Skip to content

Compliance & frameworks

GLBA

Gramm-Leach-Bliley Act — Safeguards Rule

GLBA's Safeguards Rule requires financial institutions to protect the customer information they hold with a written information security program overseen by a named, qualified individual. The rule is enforced by the FTC (16 CFR Part 314), and its 2021 revision — with a compliance deadline in June 2023 — turned what used to be broad principles into specific, testable technical safeguards: access controls, encryption of customer information at rest and in transit, multi-factor authentication, change management, and monitoring and logging. Most of those safeguards now live in your cloud configuration, which is exactly where a health check looks.

Who it applies to

GLBA reaches far more than banks. The FTC defines a "financial institution" broadly, so mortgage lenders and brokers, consumer-finance and lending companies, payment and money-transfer firms, investment advisers not registered with the SEC, tax preparers, collection agencies, auto dealers arranging financing, and many fintechs all fall under the Safeguards Rule. Banks and credit unions supervised by the federal banking agencies follow the equivalent interagency guidelines rather than the FTC rule, but the underlying cloud-technical expectations are the same. If your business collects nonpublic personal financial information about consumers, assume GLBA applies until counsel tells you otherwise.

Cloud control themes

What GLBA asks of your cloud

  • Access controls and least privilege (314.4(c)(1)) — who can reach the systems that hold customer information
  • Encryption of customer information at rest and in transit (314.4(c)(3))
  • Multi-factor authentication for anyone accessing information systems (314.4(c)(5))
  • Monitoring and logging of authorized user activity, and detection of unauthorized access (314.4(c)(8))
  • Change management and secure configuration of the environment (314.4(c)(7))
  • Periodic risk assessment and oversight of cloud service providers (314.4(b), 314.4(f))

Domain × framework

Which assessment domains produce GLBA evidence

Assessment domainHow it maps
Identity & accessMFA and access-control findings map directly to 314.4(c)(1) and (c)(5) — least privilege, enforced MFA, and deprovisioning for anyone who can reach customer information.
Data securityEncryption and storage-exposure findings evidence 314.4(c)(3) encryption at rest and in transit, and support the data-inventory and secure-disposal expectations in (c)(2) and (c)(6).
Network exposureExposed endpoints and weak segmentation around systems holding customer information are the boundary risks the Rule's access controls and risk assessment are meant to reduce.
Logging & monitoringLog coverage and detection findings map to 314.4(c)(8) — monitoring and logging authorized user activity and detecting unauthorized access to customer information.
Configuration & postureBaseline drift and change-control findings support the change-management expectation in 314.4(c)(7) and the secure configuration underlying the program.

What you get

A findings report organized around the Safeguards Rule's technical elements: each cloud gap tied to the relevant safeguard — access controls, MFA, encryption, change management, monitoring — ranked by real risk, with a remediation order your qualified individual, your engineers, and your examiner can all follow. It gives your written program an accurate picture of the environment instead of an assumed one, without touching production.

Most relevant to: FinTech, Commercial real estate

Questions

Does a health check make us GLBA compliant?

No. GLBA compliance is a written information security program overseen by a qualified individual, and it includes governance and process work that lives with you. The health check assesses and prioritizes the cloud-technical safeguards the Safeguards Rule requires — MFA, encryption, access controls, logging — so that program rests on an accurate picture of your environment.

We're a fintech, not a bank — does GLBA apply to us?

Often, yes. The FTC's definition of a financial institution is deliberately broad and covers many lenders, payment firms, advisers, and fintechs that never think of themselves as banks. We are not your lawyers, so confirm scope with counsel, but if you handle consumers' nonpublic financial information the Safeguards Rule's cloud requirements are worth assessing now.

Did the updated Safeguards Rule change what matters in the cloud?

Yes. The 2021 revision, with a June 2023 compliance date, added specific technical requirements — enforced MFA, encryption of customer information at rest and in transit, change management, and monitoring and logging of authorized activity. Each of those lands directly on cloud configuration, which is what the health check examines across your AWS, Azure, and Google Cloud accounts.

Framework work in practice

Evidence rooms and compliance tables

Mapping is for auditors and operators — shown in the spaces where evidence is reviewed.

Take free readiness check