Question

Difficulty: MediumRegulatory Compliance and Legal Requirements Management

A regional financial technology company based in the United States provides consumer loan processing software. To maintain compliance with the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule regarding nonpublic personal information (NPI), the security team is reviewing mandatory administrative and technical safeguards. Which of the following security controls is explicitly required by the GLBA Safeguards Rule for protecting customer NPI?

  1. Multi-factor authentication (MFA) for any individual accessing customer information systems, alongside encryption of NPI at rest and in transit.Answer
  2. B
    Annual submission of audited financial statements directly to the Securities and Exchange Commission (SEC) to verify internal accounting controls.
  3. C
    Execution of a Business Associate Agreement (BAA) with all third-party vendors prior to sharing protected health metrics.
  4. D
    Deployment of inline hardware security modules (HSMs) managed directly by federal regulators to handle encryption key management.

Answer

Multi-factor authentication (MFA) for any individual accessing customer information systems, alongside encryption of NPI at rest and in transit.
The correct answer highlights controls specifically required by the FTC's updated GLBA Safeguards Rule. Financial institutions must implement multi-factor authentication for any individual accessing customer information systems containing nonpublic personal information (NPI) and must encrypt customer data at rest and in transit.

Step-by-Step Solution

1
Identify the governing regulatory framework and target data classification in the scenario.
The regulatory framework is the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, which governs nonpublic personal information (NPI) held by financial institutions.
Different regulations mandate distinct technical controls based on data type and sector.
2
Evaluate the technical and administrative requirements specified under the GLBA Safeguards Rule.
The updated GLBA Safeguards Rule explicitly mandates multi-factor authentication (MFA) for all individuals accessing systems with NPI and requires encryption of NPI both at rest and in transit.
GLBA updated its requirements to establish concrete baseline controls including MFA, data encryption, and access monitoring.
3
Distinguish GLBA mandates from requirements of other regulatory frameworks like SOX or HIPAA.
Financial audit filings apply to SOX, and BAAs apply to HIPAA, leaving multi-factor authentication and NPI encryption as the correct GLBA technical mandate.
Recognizing regulatory scope prevents misapplication of compliance controls.

Key Concept

Gramm-Leach-Bliley Act (GLBA) Safeguards Rule Technical Requirements
Rate this question