GLBA: Proposed Changes

Cybersecurity staff sitting at desk reviewing security protocols.
Cybersecurity staff sitting at desk reviewing security protocols.

On March 5th, the Federal Trade Commission (“FTC”) proposed amendments to the Safeguards Rule and Privacy Rule under the Gramm-Leach-Bliley Act (“GLBA”).  These amendments are significant in several ways. However, the most impactful will be the changes to the Safeguards Rule which governs the information security programs of financial institutions. 

Proposed Revisions

Until now, the Safeguards Rule, which first went into effect in 2003, provided general guidance requiring companies to develop, implement and maintain a “comprehensive information security program.”  The proposed revisions now provide prescriptive requirements intended to provide greater protection to consumers and greater certainty to businesses. These changes include requiring:

  • The designation of a Chief Information Security Officer (CISO), responsible for overseeing and implementing the program.
  • The CISO to report at least annually to the board on issues related to the information security program.
  • Additional requirements to risk assessments, mandating that the report be written, performed regularly and include recommendations for addressing identified risks.
  • Accession control (physical security) to limit access to locations containing customer data to authorized individuals.
  • Customer data to be encrypted at rest and in transit.
  • Multi-factor authentication (MFA) for any individual accessing customer data.
  • Audit logs to include information events designed to detect and respond to security events
  • Regular testing and continuous monitoring of critical controls, systems, and procedures.
  • Appropriate training and education.
  • Key personnel take steps to maintain current cybersecurity knowledge.
  • Companies to utilize qualified security personnel.
  • Companies to oversee and assess service providers based on the risk they present to information security.
  • Companies to implement and maintain an Incident Response Plan.
  • Procedures that clearly define the secure disposal of customer information.
  • Policies and procedures for change management.
  • Policies and procedures for monitoring authorized and unauthorized access, use and modification of customer information.

Who Will Be Affected

The proposed changes also expand the definition of “financial institutions” to include finders (those who charge a fee to connect consumers to lenders) and companies who engage in activities “incidental to financial activities.” As with any prescriptive cybersecurity guidelines, those organizations who have not previously been governed by GLBA, those that did not already have a strong governance plan as well as smaller entities will be affected the most.

Responses to the Proposed Revisions

Until now, GLBA has offered general guidelines. It is unlikely that the proposed changes will be accepted with open arms. There are also concerns about the impact on smaller organizations as well as the FTC’s ability to measure and enforce these new guidelines. Those wishing to weigh in on the proposed changes have 60 days after the publication in the Federal Register.¹

Takeaways

  1. This is the opportunity to review your current information security program.
  2.  If you haven’t already, reconsider your current partnerships and any processes by which you evaluate vendors.
  3. Establish a relationship with a reputable security vendor.

We Can Help.

If your organization is concerned about compliance or feels there may be a gap in your current security posture, we would love the opportunity to earn your business.  You can speak with a member of our team by contacting us today.

¹ https://www.ftc.gov/news-events/press-releases/2019/03/ftc-seeks-comment-proposed-amendments-safeguards-privacy-rules

Corsica Technologies
Corsica Technologies is an MSP specializing in cybersecurity solutions, managed IT services, digital transformation, and data integration. Corsica provides solutions for midmarket businesses including network monitoring, data protection, incident response, and IT support. Corsica offers unmetered technology services for fully managed or co-managed teams to address all technology needs under a one-flat monthly fee. 

Related Cybersecurity and IT Reads

Tariffs effect on computer and electronic prices for businesses - Corsica Technologies
Hardware as a Service
Garrett Wiesenberg

How Will Tariffs Affect Computer Prices for Businesses?

As the United States rolls out tariffs on imported goods, companies everywhere are working hard to understand the potential impact of these economic policies on their business. While the answers are complex and dependent on your industry, one thing is

Read more
Penetration Testing Services - Corsica Technologies
Cybersecurity
Ross Filipek

Penetration Testing Services 101

In this article: What is pentesting?  Can your own staff do it?  Should you test in off-hours?  Pentesting steps  How to prepare  What do you get? See a sample report Are you easy to hack? That’s the big question. Yet many

Read more
Windows Server 2019 end of life - Corsica Technologies
Managed IT Services
Garrett Wiesenberg

Windows Server 2019 EOL: What You Need to Know

On January 9, 2024, Windows Server 2019 officially ended mainstream support. While Microsoft will continue to provide security updates until January 9, 2029, the operating system isn’t receiving new features or bug fixes. What does that mean for you? Is

Read more

Sign Up For Our Newsletter

Stay up-to-date on the Managed Services and Cybersecurity landscape, and be the first to find out about events and special offers.

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.