Skip to content

GLBAISO 27001 crosswalk

A control-by-control mapping between GLBA Safeguards Rule (16 CFR Part 314) and ISO/IEC 27001:2022. 9 mappings.

GLBAISO 27001RelationshipNotes
§314.4(a)
Designate a qualified individual
A.5.1
Policies for information security
RelatedCurated
Governance & security policy
§314.4(c)(1)
Access controls
A.5.15
Access control
EquivalentCurated
Access control & identity
§314.4(c)(1)
Access controls
A.5.16
Identity management
EquivalentCurated
Access control & identity
§314.4(c)(3)
Encryption of customer information
A.8.24
Use of cryptography
EquivalentCurated
Cryptography & data protection
§314.4(c)(8)
Monitoring and logging of authorized user activity
A.8.16
Monitoring activities
EquivalentCurated
Logging, monitoring & detection
§314.4(c)(8)
Monitoring and logging of authorized user activity
A.8.15
Logging
EquivalentCurated
Logging, monitoring & detection
§314.4(d)
Regularly test or monitor safeguards
A.8.8
Management of technical vulnerabilities
PartialCurated
Vulnerability management
§314.4(h)
Incident response plan
A.5.24
Information security incident management planning and preparation
PartialCurated
Incident response & breach notification
§314.4(h)
Incident response plan
A.5.26
Response to information security incidents
PartialCurated
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.