Framework overlap

Does ISO/IEC 23894:2023 cover FTC GLBA Safeguards Rule (16 CFR Part 314)?

You hold ISO/IEC 23894:2023 and have been told to do FTC GLBA Safeguards Rule (16 CFR Part 314). Here is how much overlaps, control by control.

64% of FTC GLBA Safeguards Rule (16 CFR Part 314) you already have

ISO/IEC 23894:2023 already covers about 64% of FTC GLBA Safeguards Rule (16 CFR Part 314), leaving 4 of 11 controls as genuinely new work.

Already covered 2 Likely covered 5 New work 4

What is genuinely new work

Nothing in ISO/IEC 23894:2023 reaches these. This is the list to scope.

FTC-Safeguards-2024-2025-Status
2024-2025 Implementation Status, FTC Enforcement Actions and Anticipated Amendments
FTC-Safeguards-AI-SBOM-Pipeline
AI Use, SBOM, Supply Chain and 2024-2025 Emerging Areas
FTC-Safeguards-Coord-Banking-SEC-Higher-Ed
Coordination with Banking Agencies, SEC, Higher Education Safeguards and Insurance
FTC-Safeguards-Crosswalk-NIST-ISO-SOC
Crosswalk to NIST CSF 2.0, NIST SP 800-53, ISO 27001 and SOC 2
Show the 7 you already have
FTC-Safeguards-9-Elements
9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
FTC-Safeguards-Scope-Defs
Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
FTC-Safeguards-EffectiveDate-Small-Institution
Effective Date, Small Institution Exemption and Sectoral Coordination (16 CFR 314.5, 314.6)
FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification
Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j))
FTC-Safeguards-Program-Qualified-Individual
Comprehensive Information Security Program + Qualified Individual (16 CFR 314.3, 314.4(a))
FTC-Safeguards-Risk-Assessment
Written Risk Assessment (16 CFR 314.4(b))
FTC-Safeguards-ServiceProvider-Evaluation
Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

How this is calculated

Already covered means a mapping runs from a control in ISO/IEC 23894:2023 to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition