Skip to content

/glba-expert

GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.

shell
$ npx -y skills add GRCEngClub/claude-grc-engineering --skill glba-expert --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/glba-expert
How auto-invocation works

Context preview

The summary Claude sees to decide when to auto-load this skill.

GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.

SKILL.md

glba-expert.SKILL.md
name: glba-expert
description: GLBA expert for financial institutions. Deep knowledge of Gramm-Leach-Bliley Act including Safeguards Rule (16 CFR Part 314), Privacy Rule (16 CFR Part 313), FTC enforcement, information security program requirements, vendor management, and consumer privacy notices.
allowed-tools: Read, Glob, Grep, Write

GLBA Expert

Deep expertise in the Gramm-Leach-Bliley Act (GLBA) for financial institutions and their service providers.

Expertise Areas

GLBA Overview

**Full Name**: Gramm-Leach-Bliley Financial Services Modernization Act of 1999 **Authority**: 15 U.S.C. 6801-6809 **Also Known As**: Financial Modernization Act, GLBA **Purpose**: Protect consumers' personal financial information held by financial institutions

**Regulatory Framework**:

  • **Federal Trade Commission (FTC)**: 16 CFR Part 313 (Privacy), 16 CFR Part 314 (Safeguards)
  • **Banking Regulators**: OCC, FDIC, Federal Reserve, NCUA (banks, credit unions)
  • **Securities and Exchange Commission (SEC)**: Broker-dealers, investment advisors
  • **State Insurance Commissioners**: Insurance companies
  • **CFTC**: Commodity futures, derivatives

**Effective Dates**:

  • **Original Act**: November 12, 1999
  • **Privacy Rule**: July 1, 2001
  • **Safeguards Rule**: May 23, 2003
  • **Amended Safeguards Rule**: December 9, 2021 (compliance June 9, 2023)

Who Must Comply

**"Financial Institution" Definition**: Any institution engaged in "financial activities"

**Covered Entities**:

1. **Depository Institutions**:

  • Commercial banks
  • Savings banks
  • Credit unions
  • Thrifts

2. **Securities Firms**:

  • Broker-dealers
  • Investment advisors
  • Investment companies (mutual funds)
  • Transfer agents

3. **Insurance Companies**:

  • Life insurance
  • Property and casualty insurance
  • Insurance agents and brokers

4. **Other Financial Services**:

  • Mortgage lenders and brokers
  • Payday lenders
  • Finance companies
  • Collection agencies
  • Check cashing services
  • Wire transfer services
  • Tax preparation services (if offer RALs)
  • Real estate appraisers
  • Courier services (financial documents)
  • Credit counselors
  • Career counseling for finance jobs

**FTC Jurisdiction**: Financial institutions NOT regulated by banking/securities/insurance regulators

**Service Providers**: Must contractually commit to safeguarding customer information

Three Main Components

**1. Financial Privacy Rule (16 CFR Part 313)**:

  • Requires privacy notices
  • Gives consumers opt-out rights
  • Restricts information sharing

**2. Safeguards Rule (16 CFR Part 314)**:

  • Requires written information security program
  • Mandates specific security controls
  • Enforces vendor management

**3. Pretexting Provisions (15 U.S.C. 6821)**:

  • Prohibits obtaining customer information under false pretenses
  • Requires institutions to protect against pretexting

Safeguards Rule (16 CFR Part 314)

Overview

**Requirement**: Develop, implement, and maintain comprehensive written information security program

**Standard**: "Administrative, technical, and physical safeguards" that are "appropriate" to size, complexity, nature, and scope of activities

**Coverage**: Protects "customer information" (current and former customers)

December 2021 Amendments

**Major Changes**:

1. **Encryption** of customer information at rest and in transit (new) 2. **Multi-factor authentication** for remote access (new) 3. **Qualified Individual** designation requirement (enhanced) 4. **Annual board reporting** (new) 5. **Written incident response plan** (enhanced) 6. **Risk assessment** requirement (clarified) 7. **Service provider oversight** (enhanced) 8. **Security awareness training** (new) 9. **Monitoring and testing** requirements (enhanced)

**Compliance Deadline**: June 9, 2023

**Reason for Update**: Modernize rule for current cyber threats, align with banking regulator standards

Nine Required Elements

**1. Designate Qualified Individual**

**Requirement**: Appoint qualified individual to oversee information security program

**Qualifications**:

  • Knowledge and expertise appropriate to institution's size, complexity, activities
  • May be employee or service provider
  • Title doesn't matter (CISO, CIO, IT Director, consultant)

**Responsibilities**:

  • Oversee development, implementation, maintenance of security program
  • Report to board of directors (or equivalent) at least annually
  • Coordinate security functions across organization

**Small Institution Flexibility**: Qualified individual can have other responsibilities

**2. Risk Assessment**

**Requirement**: Written risk assessment identifying reasonably foreseeable internal and external threats

**Assessment Scope**:

  • **Internal threats**: Employees, contractors, processes, systems
  • **External threats**: Cyberattacks, environmental, third-party failures
  • **Information covered**: Customer information in all forms (electronic, paper)
  • **Systems**: All systems that collect, process, store, or transmit customer information

**Assessment Process**:

1. Identify information assets 2. Identify threats to those assets 3. Identify vulnerabilities 4. Assess likelihood of threat exploitation 5. Assess potential impact 6. Evaluate existing safeguards 7. Determine residual risk 8. Prioritize risks

**Frequency**: Periodically (at least annually recommended) and when significant changes

**3. Design and Implement Safeguards**

**Requirement**: Design and implement safeguards to control risks identified in risk assessment

**Safeguard Types**:

**Administrative**:

  • Security policies and procedures
  • Security governance structure
  • Access control policies
  • Acceptable use policies
  • Change management procedures
  • Vendor management program

**Technical**:

  • Encryption (at rest and in transit)
  • Multi-factor authentication
  • Access controls (RBAC, least privilege)
  • Network security (firewalls, IDS/IPS)
  • Endpoint protection
  • Logging and
Read more
Read it on GitHub ↗

Showing the first part of this file.

Ships withtrust-center

Open-source GRC Engineering resource for Claude. claude-grc-engineering turns technical evidence from cloud, SaaS, code, and security tools into framework-aligned findings, gap reports, remediation guidance, evidence packages, and OSCAL workflows.

Get the whole plugin, auto-invoked