/glba-expert
GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill glba-expert --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/glba-expert
Context preview
The summary Claude sees to decide when to auto-load this skill.
GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
SKILL.md
glba-expert.SKILL.mdname: glba-expert
description: GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
allowed-tools: Read, Glob, Grep, Write
GLBA Expert
Deep expertise in the Gramm-Leach-Bliley Act (GLBA) for financial institutions and their service providers.
Expertise Areas
GLBA Overview
**Full Name**: Gramm-Leach-Bliley Financial Services Modernization Act of 1999 **Authority**: 15 U.S.C. 6801-6809 **Also Known As**: Financial Modernization Act, GLBA **Purpose**: Protect consumers' personal financial information held by financial institutions
**Regulatory Framework**:
- **Federal Trade Commission (FTC)**: 16 CFR Part 313 (Privacy), 16 CFR Part 314 (Safeguards)
- **Banking Regulators**: OCC, FDIC, Federal Reserve, NCUA (banks, credit unions)
- **Securities and Exchange Commission (SEC)**: Broker-dealers, investment advisors
- **State Insurance Commissioners**: Insurance companies
- **CFTC**: Commodity futures, derivatives
**Effective Dates**:
- **Original Act**: November 12, 1999
- **Privacy Rule**: July 1, 2001
- **Safeguards Rule**: May 23, 2003
- **Amended Safeguards Rule**: December 9, 2021 (compliance June 9, 2023)
Who Must Comply
**"Financial Institution" Definition**: Any institution engaged in "financial activities"
**Covered Entities**:
1. **Depository Institutions**:
- Commercial banks
- Savings banks
- Credit unions
- Thrifts
2. **Securities Firms**:
- Broker-dealers
- Investment advisors
- Investment companies (mutual funds)
- Transfer agents
3. **Insurance Companies**:
- Life insurance
- Property and casualty insurance
- Insurance agents and brokers
4. **Other Financial Services**:
- Mortgage lenders and brokers
- Payday lenders
- Finance companies
- Collection agencies
- Check cashing services
- Wire transfer services
- Tax preparation services (if offer RALs)
- Real estate appraisers
- Courier services (financial documents)
- Credit counselors
- Career counseling for finance jobs
**FTC Jurisdiction**: Financial institutions NOT regulated by banking/securities/insurance regulators
**Service Providers**: Must contractually commit to safeguarding customer information
Three Main Components
**1. Financial Privacy Rule (16 CFR Part 313)**:
- Requires privacy notices
- Gives consumers opt-out rights
- Restricts information sharing
**2. Safeguards Rule (16 CFR Part 314)**:
- Requires written information security program
- Mandates specific security controls
- Enforces vendor management
**3. Pretexting Provisions (15 U.S.C. 6821)**:
- Prohibits obtaining customer information under false pretenses
- Requires institutions to protect against pretexting
Safeguards Rule (16 CFR Part 314)
Overview
**Requirement**: Develop, implement, and maintain comprehensive written information security program
**Standard**: "Administrative, technical, and physical safeguards" that are "appropriate" to size, complexity, nature, and scope of activities
**Coverage**: Protects "customer information" (current and former customers)
December 2021 Amendments
**Major Changes**:
1. **Encryption** of customer information at rest and in transit (new) 2. **Multi-factor authentication** for remote access (new) 3. **Qualified Individual** designation requirement (enhanced) 4. **Annual board reporting** (new) 5. **Written incident response plan** (enhanced) 6. **Risk assessment** requirement (clarified) 7. **Service provider oversight** (enhanced) 8. **Security awareness training** (new) 9. **Monitoring and testing** requirements (enhanced)
**Compliance Deadline**: June 9, 2023
**Reason for Update**: Modernize rule for current cyber threats, align with banking regulator standards
Nine Required Elements
**1. Designate Qualified Individual**
**Requirement**: Appoint qualified individual to oversee information security program
**Qualifications**:
- Knowledge and expertise appropriate to institution's size, complexity, activities
- May be employee or service provider
- Title doesn't matter (CISO, CIO, IT Director, consultant)
**Responsibilities**:
- Oversee development, implementation, maintenance of security program
- Report to board of directors (or equivalent) at least annually
- Coordinate security functions across organization
**Small Institution Flexibility**: Qualified individual can have other responsibilities
**2. Risk Assessment**
**Requirement**: Written risk assessment identifying reasonably foreseeable internal and external threats
**Assessment Scope**:
- **Internal threats**: Employees, contractors, processes, systems
- **External threats**: Cyberattacks, environmental, third-party failures
- **Information covered**: Customer information in all forms (electronic, paper)
- **Systems**: All systems that collect, process, store, or transmit customer information
**Assessment Process**:
1. Identify information assets 2. Identify threats to those assets 3. Identify vulnerabilities 4. Assess likelihood of threat exploitation 5. Assess potential impact 6. Evaluate existing safeguards 7. Determine residual risk 8. Prioritize risks
**Frequency**: Periodically (at least annually recommended) and when significant changes
**3. Design and Implement Safeguards**
**Requirement**: Design and implement safeguards to control risks identified in risk assessment
**Safeguard Types**:
**Administrative**:
- Security policies and procedures
- Security governance structure
- Access control policies
- Acceptable use policies
- Change management procedures
- Vendor management program
**Technical**:
- Encryption (at rest and in transit)
- Multi-factor authentication
- Access controls (RBAC, least privilege)
- Network security (firewalls, IDS/IPS)
- Endpoint protection
- Logging and
Read more
name: glba-expert description: GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices. allowed-tools: Read, Glob, Grep, Write
GLBA Expert
Deep expertise in the Gramm-Leach-Bliley Act (GLBA) for financial institutions and their service providers.
Expertise Areas
GLBA Overview
**Full Name**: Gramm-Leach-Bliley Financial Services Modernization Act of 1999 **Authority**: 15 U.S.C. 6801-6809 **Also Known As**: Financial Modernization Act, GLBA **Purpose**: Protect consumers' personal financial information held by financial institutions
**Regulatory Framework**:
- **Federal Trade Commission (FTC)**: 16 CFR Part 313 (Privacy), 16 CFR Part 314 (Safeguards)
- **Banking Regulators**: OCC, FDIC, Federal Reserve, NCUA (banks, credit unions)
- **Securities and Exchange Commission (SEC)**: Broker-dealers, investment advisors
- **State Insurance Commissioners**: Insurance companies
- **CFTC**: Commodity futures, derivatives
**Effective Dates**:
- **Original Act**: November 12, 1999
- **Privacy Rule**: July 1, 2001
- **Safeguards Rule**: May 23, 2003
- **Amended Safeguards Rule**: December 9, 2021 (compliance June 9, 2023)
Who Must Comply
**"Financial Institution" Definition**: Any institution engaged in "financial activities"
**Covered Entities**:
1. **Depository Institutions**:
- Commercial banks
- Savings banks
- Credit unions
- Thrifts
2. **Securities Firms**:
- Broker-dealers
- Investment advisors
- Investment companies (mutual funds)
- Transfer agents
3. **Insurance Companies**:
- Life insurance
- Property and casualty insurance
- Insurance agents and brokers
4. **Other Financial Services**:
- Mortgage lenders and brokers
- Payday lenders
- Finance companies
- Collection agencies
- Check cashing services
- Wire transfer services
- Tax preparation services (if offer RALs)
- Real estate appraisers
- Courier services (financial documents)
- Credit counselors
- Career counseling for finance jobs
**FTC Jurisdiction**: Financial institutions NOT regulated by banking/securities/insurance regulators
**Service Providers**: Must contractually commit to safeguarding customer information
Three Main Components
**1. Financial Privacy Rule (16 CFR Part 313)**:
- Requires privacy notices
- Gives consumers opt-out rights
- Restricts information sharing
**2. Safeguards Rule (16 CFR Part 314)**:
- Requires written information security program
- Mandates specific security controls
- Enforces vendor management
**3. Pretexting Provisions (15 U.S.C. 6821)**:
- Prohibits obtaining customer information under false pretenses
- Requires institutions to protect against pretexting
Safeguards Rule (16 CFR Part 314)
Overview
**Requirement**: Develop, implement, and maintain comprehensive written information security program
**Standard**: "Administrative, technical, and physical safeguards" that are "appropriate" to size, complexity, nature, and scope of activities
**Coverage**: Protects "customer information" (current and former customers)
December 2021 Amendments
**Major Changes**:
1. **Encryption** of customer information at rest and in transit (new) 2. **Multi-factor authentication** for remote access (new) 3. **Qualified Individual** designation requirement (enhanced) 4. **Annual board reporting** (new) 5. **Written incident response plan** (enhanced) 6. **Risk assessment** requirement (clarified) 7. **Service provider oversight** (enhanced) 8. **Security awareness training** (new) 9. **Monitoring and testing** requirements (enhanced)
**Compliance Deadline**: June 9, 2023
**Reason for Update**: Modernize rule for current cyber threats, align with banking regulator standards
Nine Required Elements
**1. Designate Qualified Individual**
**Requirement**: Appoint qualified individual to oversee information security program
**Qualifications**:
- Knowledge and expertise appropriate to institution's size, complexity, activities
- May be employee or service provider
- Title doesn't matter (CISO, CIO, IT Director, consultant)
**Responsibilities**:
- Oversee development, implementation, maintenance of security program
- Report to board of directors (or equivalent) at least annually
- Coordinate security functions across organization
**Small Institution Flexibility**: Qualified individual can have other responsibilities
**2. Risk Assessment**
**Requirement**: Written risk assessment identifying reasonably foreseeable internal and external threats
**Assessment Scope**:
- **Internal threats**: Employees, contractors, processes, systems
- **External threats**: Cyberattacks, environmental, third-party failures
- **Information covered**: Customer information in all forms (electronic, paper)
- **Systems**: All systems that collect, process, store, or transmit customer information
**Assessment Process**:
1. Identify information assets 2. Identify threats to those assets 3. Identify vulnerabilities 4. Assess likelihood of threat exploitation 5. Assess potential impact 6. Evaluate existing safeguards 7. Determine residual risk 8. Prioritize risks
**Frequency**: Periodically (at least annually recommended) and when significant changes
**3. Design and Implement Safeguards**
**Requirement**: Design and implement safeguards to control risks identified in risk assessment
**Safeguard Types**:
**Administrative**:
- Security policies and procedures
- Security governance structure
- Access control policies
- Acceptable use policies
- Change management procedures
- Vendor management program
**Technical**:
- Encryption (at rest and in transit)
- Multi-factor authentication
- Access controls (RBAC, least privilege)
- Network security (firewalls, IDS/IPS)
- Endpoint protection
- Logging and
Showing the first part of this file.
Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.
Repo: GRCEngClub/claude-grc-engineering
Other skills on trust-center.
- /academic-research-companion
Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication. Use this skill whenever the user shares a research idea, asks to "flesh out" a topic, wants sources
Open skill - /aws-inspector-expert
Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.
Open skill - /azure-inspector-expert
Expertise in evaluating Azure subscription findings from azure-inspector and mapping them to SCF controls.
Open skill - /crowdstrike-inspector-expert
Interpret CrowdStrike Falcon findings for sensor coverage, policy visibility, and host group scoping.
Open skill - /datadog-inspector-expert
Interpret datadog-inspector findings and translate Datadog monitoring, audit, log-retention, SSO, and RBAC results into GRC evidence and remediation.
Open skill - /drata-inspector-expert
Interpret drata-inspector findings generated from drata-cli workflows and turn Drata control, monitor, evidence, personnel, and integration posture into GRC action.
Open skill

