33% of GLBA you already have
NIST Cybersecurity Framework 2.0 already covers about 33% of GLBA, leaving
8 of 12 controls as genuinely new work.
Already covered 0
Likely covered 4
New work 8
No control in NIST Cybersecurity Framework 2.0
maps directly to one in GLBA. Everything counted as covered is covered because both
map to the same third standard, which is what a crosswalk is, but it is an inference rather
than a lookup.
What is genuinely new work
Nothing in NIST Cybersecurity Framework 2.0 reaches these. This is the list to scope.
GLBA-2024-2025-Pipeline-Section-1033-AIGLBA 2024-2025 Pipeline - SEC Reg S-P, CFPB Section 1033, NAIC AI Bulletin
GLBA-Coordination-FCRA-HIPAA-CCPA-SectoralGLBA Coordination with FCRA, ECOA, HIPAA, CCPA, State Privacy Laws and Sectoral Frameworks
GLBA-Crosswalk-Subordinate-Substantive-RulesGLBA Crosswalk to FTC Safeguards Rule, FTC Privacy Rule, SEC Reg S-P, Interagency Guidelines, NAIC Model Law
GLBA-Scope-FinancialInstitution-NPI-DefsGLBA Scope, Financial Institution + Nonpublic Personal Information Definitions
GLBA-Sec6802-6803-Disclosure-Notice-OptOutGLBA Section 6802-6803 - Disclosure Limits, Privacy Notice and Opt-Out
GLBA-Sec6804-6805-Rulemaking-EnforcementGLBA Section 6804-6805 - Rulemaking Authority and Enforcement Mechanism
GLBA-Sec6821-Pretexting-Prohibition-CriminalGLBA Section 6821 + 6823 - Pretexting Prohibition and Criminal Penalties
GLBA-Sectoral-Higher-Ed-Insurance-BankingGLBA Sectoral Application: Banking, Securities, Insurance, Non-Bank, Higher Education
Show the 4 you already have
GLBA-Implementation-Roadmap-ExaminationGLBA Implementation Roadmap, Examination Readiness, Roles and Tooling
GLBA-Sec6801-PolicyDuty-SafeguardingStandardGLBA Section 6801 - Privacy Obligation Policy and Safeguarding Standard
GLBA-Status-FTC-CFPB-SEC-NAIC-EnforcementGLBA Status, Enforcement Activity, FTC + CFPB + SEC + NAIC Recent Actions
GLBA-Subordinate-Rules-OperationalisationGLBA Operationalisation through FTC Safeguards Rule, Privacy Rule, SEC Reg S-P and Banking-Agency Guidelines
How this is calculated
Already covered means a mapping runs from a control in NIST Cybersecurity Framework 2.0 to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition