Back to Frameworks

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule

United States (Federal / FTC)
v1999 (Safeguards Rule amended 2021)
10 domains
28 controls

The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314), as amended by the FTC in 2021, applies to higher education institutions that engage in financial activities such as student lending, financial aid processing, and payment plans. The updated rule requires institutions to develop, implement, and maintain a comprehensive information security program. Key requirements include risk assessment, access controls, encryption, multi-factor authentication, incident response, and appointment of a qualified individual. Compliance deadline was June 2023.

Verified

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule is a compliance framework from United States (Federal / FTC) with 10 domains and 28 controls that map to 174 other frameworks. The largest domains are GLBA Safeguards 314.4(c): Technical and Physical Safeguards (8 controls), GLBA Safeguards 314.4(d) to (i): Testing, Training and Oversight (6 controls), Applicability to Title IV Institutions (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

Applicability to Title IV Institutions

4 controls
Controls in the Applicability to Title IV Institutions domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule4 controls
CodeTitle
HE-1Financial institution status of higher education
HE-2Student financial information as customer information
HE-3FSA compliance requirements
HE-4Institutional governance integration

GLBA Higher Education: Title IV and Privacy Notices

2 controls
Controls in the GLBA Higher Education: Title IV and Privacy Notices domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule2 controls
CodeTitle
GLBA-HE-DoE-PPATitle IV Program Participation Agreement Compliance
GLBA-HE-Privacy-NoticePrivacy Notices and Opt Out

GLBA Safeguards 314.3 to 314.4(b): Programme and Risk Assessment

3 controls
Controls in the GLBA Safeguards 314.3 to 314.4(b): Programme and Risk Assessment domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule3 controls
CodeTitle
GLBA-HE-314.3Information Security Program
GLBA-HE-314.4(a)Qualified Individual
GLBA-HE-314.4(b)Risk Assessment

GLBA Safeguards 314.4(c): Technical and Physical Safeguards

8 controls
Controls in the GLBA Safeguards 314.4(c): Technical and Physical Safeguards domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule8 controls
CodeTitle
GLBA-HE-314.4(c)(1)Access Controls
GLBA-HE-314.4(c)(2)Data Inventory and Classification
GLBA-HE-314.4(c)(3)Encryption of Customer Information
GLBA-HE-314.4(c)(4)Secure Development Practices
GLBA-HE-314.4(c)(5)Multi-Factor Authentication
GLBA-HE-314.4(c)(6)Secure Disposal
GLBA-HE-314.4(c)(7)Change Management
GLBA-HE-314.4(c)(8)Logging and Monitoring of Authorized Users

GLBA Safeguards 314.4(d) to (i): Testing, Training and Oversight

6 controls
Controls in the GLBA Safeguards 314.4(d) to (i): Testing, Training and Oversight domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule6 controls
CodeTitle
GLBA-HE-314.4(d)Testing and Monitoring of Safeguards
GLBA-HE-314.4(e)Security Awareness Training
GLBA-HE-314.4(f)Service Provider Oversight
GLBA-HE-314.4(g)Program Evaluation and Adjustment
GLBA-HE-314.4(h)Incident Response Plan
GLBA-HE-314.4(i)Annual Report to Board

GLBA Safeguards 314.5: Security Event Notification

1 controls
Controls in the GLBA Safeguards 314.5: Security Event Notification domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule1 controls
CodeTitle
GLBA-HE-314.5Notification of Security Event

Governance

1 controls
Controls in the Governance domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule1 controls
CodeTitle
USGLBAHIGHER-1Qualified Individual and Risk Assessment

Incident

1 controls
Controls in the Incident domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule1 controls
CodeTitle
USGLBAHIGHER-4Incident Response and Notification

Monitoring

1 controls
Controls in the Monitoring domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule1 controls
CodeTitle
USGLBAHIGHER-3Continuous Monitoring, Testing, Vendor Oversight

Technical

1 controls
Controls in the Technical domain of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule1 controls
CodeTitle
USGLBAHIGHER-2Access Controls, Encryption, MFA, Inventory

Maps to 174 other frameworks

28 total controls
Nigeria Open Banking Regulatory Framework (CBN, 2023)
4 source controls mapped|2 target controls covered
14%
FTC GLBA Safeguards Rule (16 CFR Part 314)
4 source controls mapped|6 target controls covered
14%
14%
Uruguay DPL
4 source controls mapped|2 target controls covered
14%
Turkey KVKK
4 source controls mapped|2 target controls covered
14%
Texas Data Privacy Act
4 source controls mapped|2 target controls covered
14%
Taiwan PDPA
4 source controls mapped|2 target controls covered
14%
Qatar DPL
4 source controls mapped|3 target controls covered
14%
Privacy Act 2020
4 source controls mapped|3 target controls covered
14%
POPIA
4 source controls mapped|3 target controls covered
14%
Personal Data Act (personopplysningsloven)
4 source controls mapped|3 target controls covered
14%
PDPA Thailand
4 source controls mapped|3 target controls covered
14%
PDPA Singapore
4 source controls mapped|3 target controls covered
14%
Oregon Consumer Privacy Act
4 source controls mapped|3 target controls covered
14%
NRF Cybersecurity and Data Privacy Framework (National Retail Federation)
4 source controls mapped|3 target controls covered
14%
NIST SP 800-146
4 source controls mapped|2 target controls covered
14%
NIST SP 800-145
4 source controls mapped|3 target controls covered
14%
NIST SP 800-144
4 source controls mapped|3 target controls covered
14%
NIST SP 800-122
4 source controls mapped|2 target controls covered
14%
Nigeria Data Protection Regulation (NDPR)
4 source controls mapped|2 target controls covered
14%
Nigeria Data Protection Act 2023 (NDPA)
4 source controls mapped|6 target controls covered
14%
Nebraska Data Privacy Act
4 source controls mapped|6 target controls covered
14%
New Jersey Data Privacy Act
4 source controls mapped|4 target controls covered
14%
New Hampshire Data Privacy Act
4 source controls mapped|3 target controls covered
14%
MTCS (Singapore)
4 source controls mapped|5 target controls covered
14%
Montana Consumer Data Privacy Act
4 source controls mapped|3 target controls covered
14%
Minnesota Consumer Data Privacy Act
4 source controls mapped|3 target controls covered
14%
Mexico LFPDPPP
4 source controls mapped|3 target controls covered
14%
Mauritius DPA
4 source controls mapped|3 target controls covered
14%
Maryland Online Data Privacy Act of 2024
4 source controls mapped|4 target controls covered
14%
Malaysia PDPA 2010
4 source controls mapped|4 target controls covered
14%
Liechtenstein DPA
4 source controls mapped|3 target controls covered
14%
LGPD
4 source controls mapped|3 target controls covered
14%
South Korea PIPA
4 source controls mapped|3 target controls covered
14%
Kentucky Consumer Data Protection Act
4 source controls mapped|3 target controls covered
14%
Jamaica Data Protection Act 2020
4 source controls mapped|4 target controls covered
14%
ISMAP (Japan)
4 source controls mapped|2 target controls covered
14%
Iowa Consumer Data Protection Act
4 source controls mapped|3 target controls covered
14%
Indonesia PDP Law
4 source controls mapped|3 target controls covered
14%
Indiana Consumer Data Protection Act
4 source controls mapped|3 target controls covered
14%
14%
Florida Digital Bill of Rights (FDBR)
3 source controls mapped|3 target controls covered
11%
UK AI Regulation Framework
3 source controls mapped|2 target controls covered
11%
OECD AI Principles
3 source controls mapped|2 target controls covered
11%
NIST Privacy Framework
3 source controls mapped|2 target controls covered
11%
New Zealand Information Security Manual (NZISM)
3 source controls mapped|4 target controls covered
11%
Japan AI Guidelines
3 source controls mapped|2 target controls covered
11%
IEEE 7000
3 source controls mapped|2 target controls covered
11%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|4 target controls covered
11%
FedRAMP Rev 5
3 source controls mapped|3 target controls covered
11%
Family Educational Rights and Privacy Act (FERPA)
3 source controls mapped|1 target controls covered
11%
FISMA
3 source controls mapped|3 target controls covered
11%
Ghana Cybersecurity Act
3 source controls mapped|4 target controls covered
11%
HKMA Cyber Resilience Assessment Framework (C-RAF)
3 source controls mapped|3 target controls covered
11%
IEEE 1686
3 source controls mapped|3 target controls covered
11%
India CERT-In Cyber Security Directions 2022
3 source controls mapped|1 target controls covered
11%
India DPDP Act
3 source controls mapped|2 target controls covered
11%
Law No. 172-13 on the Protection of Personal Data
3 source controls mapped|2 target controls covered
11%
Ley Orgánica de Protección de Datos Personales (LOPDP)
3 source controls mapped|2 target controls covered
11%
NERC CIP
3 source controls mapped|2 target controls covered
11%
Nevada Gaming Control Board Cybersecurity Requirements
3 source controls mapped|4 target controls covered
11%
11%
UK GDPR (UK General Data Protection Regulation)
3 source controls mapped|1 target controls covered
11%
TSA Pipeline Cybersecurity Directives
3 source controls mapped|2 target controls covered
11%
Privacy Act 1988 (Australia)
3 source controls mapped|2 target controls covered
11%
ISO/IEC 27400:2022
2 source controls mapped|1 target controls covered
7%
ISO/IEC 30111:2019
2 source controls mapped|2 target controls covered
7%
Japan FSA Cybersecurity Guidelines for Financial Institutions
2 source controls mapped|3 target controls covered
7%
NIS2 Directive Implementing Acts
2 source controls mapped|2 target controls covered
7%
Oman National Cybersecurity Framework
2 source controls mapped|1 target controls covered
7%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|2 target controls covered
7%
TEFCA - Trusted Exchange Framework and Common Agreement
2 source controls mapped|1 target controls covered
7%
ISO/IEC 29147:2018
2 source controls mapped|3 target controls covered
7%
SQF Code Edition 9 - Safe Quality Food
2 source controls mapped|2 target controls covered
7%
ISO/IEC 27031:2011
2 source controls mapped|1 target controls covered
7%
ISO/IEC 29134:2023
2 source controls mapped|2 target controls covered
7%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|2 target controls covered
7%
FATF Recommendation 16 - Virtual Asset Travel Rule
2 source controls mapped|1 target controls covered
7%
FDA 21 CFR Part 11
2 source controls mapped|1 target controls covered
7%
French Sapin II Law (Law No. 2016-1691)
2 source controls mapped|2 target controls covered
7%
FSSC 22000 - Food Safety System Certification
2 source controls mapped|1 target controls covered
7%
German Supply Chain Due Diligence Act (LkSG)
2 source controls mapped|2 target controls covered
7%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
2 source controls mapped|1 target controls covered
7%
IATF 16949:2016 - Quality Management System for Automotive Production
2 source controls mapped|2 target controls covered
7%
ICAO Annex 17 - Aviation Security (AVSEC)
2 source controls mapped|2 target controls covered
7%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
2 source controls mapped|2 target controls covered
7%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
2 source controls mapped|2 target controls covered
7%
Lloyd's of London Cyber Insurance Requirements and Underwriting Standards
2 source controls mapped|2 target controls covered
7%
MARS-E
2 source controls mapped|1 target controls covered
7%
MDS2 (Medical Device)
2 source controls mapped|1 target controls covered
7%
NAIC Insurance Data Security Model Law (MDL-668)
2 source controls mapped|2 target controls covered
7%
NIST SP 800-30
2 source controls mapped|3 target controls covered
7%
NIST SP 800-37
2 source controls mapped|2 target controls covered
7%
NIST SP 800-39
2 source controls mapped|1 target controls covered
7%
NIST SP 800-66
2 source controls mapped|1 target controls covered
7%
Own Risk and Solvency Assessment (ORSA) - NAIC Model Act
2 source controls mapped|2 target controls covered
7%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
2 source controls mapped|2 target controls covered
7%
UNICEF Policy Guidance on AI for Children (2021)
2 source controls mapped|1 target controls covered
7%
UNESCO Recommendation on the Ethics of AI
2 source controls mapped|1 target controls covered
7%
UK FCA/PRA Operational Resilience Framework
2 source controls mapped|2 target controls covered
7%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
2 source controls mapped|1 target controls covered
7%
SEC Climate Disclosure Rule
2 source controls mapped|1 target controls covered
7%
IFRS 17 - Insurance Contracts
1 source controls mapped|1 target controls covered
4%
APRA CPS 230 Operational Risk Management
1 source controls mapped|1 target controls covered
4%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|4 target controls covered
4%
Virginia CDPA
1 source controls mapped|1 target controls covered
4%
Vietnam PDPD
1 source controls mapped|1 target controls covered
4%
TCFD Recommendations
1 source controls mapped|1 target controls covered
4%
SASB Standards
1 source controls mapped|2 target controls covered
4%
ISSB Standards
1 source controls mapped|1 target controls covered
4%
Bahrain PDPL
1 source controls mapped|1 target controls covered
4%
FedRAMP High
1 source controls mapped|1 target controls covered
4%
NIST SP 800-53 Revision 5.1 HIGH
1 source controls mapped|1 target controls covered
4%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
4%
NIST SP 800-53 Rev 5 MODERATE
1 source controls mapped|1 target controls covered
4%
NIST SP 800-53 Rev 5 LOW
1 source controls mapped|1 target controls covered
4%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
1 source controls mapped|1 target controls covered
4%
Saudi Arabia PDPL
1 source controls mapped|1 target controls covered
4%
ISO 27018
1 source controls mapped|1 target controls covered
4%
ISO 45001
1 source controls mapped|1 target controls covered
4%
ISO 27017
1 source controls mapped|1 target controls covered
4%
ISO 22000
1 source controls mapped|1 target controls covered
4%
ISO 14001
1 source controls mapped|1 target controls covered
4%
NIST SP 800-190
1 source controls mapped|1 target controls covered
4%
NIST SP 800-171
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27010:2015
1 source controls mapped|1 target controls covered
4%
FIRST CSIRT Services Framework and Standards
1 source controls mapped|1 target controls covered
4%
GLBA
1 source controls mapped|2 target controls covered
4%
HITECH Act
1 source controls mapped|1 target controls covered
4%
HKMA SPM
1 source controls mapped|1 target controls covered
4%
Laos Law on Prevention and Combating Cybercrime (2015)
1 source controls mapped|1 target controls covered
4%
Monetary Authority of Singapore Technology Risk Management Guidelines
1 source controls mapped|1 target controls covered
4%
Open Banking Security
1 source controls mapped|2 target controls covered
4%
OSFI B-13
1 source controls mapped|3 target controls covered
4%
OWASP Top 10:2025
1 source controls mapped|1 target controls covered
4%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|1 target controls covered
4%
Papua New Guinea National Cybersecurity Policy & Cybercrime Act (2016)
1 source controls mapped|1 target controls covered
4%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
1 source controls mapped|1 target controls covered
4%
UK Gambling Commission - Cyber Resilience Requirements
1 source controls mapped|1 target controls covered
4%
Trinidad and Tobago Data Protection Act 2011
1 source controls mapped|1 target controls covered
4%
Tanzania Personal Data Protection Act (Draft)
1 source controls mapped|1 target controls covered
4%
Singapore Cybersecurity Act 2018
1 source controls mapped|1 target controls covered
4%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
4%
PSD2 SCA
1 source controls mapped|2 target controls covered
4%
Peru DPL
1 source controls mapped|2 target controls covered
4%
ISO/IEC 27011:2024
1 source controls mapped|1 target controls covered
4%
ISO/IEC 27006:2024
1 source controls mapped|1 target controls covered
4%
MITRE ATT&CK
1 source controls mapped|1 target controls covered
4%
MITRE D3FEND
1 source controls mapped|1 target controls covered
4%
Modern Slavery Act 2018 (Australia)
1 source controls mapped|1 target controls covered
4%
NIST SP 800-123
1 source controls mapped|1 target controls covered
4%
NIST SP 800-137
1 source controls mapped|1 target controls covered
4%
NIST SP 800-61
1 source controls mapped|1 target controls covered
4%
NIST SP 800-63-4
1 source controls mapped|1 target controls covered
4%
NIST SP 800-88
1 source controls mapped|1 target controls covered
4%
NIST SP 800-92
1 source controls mapped|1 target controls covered
4%
O-RAN WG11 Security Specification
1 source controls mapped|1 target controls covered
4%
OpenSSF Scorecard
1 source controls mapped|1 target controls covered
4%
OWASP ASVS
1 source controls mapped|1 target controls covered
4%
OWASP MASVS
1 source controls mapped|1 target controls covered
4%
OWASP SAMM
1 source controls mapped|1 target controls covered
4%
UN Guiding Principles on Business and Human Rights (UNGPs)
1 source controls mapped|1 target controls covered
4%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
4%
SLSA
1 source controls mapped|1 target controls covered
4%
SIG (Shared Assessments)
1 source controls mapped|1 target controls covered
4%
Secure by Design: A Guide for Manufacturers (CISA)
1 source controls mapped|2 target controls covered
4%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
4%
PTES
1 source controls mapped|1 target controls covered
4%

What is US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule and who does it apply to?

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule is a compliance framework from United States (Federal / FTC) with 10 domains and 28 controls. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (16 CFR Part 314), as amended by the FTC in 2021, applies to higher education institutions that engage in financial activities such as student lending, financial aid processing, and payment plans. The updated rule requires institutions to develop, implement, and maintain a comprehensive information security program. Key requirements include risk assessment, access controls, encryption, multi-factor authentication, incident response, and appointment of a qualified individual. Compliance deadline was June 2023. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule actually require?

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule has 28 controls organised across 10 domains. The largest domains are GLBA Safeguards 314.4(c): Technical and Physical Safeguards (8 controls), GLBA Safeguards 314.4(d) to (i): Testing, Training and Oversight (6 controls), Applicability to Title IV Institutions (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule do I already cover?

US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule maps to 174 other compliance frameworks. The top mapping partners are Nigeria Open Banking Regulatory Framework (CBN, 2023) (14% coverage), FTC GLBA Safeguards Rule (16 CFR Part 314) (14% coverage), Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL) (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule?

Start your US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required