academic-research-comp…
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill glba-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/glba-expertContext preview
The summary Claude sees to decide when to auto-load this skill.
GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
name: glba-expert description: GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices. allowed-tools: Read, Glob, Grep, Write
Deep expertise in the Gramm-Leach-Bliley Act (GLBA) for financial institutions and their service providers.
**Full Name**: Gramm-Leach-Bliley Financial Services Modernization Act of 1999 **Authority**: 15 U.S.C. 6801-6809 **Also Known As**: Financial Modernization Act, GLBA **Purpose**: Protect consumers' personal financial information held by financial institutions
**Regulatory Framework**:
**Effective Dates**:
**"Financial Institution" Definition**: Any institution engaged in "financial activities"
**Covered Entities**:
1. **Depository Institutions**:
2. **Securities Firms**:
3. **Insurance Companies**:
4. **Other Financial Services**:
**FTC Jurisdiction**: Financial institutions NOT regulated by banking/securities/insurance regulators
**Service Providers**: Must contractually commit to safeguarding customer information
**1. Financial Privacy Rule (16 CFR Part 313)**:
**2. Safeguards Rule (16 CFR Part 314)**:
**3. Pretexting Provisions (15 U.S.C. 6821)**:
**Requirement**: Develop, implement, and maintain comprehensive written information security program
**Standard**: "Administrative, technical, and physical safeguards" that are "appropriate" to size, complexity, nature, and scope of activities
**Coverage**: Protects "customer information" (current and former customers)
**Major Changes**:
1. **Encryption** of customer information at rest and in transit (new) 2. **Multi-factor authentication** for remote access (new) 3. **Qualified Individual** designation requirement (enhanced) 4. **Annual board reporting** (new) 5. **Written incident response plan** (enhanced) 6. **Risk assessment** requirement (clarified) 7. **Service provider oversight** (enhanced) 8. **Security awareness training** (new) 9. **Monitoring and testing** requirements (enhanced)
**Compliance Deadline**: June 9, 2023
**Reason for Update**: Modernize rule for current cyber threats, align with banking regulator standards
**1. Designate Qualified Individual**
**Requirement**: Appoint qualified individual to oversee information security program
**Qualifications**:
**Responsibilities**:
**Small Institution Flexibility**: Qualified individual can have other responsibilities
**2. Risk Assessment**
**Requirement**: Written risk assessment identifying reasonably foreseeable internal and external threats
**Assessment Scope**:
**Assessment Process**:
1. Identify information assets 2. Identify threats to those assets 3. Identify vulnerabilities 4. Assess likelihood of threat exploitation 5. Assess potential impact 6. Evaluate existing safeguards 7. Determine residual risk 8. Prioritize risks
**Frequency**: Periodically (at least annually recommended) and when significant changes
**3. Design and Implement Safeguards**
**Requirement**: Design and implement safeguards to control risks identified in risk assessment
**Safeguard Types**:
**Administrative**:
**Technical**:
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing,…
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS /…
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.