As part of its implementation of the GLB Act, the Federal Trade Commission (FTC) issued the Safeguards Rule under section 501(b), requiring financial institutions under FTC jurisdiction to secure customer records and information. The three main objectives of GLBA 501(b) are to:
The Federal Financial Institutions Examination Council (FFIEC), comprised of examiners from many different regulatory bodies tasked with GLBA enforcement, has created an Information Security Handbook and an exhaustive set of tests to assess compliance with the Safeguards Rule, including over 20 specifically related to intrusion prevention and detection. The security process recommended by the FFIEC comprises five key areas:
Meeting the Compliance Challenge
Sourcefire® is ideal for helping organizations comply with GLBA. Sourcefire is the most effective and efficient way to implement the best-practice security guidelines from the FFIEC. With Sourcefire, you can establish, enforce, monitor, and manage the security policies you need to ensure compliance and protect your organization from attack.
Sourcefire Supports FFIEC Security Best Practices
As the enterprise security system for your company, Sourcefire provides the following capabilities critical to network security best practices as described by the FFIEC, and necessary for GLBA compliance:
| FFIEC Guideline | The Sourcefire Approach |
| Information Security Assessment: Gather data on assets and threats to those assets | Sourcefire FireSIGHT® passive discovery provides a real-time view of what is on the network and maps those hosts against numerous known vulnerabilities. |
| Security Strategy that includes - prevention, detection, and response | Integrates IPS, NBA, and compliance technologies to provide best-of-breed technical controls satisfying all three desired control types. |
| Monitor access for policy violations and anomalous activity | Delivers continuous monitoring for security events, anomalous behavior, configuration changes and policy violations, and vulnerability exposure IDS. |
| IPS monitoring of incoming and outgoing traffic | Delivers industry-leading IPS technology satisfying FFIEC guidelines. |
| Hardening: Minimum system requirements - disallowing non-compliant activity | Enables users to implement baseline configuration policies for endpoints, subnets, and networks. The system automates monitoring and enforcement of configuration policy. |
| Security Monitoring: Policy violations, anomalous activity, security events | Delivers continuous monitoring for security events, anomalous behavior, configuration changes and policy violations, and vulnerability exposure. |
Can't find something on our site or have a question for us? Please feel free to drop us a line, or call our headquarters: 800.917.4134