A regional financial technology company based in the United States provides consumer loan processing software. To maintain compliance with the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule regarding nonpublic personal information (NPI), the security team is reviewing mandatory administrative and technical safeguards. Which of the following security controls is explicitly required by the GLBA Safeguards Rule for protecting customer NPI?
- Multi-factor authentication (MFA) for any individual accessing customer information systems, alongside encryption of NPI at rest and in transit.Answer
- BAnnual submission of audited financial statements directly to the Securities and Exchange Commission (SEC) to verify internal accounting controls.
- CExecution of a Business Associate Agreement (BAA) with all third-party vendors prior to sharing protected health metrics.
- DDeployment of inline hardware security modules (HSMs) managed directly by federal regulators to handle encryption key management.
Answer
Multi-factor authentication (MFA) for any individual accessing customer information systems, alongside encryption of NPI at rest and in transit.
The correct answer highlights controls specifically required by the FTC's updated GLBA Safeguards Rule. Financial institutions must implement multi-factor authentication for any individual accessing customer information systems containing nonpublic personal information (NPI) and must encrypt customer data at rest and in transit.
Step-by-Step Solution
Key Concept
Gramm-Leach-Bliley Act (GLBA) Safeguards Rule Technical Requirements