GLBA
Gramm-Leach-Bliley Act Safeguards Rule for financial institutions
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
GLBA: Cybersecurity Controls
Technical cybersecurity measures (GLBA)
| Code | Title |
|---|---|
| GLBA-06 | Network security and segmentation |
| GLBA-07 | Endpoint protection and detection |
| GLBA-08 | Application security controls |
| GLBA-09 | Encryption and key management |
| GLBA-10 | Access Controls and MFA |
GLBA: Incident Management & Reporting
Incident handling for financial services (GLBA)
| Code | Title |
|---|---|
| GLBA-21 | Records Retention and Disposal |
| GLBA-22 | Examination Readiness |
| GLBA-23 | Regulatory reporting requirements |
| GLBA-24 | Customer notification procedures |
| GLBA-25 | Post-incident review and improvement |
GLBA: Information Security Governance
IT governance for financial institutions (GLBA)
| Code | Title |
|---|---|
| GLBA-01 | Information security program management |
| GLBA-02 | Board and management oversight |
| GLBA-03 | Risk appetite and tolerance for IT risk |
| GLBA-04 | Security policy framework |
| GLBA-05 | Roles and responsibilities definition |
GLBA: Operational Resilience
Business continuity and resilience (GLBA)
| Code | Title |
|---|---|
| GLBA-11 | Asset Inventory and Data Mapping |
| GLBA-12 | Encryption at Rest and in Transit |
| GLBA-13 | Secure Development Practices |
| GLBA-14 | Continuous Monitoring or Periodic Testing |
| GLBA-15 | Security Awareness Training |
GLBA: Third-Party Risk Management
Managing vendor and supplier risks (GLBA)
| Code | Title |
|---|---|
| GLBA-16 | Service Provider Oversight |
| GLBA-17 | Periodic Program Evaluation and Adjustment |
| GLBA-18 | Incident Response Plan |
| GLBA-19 | Notification of Security Event (FTC) |
| GLBA-20 | Pretexting Protections |
Governance
| Code | Title |
|---|---|
| GLBA-22 | Examination Readiness |
Pretexting
| Code | Title |
|---|---|
| GLBA-20 | Pretexting Protections |
Privacy Rule
| Code | Title |
|---|---|
| GLBA-2 | Consumer vs Customer Classification |
| GLBA-3 | Initial Privacy Notice |
| GLBA-4 | Annual Privacy Notice |
| GLBA-5 | Opt-Out Right and Method |
| GLBA-6 | Limits on Re-disclosure and Re-use |
Safeguards Rule
| Code | Title |
|---|---|
| GLBA-10 | Access Controls and MFA |
| GLBA-11 | Asset Inventory and Data Mapping |
| GLBA-12 | Encryption at Rest and in Transit |
| GLBA-13 | Secure Development Practices |
| GLBA-14 | Continuous Monitoring or Periodic Testing |
| GLBA-15 | Security Awareness Training |
| GLBA-16 | Service Provider Oversight |
| GLBA-17 | Periodic Program Evaluation and Adjustment |
| GLBA-18 | Incident Response Plan |
| GLBA-19 | Notification of Security Event (FTC) |
| GLBA-21 | Records Retention and Disposal |
| GLBA-7 | Safeguards Rule Information Security Program |
| GLBA-8 | Qualified Individual |
| GLBA-9 | Risk Assessment |
Scope
| Code | Title |
|---|---|
| GLBA-1 | Financial Institution Determination |
Your Compliance Coverage
If you comply with GLBA, you already cover:
APRA CPS 234
44%
15 controls mapped
Compare →DORA
44%
15 controls mapped
Compare →FFIEC IT Examination Handbook
44%
15 controls mapped
Compare →+ 624 more: BCBS 239 (44%), TIBER-EU (Threat Intelligence-Based Ethical Red Teaming - European Union) (44%)
See all 627 mapped frameworks ↓Maps to 627 other frameworks
Frequently Asked Questions
What is GLBA?
GLBA is a compliance framework from United States with 10 domains and 47 controls. Gramm-Leach-Bliley Act Safeguards Rule for financial institutions It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does GLBA have?
GLBA has 47 controls organised across 10 domains. The largest domains are Safeguards Rule (14 controls), GLBA: Cybersecurity Controls (5 controls), GLBA: Incident Management & Reporting (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does GLBA map to?
GLBA maps to 627 other compliance frameworks. The top mapping partners are APRA CPS 234 (44% coverage), DORA (44% coverage), FFIEC IT Examination Handbook (44% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with GLBA compliance?
Start your GLBA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about GLBA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required