in the financial industry an important law related to privacy and data security is gramm-leach-bliley gramm-leach-bliley applies to all financial institutions in the United States which is a broadly defined concept financial institutions include not only banks and credit unions but other organizations even like a pawn shop that provide consumer loans it also includes organizations that process consumer financial information gramm-leach-bliley provides for techniques that all of these financial institutions need to follow in order to secure consumer personally identifiable information and these expectations for security are generally incorporated into something it's known as the safeguards rule the safeguards
rule has been adopted by the various regulators that would apply within your part of the financial industry so for example if you are a bank you'd look to for example the Office of the Comptroller of the currency for the particular version of the safeguards and rule that applies to you if you're a pawnshop you would look to the version of the safeguards rule that is published by the Federal Trade Commission broadly speaking the safeguards rule has five major points that it expects a financial institution to cover in its security program the first point is to
designate a coordinator so a coordinator would be a official within your organization who has the authority to implement controls and to review controls and ensure that the controls are actually in place for securing data the second point out of gramm-leach-bliley safeguards rule is that the financial institution needs to have a risk assessment so a risk assessment evaluates the risks that some breach of security could compromise the privacy of person identified will information based then on that risk assessment the organization needs to have what I call the third major point of the safeguards rule and that
is logical controls that are based on the risk assessment so the risk assessment for a pawn shop is going to be different from the risk assessment data plural applies to a large bank but in each case the bank and the pawnshop need them to implement logical logical proportionate controls that respond to the of the risks that have been identified in the risk assessment the fourth point in the safeguards rule is that the financial institution needs to ensure that it has appropriate controls with its vendors those organizations who process data on behalf of the financial institution
and so of course the way to achieve those controls would be to have an appropriate contract with the vendor have audit of the vendor have certifications from the vendor to confirm that the vendor is implementing the appropriate types of controls and may be reporting any security incidents or breaches that the vendor suffers finally the fifth point in the safeguards rule is that the financial institution needs to maintain an ongoing process for reviewing and updating its security controls hence gramm-leach-bliley is not a snapshot requirement it's not just the requirement to go snap I'm looking at my
security I've confirmed my security is good I'm done instead gramm-leach-bliley emphasizes through the safeguards rule that organizations have a never-ending requirement to be reviewing their controls and ensuring that they are secured and that their vendors have appropriate security for consumer person identify belen firm ation in order to learn more about the course that I teach at the SANS Institute you can click the link below also another link below provides more information about me and my work in private practice