchmark
4 source controls mapped|7 target controls covered
33%
Regulation (EU) 2019/1239 on the Maritime Single Window (MSW)
4 source controls mapped|2 target controls covered
33%
Ley Orgánica de Protección de Datos Personales (LOPDP)
3 source controls mapped|1 target controls covered
25%
Law No. 172-13 on the Protection of Personal Data
3 source controls mapped|1 target controls covered
25%
India DPDP Act
3 source controls mapped|3 target controls covered
25%
India CERT-In Cyber Security Directions 2022
3 source controls mapped|3 target controls covered
25%
ASD Strategies to Mitigate Cyber Security Incidents
3 source controls mapped|14 target controls covered
25%
Bahrain PDPL
3 source controls mapped|4 target controls covered
25%
25%
APRA CPS 230 Operational Risk Management
3 source controls mapped|7 target controls covered
25%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
3 source controls mapped|7 target controls covered
25%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
3 source controls mapped|3 target controls covered
25%
API 1164
3 source controls mapped|7 target controls covered
25%
Privacy Act 1988 (Australia)
3 source controls mapped|4 target controls covered
25%
Spain ENS
3 source controls mapped|7 target controls covered
25%
FFIEC Cybersecurity Assessment Tool (CAT)
3 source controls mapped|6 target controls covered
25%
ISO/IEC 27010:2015
3 source controls mapped|4 target controls covered
25%
APPI
3 source controls mapped|4 target controls covered
25%
BSI IT-Grundschutz
3 source controls mapped|7 target controls covered
25%
Switzerland FADP
3 source controls mapped|4 target controls covered
25%
Canada ITSG-33 - IT Security Risk Management
3 source controls mapped|1 target controls covered
25%
25%
Rwanda Law No. 058/2021 Relating to the Protection of Personal Data
3 source controls mapped|3 target controls covered
25%
Serbia Law on Personal Data Protection (2018)
3 source controls mapped|3 target controls covered
25%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
3 source controls mapped|4 target controls covered
25%
ISO/IEC 30111:2019
3 source controls mapped|4 target controls covered
25%
Pakistan Personal Data Protection Bill 2023
3 source controls mapped|3 target controls covered
25%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
3 source controls mapped|2 target controls covered
25%
TEFCA - Trusted Exchange Framework and Common Agreement
3 source controls mapped|2 target controls covered
25%
Barbados Data Protection Act 2019
3 source controls mapped|2 target controls covered
25%
ISO/IEC 29147:2018
3 source controls mapped|3 target controls covered
25%
ISO/IEC 27031:2011
2 source controls mapped|8 target controls covered
17%
NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205)
2 source controls mapped|2 target controls covered
17%
MITRE D3FEND
2 source controls mapped|4 target controls covered
17%
ICH E6(R3) - Good Clinical Practice
2 source controls mapped|1 target controls covered
17%
ISO/IEC 38500:2024 - Governance of IT
2 source controls mapped|5 target controls covered
17%
OWASP ASVS
2 source controls mapped|7 target controls covered
17%
IEC 60601-1 - Medical Electrical Equipment Safety
2 source controls mapped|4 target controls covered
17%
ISO/IEC 27011:2024
2 source controls mapped|7 target controls covered
17%
IEC 62351 - Power Systems Communication Security
2 source controls mapped|4 target controls covered
17%
ISO 19011
2 source controls mapped|4 target controls covered
17%
17%
ISO 31000:2018
2 source controls mapped|2 target controls covered
17%
TNFD Recommendations
2 source controls mapped|4 target controls covered
17%
AASB S2 Climate-related Disclosures
2 source controls mapped|4 target controls covered
17%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|6 target controls covered
17%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|8 target controls covered
17%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
2 source controls mapped|3 target controls covered
17%
ISO 20000-1
2 source controls mapped|3 target controls covered
17%
COBIT 2019
2 source controls mapped|2 target controls covered
17%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
2 source controls mapped|6 target controls covered
17%
ISO/IEC 27007:2020
2 source controls mapped|2 target controls covered
17%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|3 target controls covered
17%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
2 source controls mapped|2 target controls covered
17%
Nevada Gaming Control Board Cybersecurity Requirements
2 source controls mapped|1 target controls covered
17%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
2 source controls mapped|2 target controls covered
17%
Singapore Cybersecurity Act 2018
2 source controls mapped|1 target controls covered
17%
NIST SP 800-171
2 source controls mapped|1 target controls covered
17%
COSO Internal Control - Integrated Framework (2013)
2 source controls mapped|1 target controls covered
17%
HL7 FHIR Security Framework
1 source controls mapped|1 target controls covered
8%
Global Cross-Border Privacy Rules (Global CBPR) Forum
1 source controls mapped|1 target controls covered
8%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
8%
Telecommunications Sector Security Reforms (TSSR)
1 source controls mapped|1 target controls covered
8%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
1 source controls mapped|1 target controls covered
8%
Aged Care Quality Standards (Australia)
1 source controls mapped|1 target controls covered
8%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|1 target controls covered
8%
South Korea Cloud Security Assurance Program (CSAP)
1 source controls mapped|1 target controls covered
8%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|3 target controls covered
8%
FBI CJIS Security Policy
1 source controls mapped|4 target controls covered
8%
ISO 27005
1 source controls mapped|1 target controls covered
8%
AS9100D - Aerospace Quality Management System
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27003:2017
1 source controls mapped|1 target controls covered
8%
OWASP API Security Top 10 - 2023
1 source controls mapped|1 target controls covered
8%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
8%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
8%
FIDO2 / WebAuthn
1 source controls mapped|1 target controls covered
8%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
1 source controls mapped|1 target controls covered
8%
Singapore Model AI Governance Framework (2nd Edition)
1 source controls mapped|1 target controls covered
8%
India Account Aggregator Framework (RBI)
1 source controls mapped|1 target controls covered
8%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
8%
ISO/IEC 29134:2023
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27014:2020
1 source controls mapped|3 target controls covered
8%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
8%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|3 target controls covered
8%
SWIFT CSCF
1 source controls mapped|2 target controls covered
8%
SWIFT CSCF v2024
1 source controls mapped|3 target controls covered
8%
Science Based Targets initiative (SBTi) Corporate Standard
1 source controls mapped|2 target controls covered
8%
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
1 source controls mapped|1 target controls covered
8%
Wisconsin Data Privacy Act (SB 670)
1 source controls mapped|1 target controls covered
8%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
8%
Saudi PDPL
1 source controls mapped|1 target controls covered
8%
21 CFR Part 58 - Good Laboratory Practice (GLP)
1 source controls mapped|2 target controls covered
8%
Regulation on the European Health Data Space (EHDS)
1 source controls mapped|1 target controls covered
8%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
8%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|1 target controls covered
8%
ISO 13485
1 source controls mapped|1 target controls covered
8%
ISO 13485:2016
1 source controls mapped|1 target controls covered
8%
ISO 9001:2015
1 source controls mapped|2 target controls covered
8%
Illinois Biometric Information Privacy Act (BIPA)
1 source controls mapped|3 target controls covered
8%
ISO 14001
1 source controls mapped|1 target controls covered
8%
ISO 45001:2018
1 source controls mapped|1 target controls covered
8%
Portugal Law No. 58/2019 - Data Protection Implementation Act
1 source controls mapped|3 target controls covered
8%
Romania Law No. 190/2018 on Data Protection Measures (GDPR Implementation)
1 source controls mapped|3 target controls covered
8%
Uruguay Personal Data Protection Act (Law No. 18.331)
1 source controls mapped|3 target controls covered
8%
South Korea Credit Information Act
1 source controls mapped|1 target controls covered
8%
8%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
8%
Paraguay Law on Protection of Personal Data (Law No. 6534/2020)
1 source controls mapped|1 target controls covered
8%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
1 source controls mapped|1 target controls covered
8%
Spain Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD)
1 source controls mapped|1 target controls covered
8%
Turkey Personal Data Protection Law (KVKK - Law No. 6698)
1 source controls mapped|1 target controls covered
8%
Uzbekistan Law on Personal Data (No. ZRU-547)
1 source controls mapped|1 target controls covered
8%
Panama Law on Personal Data Protection (Law No. 81 of 2019)
1 source controls mapped|1 target controls covered
8%
Oman Personal Data Protection Law (Royal Decree 6/2022)
1 source controls mapped|1 target controls covered
8%
Qatar Personal Data Privacy Protection Law (Law No. 13 of 2016)
1 source controls mapped|1 target controls covered
8%
UNCITRAL Model Law on Electronic Commerce (1996, updated 2005)
1 source controls mapped|1 target controls covered
8%
Florida Digital Bill of Rights (FDBR)
1 source controls mapped|1 target controls covered
8%
Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
1 source controls mapped|1 target controls covered
8%
RBI Cybersecurity Framework for Banks
1 source controls mapped|1 target controls covered
8%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|3 target controls covered
8%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
8%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
8%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
8%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
8%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
8%
FedRAMP High
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
8%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
8%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
8%
Union Customs Code (UCC) - Regulation (EU) No 952/2013
1 source controls mapped|1 target controls covered
8%
ISO/IEC 27050 - Electronic Discovery (Parts 1-4)
1 source controls mapped|1 target controls covered
8%

Frequently Asked Questions

What is GLBA?

GLBA is a compliance framework from United States with 7 domains and 12 controls. The Gramm-Leach-Bliley Act (GLBA, also known as the Financial Services Modernization Act of 1999, Public Law 106-102) is a US federal statute enacted 12 November 1999 that imposes privacy + safeguarding + anti-pretexting obligations on FINANCIAL INSTITUTIONS handling nonpublic personal information (NPI). KEY PROVISIONS: (a) SUBCHAPTER I - DISCLOSURE OF NONPUBLIC PERSONAL INFORMATION (15 USC 6801-6809): policy of privacy obligation + safeguarding standard (Sec. 6801); notice + opt-out obligations on disclosure to nonaffiliated third parties (Sec. 6802); annual privacy notice obligation (Sec. 6803); rulemaking authority delegated to Bureau of Consumer Financial Protection (CFPB) + Securities and Exchange Commission (SEC) + Commodity Futures Trading Commission (CFTC) (Sec. 6804); enforcement by federal banking agencies (OCC + Federal Reserve + FDIC + NCUA + OTS) + SEC + CFTC + FTC + State insurance authorities (Sec. 6805); state insurance preemption (Sec. 6806); relation to other Acts (Sec. 6807); study of information sharing (Sec. 6808); definitions (Sec. 6809). (b) SUBCHAPTER II - FRAUDULENT ACCESS TO FINANCIAL INFORMATION (15 USC 6821-6827): PRETEXTING prohibition (Sec. 6821) - obtaining customer information by false pretenses + including phone + internet + impersonation prohibited; administrative enforcement by FTC + federal banking agencies (Sec. 6822); criminal penalties up to 5 years imprisonment or 10 years if aggravated (Sec. 6823); relation to other laws (Sec. 6824); agency guidance (Sec. 6825); reports (Sec. 6826); definitions (Sec. 6827). OPERATIONALISATION: GLBA establishes the statutory umbrella; substantive operational controls are issued by regulators via subordinate rules: (a) FTC Safeguards Rule 16 CFR Part 314 (last major revision 2021 + 2023 breach-notification amendment effective 2024 + further 2024-2025 amendments - verified separately); (b) FTC Privacy Rule 16 CFR Part 313 + model privacy form; (c) SEC Regulation S-P (17 CFR Part 248) - amended March 2024 + effective 2025-2026 with incident-response + breach-notification + 30-day individual notification + supervisory + record-keeping requirements; (d) BANKING-AGENCY RULES (Interagency Guidelines Establishing Standards for Safeguarding Customer Information + Interagency Guidance on Response Programs for Unauthorized Access to Customer Information + Customer Notice) issued by OCC + Federal Reserve + FDIC + NCUA + OTS - see 12 CFR Part 30 + Part 208 + Part 364 + Part 748; (e) NAIC Insurance Data Security Model Law (NAIC #668) adopted by 20+ states; (f) CFPB enforcement under Dodd-Frank for non-bank financial institutions; (g) HIGHER EDUCATION institutions participating in Title IV (FSA - Federal Student Aid) are FTC Safeguards Rule covered + tracked separately as a sectoral application. 2024-2025 PIPELINE: SEC Reg S-P amendments effective 2025-12-03 large + 2026-06-03 small institutions; FTC Safeguards 2024 30-day FTC notification rule effective; CFPB Section 1033 Open Banking Rule (October 2024) imposes additional safeguarding obligations on screen-scrapers; NAIC Model Bulletin on AI 2023; state privacy laws (CCPA + state DP laws) coordinate. ENGAGEMENT: GLBA is the statutory umbrella - cross-mapping to substantive controls + auditor evidence should target the subordinate FTC Safeguards Rule + FTC Privacy Rule + SEC Reg S-P + banking-agency rule frameworks. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does GLBA have?

GLBA has 12 controls organised across 7 domains. The largest domains are GLBA: 2024-2025 Pipeline, Coordination and Cross-Mapping to Subordinate Substantive Rules (4 controls), GLBA: Operationalisation through FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P (2 controls), GLBA: Subchapter I (15 USC 6801-6809) Privacy and Safeguarding Obligations (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does GLBA map to?

GLBA maps to 153 other compliance frameworks. The top mapping partners are HKMA Cyber Resilience Assessment Framework (C-RAF) (33% coverage), APRA CPS 234 (33% coverage), AWS Well-Architected Security Pillar (33% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with GLBA compliance?

Start your GLBA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about GLBA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 12 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 701 frameworks.

Get Started Free →

Free forever — no credit card required