Skip to content

GLBANIST 800-171 crosswalk

A control-by-control mapping between GLBA Safeguards Rule (16 CFR Part 314) and NIST SP 800-171 Rev. 2. 5 mappings.

GLBANIST 800-171RelationshipNotes
§314.4(c)(1)
Access controls
3.1.1
Limit system access to authorized users
EquivalentCurated
Contrôle d'accès et identité
§314.4(c)(3)
Encryption of customer information
3.13.11
Employ FIPS-validated cryptography
EquivalentCurated
Cryptographie et protection des données
§314.4(c)(8)
Monitoring and logging of authorized user activity
3.3.1
Create and retain audit logs
EquivalentCurated
Journalisation, surveillance et détection
§314.4(d)
Regularly test or monitor safeguards
3.11.2
Scan for vulnerabilities
PartialCurated
Gestion des vulnérabilités
§314.4(h)
Incident response plan
3.6.1
Establish an incident-handling capability
PartialCurated
Réponse aux incidents et notification des violations

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.