GLBA
GLBA Safeguards Rule Information Security Checklist
A Safeguards Rule checklist for written program, risk assessment, access controls, encryption, and qualified individual.
- Estimated time
- 3–8 Months
- Audience
- US Financial Institutions and Fintechs under FTC/Banking Agencies
- Last updated
Operational reference for GLBA Safeguards readiness. FTC and federal banking agencies enforce; this is not legal advice.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Program
Phase 2: Controls
Phase 3: Test & Train
Phase 4: Evidence
FAQ
Who is a financial institution under GLBA?+–
A defined term—banks, and many non-banks that provide financial products. Fintechs should confirm with counsel.
FTC vs banking agencies?+–
Non-bank financial institutions often fall under the FTC Safeguards Rule; banks have parallel agency guidelines.
Does SOC 2 cover GLBA?+–
SOC 2 evidence helps. GLBA has specific program and reporting elements.
Is MFA required?+–
The FTC Safeguards Rule requires MFA for individuals accessing customer information, with limited exceptions.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer