Framework library
Framework module · glba-safeguards-rule

GLBA Safeguards Rule

The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers.

16 CFR Part 314 (amended 2023) · Federal Trade Commission · published 2023-11-13

Standing today
Catalog only

01Standing

Catalog only

A directory entry — authority, version ledger, verification — not a workspace you can open.

GLBA Safeguards Rule is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.

Named and tracked only; requirements not modelled as a control catalog.

02Registry record

checked 2026-08-06
Registry status
Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Information security program · Access controls · Encryption · Testing and monitoring · Breach notification
Applies to
financial services · lending · tax preparation · auto dealers · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06

03Version ledger

3 editions
16 CFR Part 314 (2003)Supersededdate not published
16 CFR Part 314 (2021 amendments)Superseded · supersedes 16 CFR Part 314 (2003)date not published
16 CFR Part 314 (amended 2023)Current edition · supersedes 16 CFR Part 314 (2021 amendments)2023-11-13
GLBA Safeguards Rule — framework module | ControlFrame