Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

What does the GLBA Safeguards Rule require of a financial institution?

A written security program owned by a named qualified individual, built on a written risk assessment, with access controls, inventory, encryption, multi-factor authentication, secure disposal, monitoring, training, oversight of service providers, an incident response plan and an annual written report to the board.

The answer differs between the federal level and the states, see the rows below.

The answer by level

  • Federal level

    A financial institution maintains a written information security program with a qualified individual in charge, a written risk assessment, access controls, encryption, multi-factor authentication and an incident response plan.

    16 CFR Part 314
  • Sector rule

    Notification to the Commission is required as soon as possible and no later than 30 days after discovery of a notification event affecting at least 500 consumers.

    16 CFR Part 314, Safeguards Rule
  • State level

    New York adds an annual certification of compliance, a named chief information security officer and a 72 hour notification duty for covered entities.

    23 NYCRR Part 500

Source lines

  • The rule applies to financial institutions under the Commission's jurisdiction, a category far broader than banks and including many lenders, advisers and dealers.
  • Institutions maintaining information on fewer than five thousand consumers are exempt from several elements, including the written risk assessment and the annual report.
  • A notification event affecting at least 500 consumers is reported to the Commission within 30 days of discovery.

What it means for the company

The obligation is documentary as much as technical. An institution that runs strong controls but cannot show the written risk assessment and the annual board report is still exposed.

Comparison across levels and states
LevelRequirementSource
Federal levelA financial institution maintains a written information security program with a qualified individual in charge, a written risk assessment, access controls, encryption, multi-factor authentication and an incident response plan.16 CFR Part 314
Sector ruleNotification to the Commission is required as soon as possible and no later than 30 days after discovery of a notification event affecting at least 500 consumers.16 CFR Part 314, Safeguards Rule
State levelNew York adds an annual certification of compliance, a named chief information security officer and a 72 hour notification duty for covered entities.23 NYCRR Part 500

What it means for the individual

Customer information covered by the rule includes records held about people who are not customers of the institution, when the institution received the data from another institution.

Source lines

  • GLBA Safeguards Rule
    16 CFR Part 314 · read 2026-08-25 · proof 9b9860e70d7311b7
  • NYDFS Cybersecurity Regulation
    23 NYCRR Part 500 · read 2026-08-25 · proof 9b9860e70d7311b7
  • Electronic Code of Federal Regulations
    16 CFR Part 314, Safeguards Rule · read 2026-08-25 · proof 9b9860e70d7311b7
    Official source
  • New York State Department of Financial Services
    23 NYCRR Part 500 · read 2026-08-25 · proof 9b9860e70d7311b7
    Official source

Next step

Name the qualified individual in writing, date the risk assessment, and calendar the annual board report.

All US questions

This page reports what the sources say, with the identifier and address of the publisher. It is not legal advice and does not decide an individual matter.

Next step

Three ways to put the register to work in your own practice.

Start with your task