⚠ Experiencing a security incident right now? Urgent contact — (813) 321-2006 · Send urgent message
NaviSec Blog

GLBA and the Penetration Testing Mandate: Everything You Need to Know

2022-03-04 · NaviSec Team
GLBA and the Penetration Testing Mandate: Everything You Need to Know

Over the past decade, we have primarily become denizens of a digitalized world. Financial data remains particularly vulnerable to cyber attacks, necessitating regulations like GLBA to protect banking and financial information.

What Is GLBA?

GLBA, the Gramm-Leach-Bliley Act, was introduced in 1999 and is widely recognized as the Financial Modernization Act. The regulation applies to any business providing financial products or services to customers, overseeing how they accumulate, share, and reuse information including bank account details, social security numbers, addresses, and credit history — collectively termed personally identifiable information (PII).

Key Components of the Gramm-Leach-Bliley Act, 1999

GLBA establishes three principal rules:

The Financial Privacy Rule

Organizations must issue a clear and unambiguous notice highlighting their privacy policy before commencing business relationships with customers.

The Safeguards Rule

Financial organizations with access to non-public financial information must draft and maintain a proper cybersecurity plan outlining procedures to protect PII against phishing schemes, cyber attacks, and other data security risks. The rule mandates appointing a designated employee to oversee the security program.

The Pretexting Rule

Businesses cannot gather non-public financial information through false pretense, preventing unwanted access to personal information.

5 Recent Updates Under the GLBA

The Federal Trade Commission issued a revised final rule in December 2021 modifying the Safeguards Rule with five prime amendments.

1. More Elaborate Guidelines

The revised rule now includes more elaborate guidelines to help financial institutions frame specific aspects of an appropriate information security program. Required safeguard elements include:

  • Inventory management and classification of systems, devices, and data
  • Access controls
  • Adequate secure development practices for software and apps
  • Change management process
  • Robust encryption of information
  • Authentication
  • Monitoring and detecting unwanted access or utilization of consumer data

The rule mandates yearly penetration testing and semi-annual vulnerability assessments, or continuous monitoring in lieu of periodic assessments.

2. Exemption Provision

Entities accumulating financial data on fewer than 5,000 customers are exempt from preparing incident response plans, written risk assessments, or annual director reporting.

3. Timely Reports Required

The amended rule requires submission of timely reports to the management bodies or the board of directors.

4. Financial Institution Definition Expanded

The definition now encompasses organizations engaged in activities determined by the Federal Reserve as those incidental to financial activities, including brokers, agents, finders, collection agencies, payday lenders, and auto dealers.

5. Additional Definitions

The revised rule includes its own set of definitions for relevant terms with appropriate examples.

The revised Safeguards Rule scope is similar to that stated in the cybersecurity regulation brought forth by the New York Department of Financial Services (NYDFS).

Understanding the Penetration Testing Mandate of GLBA

Penetration testing is defined as a testing methodology wherein the assessors try to evade or defeat an information system's data security features. The revised rule explicitly requires either continuous monitoring of the safeguards implemented, or yearly penetration testing and half-yearly vulnerability scanning.

Implications of FTC's Penetration Testing Mandate on Various Industries

Unlike in the past, you cannot just rely on automated system checks, simple gap analysis, or basic vulnerability assessments. Organizations must adopt more robust testing tactics and methodologies. The FTC mandates that all forms of business entities that fall under the category of financial institutions must prepare their team to address the amended compliances.

Possible Future Transformations Under the GLBA Regulation

The FTC is considering a provision requiring financial institutions to report security breaches to the FTC, potentially becoming a concrete part of the GLBA legislation in the upcoming half of 2022 or the initial phase of 2023.

Find Proficient Penetration Testing for GLBA with NaviSec

Contact NaviSec for a free 30-minute call to learn how our penetration testing and cybersecurity expertise can help your organization achieve GLBA compliance.

Security is a journey, not a destination

Find out where you stand — free.

Take the free online risk assessment, or start with a confidential conversation about your risk, threats, and current cybersecurity posture.

Take the Free Risk Assessment
// online · confidential · no obligation