This 1999 act, also known as the Financial Modernization Act, repealed the Glass-Steagall restrictions on bank mergers.
What is the Gramm-Leach-Bliley Act (GLBA)?
This body must approve a bank or credit union's written information security program.
What is the board of directors (or an appropriate committee)?
This regulation, formally known as 23 NYCRR Part 500, took effect in March 2017.
What is the New York DFS Cybersecurity Regulation?
This crime occurs when a criminal impersonates an authorized employee to access and drain corporate bank accounts.
What is corporate account takeover?
This EU regulation provides a comprehensive framework for digital asset issuers and service providers.
What is MiCA (Markets in Crypto-Assets Regulation)?
This term describes names, addresses, and SSNs when linked to account numbers, income, or credit histories — the information GLBA protects.
What is nonpublic personal information (NPPI)?
This term describes the level of risk that remains after safeguards and controls have been implemented.
What is residual risk?
Covered entities must notify the superintendent within this many hours of determining that a cybersecurity event occurred.
What is 72 hours?
This FTC database, part of the Consumer Sentinel system, is the nation's official repository for identity theft complaints.
What is the Identity Theft Data Clearinghouse?
This EU regulation focuses on the cybersecurity and operational resilience of digital finance platforms.
What is DORA (Digital Operational Resilience Act)?
This GLBA rule limits a financial institution's disclosure of NPPI to unaffiliated third parties.
What is the Privacy Rule?
This ISO standard is recommended as a framework for building a GLBA-compliant information security program.
What is ISO 27002:2013?
This FFIEC rating system scores financial institutions from 1 (best) to 5 (worst) during IT examinations.
What is the Uniform Rating System for Information Technology (URSIT)?
This 2011 FFIEC guidance required layered security and multifactor authentication for commercial cash-management customers.
What is the Supplement to the Authentication in an Internet Banking Environment Guidance?
This international body updated its recommendations to bring virtual assets under anti-money-laundering rules.
What is the Financial Action Task Force (FATF)?
This GLBA rule addresses the protection of the confidentiality and security of customer NPPI and its proper disposal.
What is the Safeguards Rule?
This testing approach involves no prior knowledge of the system or process being examined, unlike its 'white box' counterpart.
What is black box testing?
Covered entities must retain records supporting their annual compliance certification for this many years.
What is five years?
This term describes individuals who withdraw fraudulently transferred funds and route the money overseas.
What are money mules?
Alongside the SEC and CFTC, this U.S. agency has jurisdiction over fintech and digital assets, with a focus on illicit finance.
What is FinCEN (Financial Crimes Enforcement Network)?
This is the maximum civil penalty per violation that a noncompliant financial institution faces under GLBA.
What is $100,000?
According to the FDIC's risk categories, this type of risk arises specifically from negative public opinion.
What is reputational risk?
This executive role, required under NY DFS Part 500, oversees an organization's cybersecurity program.
What is the Chief Information Security Officer (CISO)?
This 2005 supplement to the Interagency Guidelines covers response programs for unauthorized access to customer information.
What is Supplement A?
These controlled environments let fintech startups and institutions test innovative products under regulatory supervision.
What are regulatory sandboxes?