GLBA Safeguards Rule
The FTC's mandatory security program for non-banking financial institutions — encryption, MFA, penetration testing, and breach reporting for events over 500 customers.
16 CFR Part 314 (amended 2023) · Federal Trade Commission · published 2023-11-13
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
GLBA Safeguards Rule is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Named and tracked only; requirements not modelled as a control catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Information security program · Access controls · Encryption · Testing and monitoring · Breach notification
- Applies to
- financial services · lending · tax preparation · auto dealers · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
03Version ledger
| 16 CFR Part 314 (2003) | Superseded | date not published |
| 16 CFR Part 314 (2021 amendments) | Superseded · supersedes 16 CFR Part 314 (2003) | date not published |
| 16 CFR Part 314 (amended 2023) | Current edition · supersedes 16 CFR Part 314 (2021 amendments) | 2023-11-13 |
05Change history
06Related frameworks
- HITRUST CSFv11.8.0
Also applies to financial services · A licensed cybersecurity and risk-management framework used across healthcare and other sectors. HITRUST offers scoped assessment and certification programs through its authorized processes; registry tracking claims no certification.
Also applies to financial services · The widely used internal-control framework for operations, reporting, and compliance, including internal control over financial reporting. It supplies evaluation criteria; it is not a certification and SOX does not create a fixed IT-control catalog.
- Digital Operational Resilience ActRegulation (EU) 2022/2554
Also applies to financial services · The EU digital-operational-resilience rulebook for financial entities, covering ICT risk, incidents, testing, information sharing, and third-party risk, plus an oversight framework for ICT providers designated critical.
- FFIEC IT Examination HandbookCurrent booklets (living collection)
Also applies to financial services · The living technology-supervision reference used by US financial institution examiners, with current booklets, work programs, laws, and guidance. It is supervisory guidance, not a certification; the separate FFIEC Cybersecurity Assessment Tool was retired in 2025.