Information Shield GLBA Solutions
The Gramm-Leach-Bliley Act of 1999The Gramm-Leach-Bliley Act of 1999 (GLBA), Title V, requires financial services organizations to insure the security and confidentiality of customer records and information. Title V has both privacy and security requirements for the protection of nonpublic personal information. Among the many requirements, organizations must adopt a "written security program" that includes administrative, technical, and physical safeguards for protecting customer information. Information Shield can save organizations thousands of dollars in their compliance efforts by helping address many of the critical aspects of GLBA.
Information Security Policies Made Easy (ISPME) provides a complete set of security policies and standards that cover both internal data security and customer data privacy. ISPME is organized around the ISO 17799 security standard, and enables organizations to quickly establish a risk-based information security policy program. Specific benefits include:
- Over 1300 pre-written security polices and standards ready to customize.
- Coverage for critical GLBA topics such as Risk Assessment, Data Classification, Data Confidentiality, Third-Party Service providers and many others.
- Complete policy coverage for the safeguards suggested in Interagency Guidelines for Establishing Standards for Protecting Customer Information.
- Policies targeted at different organizational roles (management, technical, end-user).
- Detailed implementation advice to create an effective security environment.
GLBA is very specific about the requirements for properly defining information security roles and responsibilities. According to GLBA, "the lines of authority and responsibility for development, implementation, and administration of a financial institution's information security program need to be well defined and clearly articulated."
Information Security Roles and Responsibilities Made Easy (ISRR) is the only resource available that can save your organization hours of detailed effort in developing and documenting your security organization. Information Security Roles and Responsibilities Made Easy contains:
- 40 pre-written job description with detailed security requirements for each job function.
- Pre-written organization charts that map security roles and reporting relationships.
- Security-related mission statements for various organizational departments.
- Detailed discussion on establishing security within outsourcing and third-party service providers.
- Advice on proper staffing and budgeting for security roles.
- Standard practices that have been shown to be effective at over 125 organizations around the world .
Policies and GLBA Requirements
According to GLBA, organizations must develop written policies that define the administrative, technical and physical safeguards that protect customer information. GLBA also requires that organizations provide notice of written privacy policies to customers. Beyond simply writing policies, however, organizations must establish an environment of information control that includes risk assessments, security awareness training, personnel security, physical security, incident response and disaster recovery. Information Shield publications will save organizations hundreds of development hours by providing a complete library of policies and standards that cover each of these critical areas.
Organizational Compliance with GLBA
In order to help simplify compliance with GLBA, the various Federal agencies responsible for enforcement of the Act established Interagency Guidelines Establishing Standards for Safeguarding Customer Information. These guidelines are intended to help implement industry best-practices by breaking them down into seven different steps. The following table illustrates how Information Shield publications help with each of these compliance requirements.
- Involve the Board of Directors
- Assess Risk
- Manage and Control Risk
- Oversee Service Provider Arrangements
- Adjust the Program
- Report to the Board
- Implement the Standards
For more information on using Information Shield solutions for your GLBA compliance efforts, please contact us.