Kayne McGladrey on What Businesses other than Banks Need to Know about Gramm-Leach-Bliley [Podcast]




Compliance Perspectives show

Summary: <a href="https://www.complianceandethics.org/wp-content/uploads/2015/02/turteltaub-adam-200x200.jpg"></a>By Adam Turteltaub<br> <br> The <a href="https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act">Gramm-Leach-Bliley Act</a> (GLBA) is typically referred to in the context of financial institutions. It requires offerers of consumer financial products to explain how they share information and protect sensitive data.<br> <br> It’s not, however, only banks that fall under GLBA’s umbrella. New rules will affect retailers offering credit terms to their customers, higher education institutions that administer federal student aid and others a well, explains <a href="https://www.linkedin.com/in/kaynemcgladrey/">Kayne McGladrey</a>, Field CISO for <a href="https://hyperproof.io/">Hyperproof</a>.<br> <br> The FTC, has set <a href="https://www.ftc.gov/business-guidance/blog/2022/11/compliance-deadline-certain-revised-ftc-safeguards-rule-provisions-extended-june-2023">June 2023</a> as the deadline for compliance with the revised GLBA Safeguards Rule. It requires that affected organizations:<br> <br> * Have a qualified individual to implement and enforce an information security plan<br> * Conduct a periodic cybersecurity risk assessment<br> * Implement cybersecurity controls to manage those risk<br> * Document who has access to customer data<br> * Assess the risks of applications that can access the data<br> * Securely destroy old data<br> * Periodically test the controls to verify their effectiveness<br> <br> In addition, staff needs to be trained, there must be a written incidence response plan and ongoing testing.<br> <br> It is a considerable commitment, Kayne points out, but since it overlaps with the requirements of the European General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA), many organizations may already have significant structures in place.<br> <br> Even so, it’s important to conduct a gap analysis, he advises, to ensure all the requirements are being met.<br> <br> Listen in to learn more about what Gramm-Leach-Bliley now requires for your organization.