Gramm Leach Bliley Act (GLBA) Information Sheet
The Gramm Leach Bliley Act (GLBA) is a comprehensive law affecting institutions and departments that deal with financial information which includes nonpublic personal information such as addresses and phone numbers; bank and credit card account numbers; income and credit histories; and Social Security numbers.
Requirements
The GLBA includes requirements to protect the security, integrity, and confidentiality of this consumer information. To be GLBA compliant, organizations must develop, implement, and enforce a comprehensive information security program including administrative, technical, and physical safeguards as determined appropriate for the institution and data. In addition to developing their own safeguards, organizations are responsible for taking steps to ensure that their affiliates and service providers safeguard customer information in their care.
Due to these requirements, the IT Security and Policy group will be performing risk assessments on all areas that must meet GLBA compliance requirements.
Actions required
The following basic actions must be taken to satisfy GLBA requirements:
- Assess risk
- Manage and control risk
- Oversee service provider arrangements
- Adjust the program to work with new technologies.





