Back to Frameworks

FTC Safeguards Rule

United States
25 domains
29 controls

FTC Safeguards Rule (16 CFR Part 314, revised effective 9 Jun 2023, breach notification effective 13 May 2024).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (25)

Applicability

2 controls
Controls in the Applicability domain of FTC Safeguards Rule2 controls
CodeTitle
SR-314.2-CICustomer information definition
SR-314.2-FIFinancial institution scoping

Application security

1 controls
Controls in the Application security domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-4Secure development practices

Asset management

1 controls
Controls in the Asset management domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-2Inventory of data, personnel, devices, systems, and facilities

Assurance

2 controls
Controls in the Assurance domain of FTC Safeguards Rule2 controls
CodeTitle
SR-314.4-d-1Regular testing or monitoring effectiveness
SR-314.4-d-2Penetration testing and vulnerability assessment

Authentication

1 controls
Controls in the Authentication domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-5Multi-factor authentication

Breach notification

1 controls
Controls in the Breach notification domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-jNotification of security event to FTC

Cross-regulatory alignment

2 controls
Controls in the Cross-regulatory alignment domain of FTC Safeguards Rule2 controls
CodeTitle
SR-INT-STATEInteraction with state breach notification and sectoral laws
SR-PRIV-NOTICERelationship with Privacy Rule (16 CFR Part 313)

Cryptographic protection

1 controls
Controls in the Cryptographic protection domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-3Encryption of customer information

Data lifecycle

1 controls
Controls in the Data lifecycle domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-6Secure disposal of customer information

Documentation

1 controls
Controls in the Documentation domain of FTC Safeguards Rule1 controls
CodeTitle
SR-DOC-EVIDENCERecords and evidence retention

Governance

1 controls
Controls in the Governance domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-aDesignation of Qualified Individual

Governance reporting

1 controls
Controls in the Governance reporting domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-iAnnual report to governing body

Human resources

1 controls
Controls in the Human resources domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-ePersonnel training and qualification

Implementation

1 controls
Controls in the Implementation domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.5Effective date and implementation

Incident response

1 controls
Controls in the Incident response domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-hWritten incident response plan

Monitoring

1 controls
Controls in the Monitoring domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-8Monitoring and logging of authorized user activity

Operational security

1 controls
Controls in the Operational security domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-7Change management

Program lifecycle

1 controls
Controls in the Program lifecycle domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-gEvaluation and adjustment of program

Program scope and objective

1 controls
Controls in the Program scope and objective domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.3Standards for safeguarding customer information

Regulatory enforcement

1 controls
Controls in the Regulatory enforcement domain of FTC Safeguards Rule1 controls
CodeTitle
SR-ENFEnforcement and penalties

Resilience

1 controls
Controls in the Resilience domain of FTC Safeguards Rule1 controls
CodeTitle
SR-CONT-PLANBusiness continuity considerations (implicit via CIA objective)

Risk assessment

1 controls
Controls in the Risk assessment domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-bWritten risk assessment

Scope exception

1 controls
Controls in the Scope exception domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.6Exceptions for small institutions

Technical safeguard

1 controls
Controls in the Technical safeguard domain of FTC Safeguards Rule1 controls
CodeTitle
SR-314.4-c-1Access controls

Third party risk

2 controls
Controls in the Third party risk domain of FTC Safeguards Rule2 controls
CodeTitle
SR-314.4-f-1Service provider selection and contractual safeguards
SR-314.4-f-3Periodic assessment of service providers

Frequently Asked Questions

What is FTC Safeguards Rule?

FTC Safeguards Rule is a compliance framework from United States with 25 domains and 29 controls. FTC Safeguards Rule (16 CFR Part 314, revised effective 9 Jun 2023, breach notification effective 13 May 2024). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does FTC Safeguards Rule have?

FTC Safeguards Rule has 29 controls organised across 25 domains. The largest domains are Applicability (2 controls), Assurance (2 controls), Cross-regulatory alignment (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does FTC Safeguards Rule map to?

FTC Safeguards Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with FTC Safeguards Rule compliance?

Start your FTC Safeguards Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FTC Safeguards Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 29 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required