FTC Safeguards Rule
FTC Safeguards Rule (16 CFR Part 314, revised effective 9 Jun 2023, breach notification effective 13 May 2024).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (25)
Applicability
| Code | Title |
|---|---|
| SR-314.2-CI | Customer information definition |
| SR-314.2-FI | Financial institution scoping |
Application security
| Code | Title |
|---|---|
| SR-314.4-c-4 | Secure development practices |
Asset management
| Code | Title |
|---|---|
| SR-314.4-c-2 | Inventory of data, personnel, devices, systems, and facilities |
Assurance
| Code | Title |
|---|---|
| SR-314.4-d-1 | Regular testing or monitoring effectiveness |
| SR-314.4-d-2 | Penetration testing and vulnerability assessment |
Authentication
| Code | Title |
|---|---|
| SR-314.4-c-5 | Multi-factor authentication |
Breach notification
| Code | Title |
|---|---|
| SR-314.4-j | Notification of security event to FTC |
Cross-regulatory alignment
| Code | Title |
|---|---|
| SR-INT-STATE | Interaction with state breach notification and sectoral laws |
| SR-PRIV-NOTICE | Relationship with Privacy Rule (16 CFR Part 313) |
Cryptographic protection
| Code | Title |
|---|---|
| SR-314.4-c-3 | Encryption of customer information |
Data lifecycle
| Code | Title |
|---|---|
| SR-314.4-c-6 | Secure disposal of customer information |
Documentation
| Code | Title |
|---|---|
| SR-DOC-EVIDENCE | Records and evidence retention |
Governance
| Code | Title |
|---|---|
| SR-314.4-a | Designation of Qualified Individual |
Governance reporting
| Code | Title |
|---|---|
| SR-314.4-i | Annual report to governing body |
Human resources
| Code | Title |
|---|---|
| SR-314.4-e | Personnel training and qualification |
Implementation
| Code | Title |
|---|---|
| SR-314.5 | Effective date and implementation |
Incident response
| Code | Title |
|---|---|
| SR-314.4-h | Written incident response plan |
Monitoring
| Code | Title |
|---|---|
| SR-314.4-c-8 | Monitoring and logging of authorized user activity |
Operational security
| Code | Title |
|---|---|
| SR-314.4-c-7 | Change management |
Program lifecycle
| Code | Title |
|---|---|
| SR-314.4-g | Evaluation and adjustment of program |
Program scope and objective
| Code | Title |
|---|---|
| SR-314.3 | Standards for safeguarding customer information |
Regulatory enforcement
| Code | Title |
|---|---|
| SR-ENF | Enforcement and penalties |
Resilience
| Code | Title |
|---|---|
| SR-CONT-PLAN | Business continuity considerations (implicit via CIA objective) |
Risk assessment
| Code | Title |
|---|---|
| SR-314.4-b | Written risk assessment |
Scope exception
| Code | Title |
|---|---|
| SR-314.6 | Exceptions for small institutions |
Technical safeguard
| Code | Title |
|---|---|
| SR-314.4-c-1 | Access controls |
Third party risk
| Code | Title |
|---|---|
| SR-314.4-f-1 | Service provider selection and contractual safeguards |
| SR-314.4-f-3 | Periodic assessment of service providers |
Frequently Asked Questions
What is FTC Safeguards Rule?
FTC Safeguards Rule is a compliance framework from United States with 25 domains and 29 controls. FTC Safeguards Rule (16 CFR Part 314, revised effective 9 Jun 2023, breach notification effective 13 May 2024). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does FTC Safeguards Rule have?
FTC Safeguards Rule has 29 controls organised across 25 domains. The largest domains are Applicability (2 controls), Assurance (2 controls), Cross-regulatory alignment (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does FTC Safeguards Rule map to?
FTC Safeguards Rule does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with FTC Safeguards Rule compliance?
Start your FTC Safeguards Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about FTC Safeguards Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 29 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required