FTC Safeguards Rule (16 CFR Part 314)
What is FTC Safeguards Rule (16 CFR Part 314)?
Standards for Safeguarding Customer Information under the Gramm-Leach-Bliley Act. 16 CFR Part 314 requires FTC-regulated financial institutions to develop, implement, and maintain a comprehensive information security program with administrative, technical, and physical safeguards to protect customer information. It comprises 32 controls organised across 4 domains, and applies in the United States.
How FTC Safeguards Rule (16 CFR Part 314) maps to other frameworks
All 32 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 4 domains FTC Safeguards Rule (16 CFR Part 314) groups its controls into
Where FTC Safeguards Rule (16 CFR Part 314) overlaps with the standards you already hold
What FTC Safeguards Rule (16 CFR Part 314) means in your sector
What FTC Safeguards Rule (16 CFR Part 314) means for your job
Questions people ask about FTC Safeguards Rule (16 CFR Part 314)
What is FTC Safeguards Rule?
How many controls does FTC Safeguards Rule have?
Where does FTC Safeguards Rule apply?
What frameworks does FTC Safeguards Rule map to?
How do I get started with FTC Safeguards Rule compliance?
Query FTC Safeguards Rule (16 CFR Part 314) programmatically
FTC Safeguards Rule (16 CFR Part 314), its 32 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
FTC Safeguards Rule (16 CFR Part 314) API reference and MCP config →What FTC Safeguards Rule (16 CFR Part 314) requires, control by control
Each page carries the requirement text for one FTC Safeguards Rule (16 CFR Part 314) control and what an assessor expects to see as evidence.
- FTC-SAFEGUARDS-9-ELEMENTS 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
- FTC-SAFEGUARDS-EFFECTIVEDATE-SMALL-INSTITUTION Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)
- FTC-SAFEGUARDS-IR-PLAN-BOARDREPORTING-FTC-NOTIFICATION Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
- FTC-SAFEGUARDS-PROGRAM-QUALIFIED-INDIVIDUAL Comprehensive Information Security Program + Qualified Individual (16 CFR 314.3, 314.4(a))
- FTC-SAFEGUARDS-RISK-ASSESSMENT Written Risk Assessment (16 CFR 314.4(b))
- FTC-SAFEGUARDS-SCOPE-DEFS Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
- FTC-SAFEGUARDS-SERVICEPROVIDER-EVALUATION Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))
How ready are you for FTC Safeguards Rule (16 CFR Part 314)?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.