{"id":1985,"date":"2023-01-31T21:00:34","date_gmt":"2023-02-01T05:00:34","guid":{"rendered":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/"},"modified":"2023-01-31T21:00:34","modified_gmt":"2023-02-01T05:00:34","slug":"the-final-countdown-safeguards-rule-glba","status":"publish","type":"post","link":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/","title":{"rendered":"The Final Countdown: Safeguards Rule (GLBA)"},"content":{"rendered":"\n<p>We wanted to issue a brief reminder to all of our clients about the upcoming due date for the new Safeguards Rule <a href=\"https:\/\/www.ecfr.gov\/current\/title-16\/chapter-I\/subchapter-C\/part-314\" target=\"_blank\" rel=\"noreferrer noopener\">requirements<\/a> that apply to Title IV institutions.  The new requirements issued by the FTC garnered headlines earlier in 2022, but we recognize compliance with the new controls may have slipped on many organizations\u2019 check lists as competing initiatives took priority. <\/p>\n\n\n\n<p>While previous guidance from the FTC contained more general language regarding cybersecurity program specifics, the guidance issued at the end of 2021 was very specific and outlined several key cybersecurity program requirements including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Designating a qualified individual to oversee the Information Security Program<\/strong>\n<ul class=\"wp-block-list\">\n<li>This \u2018individual\u2019 can be an employee, service provider, or affiliate, however, if it\u2019s either of the external options they must have oversight from an institutional employee.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Conducting a risk assessment with written results<\/strong>\n<ul class=\"wp-block-list\">\n<li>The FTC laid out some general requirements as to what is required in a risk assessment such as identifying risks, assessing controls associated with the risks, and how organizations will mitigate or accept the risks identified. <\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Specific information security program requirements include:<\/strong>\n<ul class=\"wp-block-list\">\n<li>Creating an inventory of data, personnel, systems<\/li>\n\n\n\n<li>Encrypting personal data at rest and in transit<\/li>\n\n\n\n<li>Implementing multi factor authentication to key systems<\/li>\n\n\n\n<li>Creating and maintaining a change management process<\/li>\n\n\n\n<li>Performing vulnerability scanning and <a href=\"https:\/\/www.sigcorp.com\/solutions\/cybersecurity\/penetration-testing\/\"  data-wpil-monitor-id=\"68\">penetration testing<\/a><\/li>\n\n\n\n<li>Requiring and documenting security awareness training<\/li>\n\n\n\n<li>Creating, testing, and maintaining an incident response plan<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p><strong>These requirements may seem overwhelming, however, there is still time to comply with the new SafeGuard rule by the new deadline of June 9, 2023<\/strong>  The majority of these requirements can be addressed with a third party security assessment against a known framework such as the Center for Internet Security (CIS) or NIST Cyber Security Framework (CSF).  Strata Information Group (SIG) can perform these assessments and work with your technical teams to ensure that controls are in place (or planned for implementation) that will help your organization comply with the new requirements.  <strong><a href=\"https:\/\/www.sigcorp.com\/contact\/\" target=\"_blank\" rel=\"noreferrer noopener sponsored nofollow\">Contact SIG<\/a> <\/strong>to request assistance with the Safeguards rule today.  Consultations with our security team about the legislation are free.<\/p>\n\n\n\n<p>Additional analysis for higher education is available from Educause <a href=\"https:\/\/er.educause.edu\/articles\/2021\/12\/policy-analysis-revised-highly-prescriptive-ftc-safeguards-rule\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The clock is ticking for Title IV institutions as new Safeguards Rule requirements demand action. Learn key cybersecurity steps to stay compliant before the deadline.<\/p>\n","protected":false},"author":1,"featured_media":1564,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"insight_topic":[],"class_list":["post-1985","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-insights"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.5 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The Final Countdown: Safeguards Rule (GLBA) - Strata Information Group (SIG)<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Final Countdown: Safeguards Rule (GLBA)\" \/>\n<meta property=\"og:description\" content=\"The clock is ticking for Title IV institutions as new Safeguards Rule requirements demand action. Learn key cybersecurity steps to stay compliant before the deadline.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/\" \/>\n<meta property=\"og:site_name\" content=\"Strata Information Group (SIG)\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/sigcorplive\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-01T05:00:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2023\/01\/Insight-29-scaled.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1435\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"sig-mm\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@SIGCorpLIVE\" \/>\n<meta name=\"twitter:site\" content=\"@SIGCorpLIVE\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"sig-mm\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/\"},\"author\":{\"name\":\"sig-mm\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#\\\/schema\\\/person\\\/d5f2b933f763ad7aca9b4b4786e5f55a\"},\"headline\":\"The Final Countdown: Safeguards Rule (GLBA)\",\"datePublished\":\"2023-02-01T05:00:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/\"},\"wordCount\":354,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.sigcorp.com\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/Insight-29-scaled.jpeg\",\"articleSection\":[\"Insights\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/\",\"url\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/\",\"name\":\"The Final Countdown: Safeguards Rule (GLBA) - Strata Information Group (SIG)\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.sigcorp.com\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/Insight-29-scaled.jpeg\",\"datePublished\":\"2023-02-01T05:00:34+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.sigcorp.com\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/Insight-29-scaled.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.sigcorp.com\\\/wp-content\\\/uploads\\\/2023\\\/01\\\/Insight-29-scaled.jpeg\",\"width\":2560,\"height\":1435},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/insights\\\/the-final-countdown-safeguards-rule-glba\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.sigcorp.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Final Countdown: Safeguards Rule (GLBA)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#website\",\"url\":\"https:\\\/\\\/www.sigcorp.com\\\/\",\"name\":\"Strata Information Group (SIG)\",\"description\":\"Higher Education Technology Consultants\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#organization\"},\"alternateName\":\"SIG\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.sigcorp.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#organization\",\"name\":\"Strata Information Group (SIG)\",\"alternateName\":\"SIG\",\"url\":\"https:\\\/\\\/www.sigcorp.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.sigcorp.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/sig-social.png\",\"contentUrl\":\"https:\\\/\\\/www.sigcorp.com\\\/wp-content\\\/uploads\\\/2026\\\/03\\\/sig-social.png\",\"width\":1200,\"height\":675,\"caption\":\"Strata Information Group (SIG)\"},\"image\":{\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/sigcorplive\",\"https:\\\/\\\/x.com\\\/SIGCorpLIVE\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/strata-information-group\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.sigcorp.com\\\/#\\\/schema\\\/person\\\/d5f2b933f763ad7aca9b4b4786e5f55a\",\"name\":\"sig-mm\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e272430a3104be2dd20bb8280f0c6d969182fa9d8ea0599669676228903faece?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e272430a3104be2dd20bb8280f0c6d969182fa9d8ea0599669676228903faece?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/e272430a3104be2dd20bb8280f0c6d969182fa9d8ea0599669676228903faece?s=96&d=mm&r=g\",\"caption\":\"sig-mm\"},\"sameAs\":[\"https:\\\/\\\/www.sigcorp.com\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Final Countdown: Safeguards Rule (GLBA) - Strata Information Group (SIG)","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/","og_locale":"en_US","og_type":"article","og_title":"The Final Countdown: Safeguards Rule (GLBA)","og_description":"The clock is ticking for Title IV institutions as new Safeguards Rule requirements demand action. Learn key cybersecurity steps to stay compliant before the deadline.","og_url":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/","og_site_name":"Strata Information Group (SIG)","article_publisher":"https:\/\/www.facebook.com\/sigcorplive","article_published_time":"2023-02-01T05:00:34+00:00","og_image":[{"width":2560,"height":1435,"url":"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2023\/01\/Insight-29-scaled.jpeg","type":"image\/jpeg"}],"author":"sig-mm","twitter_card":"summary_large_image","twitter_creator":"@SIGCorpLIVE","twitter_site":"@SIGCorpLIVE","twitter_misc":{"Written by":"sig-mm","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/#article","isPartOf":{"@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/"},"author":{"name":"sig-mm","@id":"https:\/\/www.sigcorp.com\/#\/schema\/person\/d5f2b933f763ad7aca9b4b4786e5f55a"},"headline":"The Final Countdown: Safeguards Rule (GLBA)","datePublished":"2023-02-01T05:00:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/"},"wordCount":354,"commentCount":0,"publisher":{"@id":"https:\/\/www.sigcorp.com\/#organization"},"image":{"@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2023\/01\/Insight-29-scaled.jpeg","articleSection":["Insights"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/","url":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/","name":"The Final Countdown: Safeguards Rule (GLBA) - Strata Information Group (SIG)","isPartOf":{"@id":"https:\/\/www.sigcorp.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/#primaryimage"},"image":{"@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2023\/01\/Insight-29-scaled.jpeg","datePublished":"2023-02-01T05:00:34+00:00","breadcrumb":{"@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/#primaryimage","url":"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2023\/01\/Insight-29-scaled.jpeg","contentUrl":"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2023\/01\/Insight-29-scaled.jpeg","width":2560,"height":1435},{"@type":"BreadcrumbList","@id":"https:\/\/www.sigcorp.com\/insights\/the-final-countdown-safeguards-rule-glba\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sigcorp.com\/"},{"@type":"ListItem","position":2,"name":"The Final Countdown: Safeguards Rule (GLBA)"}]},{"@type":"WebSite","@id":"https:\/\/www.sigcorp.com\/#website","url":"https:\/\/www.sigcorp.com\/","name":"Strata Information Group (SIG)","description":"Higher Education Technology Consultants","publisher":{"@id":"https:\/\/www.sigcorp.com\/#organization"},"alternateName":"SIG","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sigcorp.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.sigcorp.com\/#organization","name":"Strata Information Group (SIG)","alternateName":"SIG","url":"https:\/\/www.sigcorp.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sigcorp.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2026\/03\/sig-social.png","contentUrl":"https:\/\/www.sigcorp.com\/wp-content\/uploads\/2026\/03\/sig-social.png","width":1200,"height":675,"caption":"Strata Information Group (SIG)"},"image":{"@id":"https:\/\/www.sigcorp.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/sigcorplive","https:\/\/x.com\/SIGCorpLIVE","https:\/\/www.linkedin.com\/company\/strata-information-group\/"]},{"@type":"Person","@id":"https:\/\/www.sigcorp.com\/#\/schema\/person\/d5f2b933f763ad7aca9b4b4786e5f55a","name":"sig-mm","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/e272430a3104be2dd20bb8280f0c6d969182fa9d8ea0599669676228903faece?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/e272430a3104be2dd20bb8280f0c6d969182fa9d8ea0599669676228903faece?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e272430a3104be2dd20bb8280f0c6d969182fa9d8ea0599669676228903faece?s=96&d=mm&r=g","caption":"sig-mm"},"sameAs":["https:\/\/www.sigcorp.com"]}]}},"_links":{"self":[{"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/posts\/1985","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/comments?post=1985"}],"version-history":[{"count":0,"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/posts\/1985\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/media\/1564"}],"wp:attachment":[{"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/media?parent=1985"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/categories?post=1985"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/tags?post=1985"},{"taxonomy":"insight_topic","embeddable":true,"href":"https:\/\/www.sigcorp.com\/wp-json\/wp\/v2\/insight_topic?post=1985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}