A regional financial institution based in the United States is updating its cybersecurity policy framework to ensure full alignment with the updated Gramm-Leach-Bliley Act (GLBA) Safeguards Rule. Which of the following administrative or technical controls is explicitly mandated by this regulatory framework to protect customer nonpublic personal information (NPI)?
- Implementing multi-factor authentication for any individual accessing customer information systems containing nonpublic personal informationCevap
- BFiling a public materiality disclosure with federal market regulators within four business days of confirming a data breach incident
- CExecuting a mandatory Business Associate Agreement prior to sharing audit logs containing financial data with external service providers
- DRestricting all data storage and analytical processing exclusively to physical servers located within the state of incorporation
Cevap
Implementing multi-factor authentication for any individual accessing customer information systems containing nonpublic personal information.
The correct answer states the requirement to implement multi-factor authentication for any individual accessing customer information systems containing nonpublic personal information. Under the Federal Trade Commission (FTC) updated Safeguards Rule of the Gramm-Leach-Bliley Act (GLBA), covered financial institutions must implement specific technical controls, including mandatory multi-factor authentication, robust access controls, and data encryption to safeguard nonpublic personal information (NPI).
Adım Adım Çözüm
Anahtar Kavram
Gramm-Leach-Bliley Act (GLBA) Safeguards Rule Compliance Mandates
Tahmini Süre:1m 15s