Soru

Zorluk: OrtaRegulatory Compliance and Legal Requirements Management

A regional financial institution based in the United States is updating its cybersecurity policy framework to ensure full alignment with the updated Gramm-Leach-Bliley Act (GLBA) Safeguards Rule. Which of the following administrative or technical controls is explicitly mandated by this regulatory framework to protect customer nonpublic personal information (NPI)?

  1. Implementing multi-factor authentication for any individual accessing customer information systems containing nonpublic personal informationCevap
  2. B
    Filing a public materiality disclosure with federal market regulators within four business days of confirming a data breach incident
  3. C
    Executing a mandatory Business Associate Agreement prior to sharing audit logs containing financial data with external service providers
  4. D
    Restricting all data storage and analytical processing exclusively to physical servers located within the state of incorporation

Cevap

Implementing multi-factor authentication for any individual accessing customer information systems containing nonpublic personal information.
The correct answer states the requirement to implement multi-factor authentication for any individual accessing customer information systems containing nonpublic personal information. Under the Federal Trade Commission (FTC) updated Safeguards Rule of the Gramm-Leach-Bliley Act (GLBA), covered financial institutions must implement specific technical controls, including mandatory multi-factor authentication, robust access controls, and data encryption to safeguard nonpublic personal information (NPI).

Adım Adım Çözüm

1
Identify the target regulatory framework and governed data classification.
The target framework is the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, which governs nonpublic personal information (NPI) held by financial institutions.
Regulatory requirements vary significantly depending on whether the data is classified as PHI (HIPAA), CHD (PCI-DSS), or NPI (GLBA).
2
Evaluate the specific security control requirements under the updated GLBA Safeguards Rule.
The GLBA Safeguards Rule requires financial institutions to implement specific technical safeguards, including data encryption at rest and in transit, continuous monitoring or vulnerability assessments, robust access controls, and mandatory multi-factor authentication (MFA) for anyone accessing systems with NPI.
Understanding regulatory baseline requirements ensures correct selection of mandatory security controls.
3
Differentiate GLBA requirements from non-applicable regulatory mandates.
Four-day SEC breach reporting applies to publicly traded entities, BAAs apply to healthcare entities under HIPAA, and data localization mandates are not part of GLBA.
Eliminating distractor options based on mismatched regulatory scopes leaves the correct GLBA mandate.

Anahtar Kavram

Gramm-Leach-Bliley Act (GLBA) Safeguards Rule Compliance Mandates
Tahmini Süre:1m 15s
Bu soruyu puanla