Cyber Insurance Subjectivity Tracker

Rules

Add-on: United States

FTC GLBA Safeguards Rule (16 CFR Part 314)

Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.

edition 16 CFR Part 314, from the eCFR text held at 1 Jan 2026. 13 requirements cited here. Every FTC Safeguards Rule clause we hold.

Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(5)
FTC Safeguards Rule
314.4(c)(5) Multi-factor authentication

Multi-factor authentication is implemented for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.

evidence an assessor asks for MFA enforcement on every information system access, including remote and administrative access; Qualified Individual's written approval of any equivalent control

Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(5)
FTC Safeguards Rule
314.4(c)(5) Multi-factor authentication

Multi-factor authentication is implemented for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls.

evidence an assessor asks for MFA enforcement on every information system access, including remote and administrative access; Qualified Individual's written approval of any equivalent control

Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements

ClauseThe held text, and the evidence an assessor asks for
314.4(d)(2)
FTC Safeguards Rule
314.4(d)(2) Continuous monitoring or annual penetration testing and six-monthly vulnerability assessment

For information systems, monitoring and testing include continuous monitoring or periodic penetration testing and vulnerability assessments; absent effective continuous monitoring or other systems that detect changes creating vulnerabilities on an ongoing basis, the institution conducts annual penetration testing of its information systems, scoped each year to the relevant risks identified in the risk assessment, and vulnerability assessments including systemic scans or reviews reasonably designed to find publicly known vulnerabilities, at least every six months, whenever there are material changes to operations or business arrangements, and whenever circumstances may have a material impact on the program. Not required of institutions holding information on fewer than 5,000 consumers (314.6).

The requirement's own words: every six months

evidence an assessor asks for Continuous monitoring capability, or annual penetration test reports scoped to the risk assessment; Vulnerability assessment reports at least every six months and after material changes

Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(1)
FTC Safeguards Rule
314.4(c)(1) Access controls

Access controls, technical and where appropriate physical, are implemented and periodically reviewed to authenticate and permit access only to authorised users so as to protect against unauthorised acquisition of customer information, and to limit authorised users to the customer information they need for their duties and functions, or, for customers, to their own information.

evidence an assessor asks for Access control policy and user access reviews; Role-based permissions limiting access to need; Customer self-service access limited to own records

Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(8)
FTC Safeguards Rule
314.4(c)(8) Monitoring and logging of authorised users

Policies, procedures and controls are implemented to monitor and log the activity of authorised users and to detect unauthorised access to or use of, or tampering with, customer information by such users.

evidence an assessor asks for User activity logging on systems holding customer information; Monitoring rules or reviews that detect misuse by authorised users

There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names

ClauseThe held text, and the evidence an assessor asks for
314.4(h)
FTC Safeguards Rule
314.4(h) Written incident response plan

The institution establishes a written incident response plan designed to promptly respond to and recover from any security event materially affecting the confidentiality, integrity or availability of customer information in its control, addressing the goals of the plan, the internal processes for responding to a security event, clear roles, responsibilities and levels of decision-making authority, external and internal communications and information sharing, the requirements for remediating identified weaknesses in information systems and controls, documentation and reporting of security events and response activities, and the evaluation and revision of the plan after a security event. Not required of institutions holding information on fewer than 5,000 consumers (314.6).

evidence an assessor asks for Written incident response plan covering the seven areas; Post-incident review records

Staff are trained to recognise phishing and other social engineering, and to report a suspected incident

ClauseThe held text, and the evidence an assessor asks for
314.4(e)(1)
FTC Safeguards Rule
314.4(e)(1) Security awareness training

Personnel receive security awareness training that is updated as necessary to reflect the risks identified by the risk assessment.

evidence an assessor asks for Security awareness training records; Evidence the content was updated for identified risks

Laptops, phones and removable media that hold sensitive data are encrypted

ClauseThe held text, and the evidence an assessor asks for
314.4(c)(3)
FTC Safeguards Rule
314.4(c)(3) Encryption in transit and at rest

All customer information held or transmitted by the institution is protected by encryption both in transit over external networks and at rest; where the institution determines encryption is infeasible in either case, it may instead secure the information by effective alternative compensating controls reviewed and approved by the Qualified Individual.

evidence an assessor asks for Encryption standards and coverage for data at rest and in transit over external networks; Qualified Individual's written approval of any compensating control with the infeasibility determination

IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements

ClauseThe held text, and the evidence an assessor asks for
314.4(f)(1)
FTC Safeguards Rule
314.4(f)(1) Selection and retention of capable service providers

The institution takes reasonable steps to select and retain service providers capable of maintaining appropriate safeguards for the customer information at issue.

evidence an assessor asks for Due diligence records for service providers with access to customer information

314.4(f)(2)
FTC Safeguards Rule
314.4(f)(2) Contractual safeguards

Service providers are required by contract to implement and maintain such safeguards.

evidence an assessor asks for Contract clauses requiring safeguards for customer information

A written information security program exists, owned by a named qualified individual or officer

ClauseThe held text, and the evidence an assessor asks for
314.3(a)
FTC Safeguards Rule
314.3(a) Comprehensive written information security program

The institution develops, implements and maintains a comprehensive information security program, written in one or more readily accessible parts, containing administrative, technical and physical safeguards appropriate to its size and complexity, the nature and scope of its activities and the sensitivity of the customer information at issue, including the elements of 314.4 and reasonably designed to meet the rule's objectives: the security and confidentiality of customer information, protection against anticipated threats or hazards to its security or integrity, and protection against unauthorised access or use that could result in substantial harm or inconvenience to a customer.

evidence an assessor asks for Written information security program covering administrative, technical and physical safeguards; Mapping of the program to the 314.4 elements; Evidence of proportionality to size, complexity and data sensitivity

314.4(a)
FTC Safeguards Rule
314.4(a) Qualified Individual

The institution designates a Qualified Individual responsible for overseeing, implementing and enforcing the information security program; the individual may be employed by the institution, an affiliate or a service provider, and where a service provider or affiliate fills the role the institution retains responsibility for compliance, designates a senior member of its own personnel to direct and oversee the Qualified Individual, and requires the provider or affiliate to maintain an information security program that protects the institution to the rule's requirements.

evidence an assessor asks for Designation of the Qualified Individual with responsibilities; Where outsourced: the named senior overseer and the provider's contractual program obligation

A written risk assessment of the information systems is done and repeated periodically

ClauseThe held text, and the evidence an assessor asks for
314.4(b)(1)
FTC Safeguards Rule
314.4(b)(1) Written risk assessment

The risk assessment is written and includes criteria for evaluating and categorising the identified security risks and threats, criteria for assessing the confidentiality, integrity and availability of the institution's information systems and customer information including the adequacy of existing controls against the identified risks, and requirements describing how identified risks will be mitigated or accepted and how the program will address them. Not required of institutions holding information on fewer than 5,000 consumers (314.6).

evidence an assessor asks for Written risk assessment with categorisation criteria, CIA assessment criteria and mitigation or acceptance requirements; Inventory of identified internal and external risks

The business knows the notice its rule requires after an incident or a data breach, to whom and by when

ClauseThe held text, and the evidence an assessor asks for
314.4(j)(1)
FTC Safeguards Rule
314.4(j)(1) Notice to the FTC within 30 days of a notification event affecting 500 or more consumers

On discovering a notification event (the unauthorised acquisition of unencrypted customer information) involving the information of at least 500 consumers, the institution notifies the FTC as soon as possible and no later than 30 days after discovery, electronically on the form on the FTC's website, giving its name and contact information, a description of the types of information involved, the date or date range if determinable, the number of consumers affected or potentially affected, a general description of the event, and whether a law enforcement official has provided a written determination that public notification would impede a criminal investigation or damage national security, with a means for the FTC to contact that official.

The requirement's own words: no later than 30 days after discovery

evidence an assessor asks for Notification procedure with the 500-consumer threshold, 30-day clock and the six content items; Records of notifications made and law enforcement determinations

Questions

When does FTC Safeguards Rule apply here?
Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
Which edition is held?
16 CFR Part 314, from the eCFR text held at 1 Jan 2026
Is a gap against it a finding about the business?
No. A gap is a control the list marks partly, not in place or not sure; the page shows the requirement behind it and never rules on the business.