Abschnittsknoten
Information security program
16 CFR 314.4(a)
- Was diese Seite ist
- Abschnittsknoten, 16 CFR 314.4(a)
- Gegen die amtliche Quelle geprüft
- 2026-08-15Aktuell
- Verantwortlicher Herausgeber
- ExploreWorld Legal, RedaktionHaftungsposition
Kurze Antwort
What does 16 CFR 314.4(a) require, and where does it carry an outcome in the rule tree?
16 CFR 314.4(a) is the paragraph the GLBA decision agent rests on for this question. A written programme with a named qualified individual responsible for it. The block was read against the publisher on 2026-08-15 and carries 3 outcomes in the agent's rule tree. The reference can be cited as it stands, with a link to the official text and a content hash.
16 CFR 314.4(a)Gegen den Herausgeber geprüft 2026-08-15Amtlicher Text
Ein Quellenverweis, keine Rechtsberatung.
- Rechtsordnung
- 16 CFR Part 314
- Abschnittsknoten
- program
- Gelesen
- 2026-08-15
- Hash
- sha256:a641b1a147b83f86
Ergebnisse, die auf diesem Abschnitt ruhen
Die Regeln unten verweisen in ihrem Ergebnis auf diesen Abschnitt. Das Verdikt ist eine maschinelle Einordnung, kein Urteil über einen Einzelfall.
glba-program
The written information security program is absent
16 CFR 314.3(a) requires a written information security program appropriate to the size and complexity of the activity and the information handled.
unzulässig, Die Anforderung gilt
glba-qualified
No qualified individual is designated
16 CFR 314.4(a) requires designating a qualified individual responsible for the program, and 16 CFR 314.4(i) requires reporting to the board or equivalent.
Risiko, Die Anforderung gilt
glba-base
The rule applies, with the exemption for smaller holdings
16 CFR 314.1 states the scope for financial institutions under the Commission's jurisdiction. 16 CFR 314.6 exempts those maintaining information on fewer than 5,000 customers from parts of 314.4.
Risiko, Die Anforderung gilt bedingt
Abschnittsknoten
- Risk assessment16 CFR 314.4(b)
- Safeguards16 CFR 314.4(c)
- Notification of a security event16 CFR 314.5
Das Verdikt ist eine maschinelle Einordnung des Ergebnisses, keine Rechtsberatung und keine Compliance-Entscheidung.
Überprüfbare Vertrauenssignale
- Sechs feste Blöcke, eine Quelle je Zeile
- Kein Satz von einem Sprachmodell geschrieben
- Version und Lesedatum an jeder Antwort
- Keine Kundendaten, keine Dokumente, keine Beratung
- Modellkarte und Prüfung nach der KI-Verordnung veröffentlicht