10 likes | 150 Vues
The GLBA Section 501 provides essential interagency guidance for financial institutions on safeguarding consumer data. It emphasizes the importance of conducting risk assessments and implementing access controls to protect sensitive information. Institutions are advised to conduct thorough background checks on employees with access to consumer data. In the event of a data breach, institutions must assess the situation, notify federal regulators, and take necessary corrective measures, such as flagging affected accounts. Customer notifications are advised only when sensitive information is compromised and misuse is likely.
E N D
GLBA Section 501 • Interagency Guidance • Prospective measures • Conduct a risk assessment • Implement access controls • Conduct background checks on employees with access to consumer information • Retrospective measures • Assess the situation • Notify the institution’s primary federal regulator of the incident • Take steps to contain and control • Take corrective measures such as flagging accounts • Notify customers—only if sensitive customer information involved and only if conclude misuse is likely to occur