Skip to content

GLBAPCI DSS crosswalk

A control-by-control mapping between GLBA Safeguards Rule (16 CFR Part 314) and PCI DSS v4.0. 7 mappings.

GLBAPCI DSSRelationshipNotes
§314.4(a)
Designate a qualified individual
Req. 12
Support information security with organizational policies and programs
RelatedCurated
Governance & security policy
§314.4(c)(1)
Access controls
Req. 7
Restrict access by business need to know
EquivalentCurated
Access control & identity
§314.4(c)(1)
Access controls
Req. 8
Identify users and authenticate access
EquivalentCurated
Access control & identity
§314.4(c)(3)
Encryption of customer information
Req. 3
Protect stored account data
EquivalentCurated
Cryptography & data protection
§314.4(c)(3)
Encryption of customer information
Req. 4
Protect cardholder data with strong cryptography during transmission
EquivalentCurated
Cryptography & data protection
§314.4(c)(8)
Monitoring and logging of authorized user activity
Req. 10
Log and monitor all access to system components and cardholder data
EquivalentCurated
Logging, monitoring & detection
§314.4(d)
Regularly test or monitor safeguards
Req. 11
Test security of systems and networks regularly
PartialCurated
Vulnerability management

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.