As part of its implementation of the GLB Act, the Federal Trade Commission (FTC) issued the Safeguards Rule under section 501(b), requiring financial institutions under FTC jurisdiction to secure customer records and information. The three main objectives of GLBA 501(b) are to:

  • Ensure the security and confidentiality of customer records and information
  • Protect against any anticipated threats or hazards to the security or integrity of such records
  • Protect against unauthorized access or use of such records or information which could result in substantial harm or inconvenience to any customer.

The Federal Financial Institutions Examination Council (FFIEC), comprised of examiners from many different regulatory bodies tasked with GLBA enforcement, has created an Information Security Handbook and an exhaustive set of tests to assess compliance with the Safeguards Rule, including over 20 specifically related to intrusion prevention and detection. The security process recommended by the FFIEC comprises five key areas:

  • Information security risk assessment
  • Information security strategy
  • Implement security controls
  • Security testing
  • Monitoring and updating

Meeting the Compliance Challenge
Sourcefire® is ideal for helping organizations comply with GLBA. Sourcefire is the most effective and efficient way to implement the best-practice security guidelines from the FFIEC. With Sourcefire, you can establish, enforce, monitor, and manage the security policies you need to ensure compliance and protect your organization from attack.

Sourcefire Supports FFIEC Security Best Practices
As the enterprise security system for your company, Sourcefire provides the following capabilities critical to network security best practices as described by the FFIEC, and necessary for GLBA compliance:

 FFIEC Guideline The Sourcefire Approach
Information Security Assessment: Gather data on assets and threats to those assets Sourcefire FireSIGHT® passive discovery provides a real-time view of what is on the network and maps those hosts against numerous known vulnerabilities.  
Security Strategy that includes - prevention, detection, and response Integrates IPS, NBA, and compliance technologies to provide best-of-breed technical controls satisfying all three desired control types.
Monitor access for policy violations and anomalous activity Delivers continuous monitoring for security events, anomalous behavior, configuration changes and policy violations, and vulnerability exposure IDS.
IPS monitoring of incoming and outgoing traffic Delivers industry-leading IPS technology satisfying FFIEC guidelines.
Hardening: Minimum system requirements - disallowing non-compliant activity Enables users to implement baseline configuration policies for endpoints, subnets, and networks. The system automates monitoring and enforcement of configuration policy. 
Security Monitoring: Policy violations, anomalous activity, security events Delivers continuous monitoring for security events, anomalous behavior, configuration changes and policy violations, and vulnerability exposure.

Contact Us

Can't find something on our site or have a question for us? Please feel free to drop us a line, or call our headquarters: 800.917.4134

COLLAPSE FOOTER