Framework overlap

Does ISO 27019 cover GLBA?

You hold ISO 27019 and have been told to do GLBA. Here is how much overlaps, control by control.

33% of GLBA you already have

ISO 27019 already covers about 33% of GLBA, leaving 8 of 12 controls as genuinely new work.

Already covered 0 Likely covered 4 New work 8

No control in ISO 27019 maps directly to one in GLBA. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in ISO 27019 reaches these. This is the list to scope.

GLBA-2024-2025-Pipeline-Section-1033-AI
GLBA 2024-2025 Pipeline - SEC Reg S-P, CFPB Section 1033, NAIC AI Bulletin
GLBA-Coordination-FCRA-HIPAA-CCPA-Sectoral
GLBA Coordination with FCRA, ECOA, HIPAA, CCPA, State Privacy Laws and Sectoral Frameworks
GLBA-Crosswalk-Subordinate-Substantive-Rules
GLBA Crosswalk to FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P, Interagency Guidelines, NAIC Model Law
GLBA-Scope-FinancialInstitution-NPI-Defs
GLBA Scope, Financial Institution + Nonpublic Personal Information Definitions
GLBA-Sec6802-6803-Disclosure-Notice-OptOut
GLBA Section 6802-6803 - Disclosure Limits, Privacy Notice and Opt-Out
GLBA-Sec6804-6805-Rulemaking-Enforcement
GLBA Section 6804-6805 - Rulemaking Authority and Enforcement Mechanism
GLBA-Sec6821-Pretexting-Prohibition-Criminal
GLBA Section 6821 + 6823 - Pretexting Prohibition and Criminal Penalties
GLBA-Sectoral-Higher-Ed-Insurance-Banking
GLBA Sectoral Application: Banking, Securities, Insurance, Non-Bank, Higher Education
Show the 4 you already have
GLBA-Implementation-Roadmap-Examination
GLBA Implementation Roadmap, Examination Readiness, Roles and Tooling
GLBA-Sec6801-PolicyDuty-SafeguardingStandard
GLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard
GLBA-Status-FTC-CFPB-SEC-NAIC-Enforcement
GLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions
GLBA-Subordinate-Rules-Operationalisation
GLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines

How this is calculated

Already covered means a mapping runs from a control in ISO 27019 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition