Life & Health Insurance Exam (National Portion)Federal RegulationsHard
A life insurance agent is completing an application for a client and needs to understand the implications of the Gramm-Leach-Bliley Act (GLBA) regarding the client's information. Under GLBA's Safeguards Rule, what is an insurance company specifically required to do?
- APublicly disclose all internal data security breaches within 24 hours.
- BObtain annual audits from an independent third-party cybersecurity firm.
- CAppoint a Chief Privacy Officer to oversee all data sharing with nonaffiliated third parties.
- DDevelop, implement, and maintain a comprehensive information security program.
Show answer & explanationAnswer & explanation
Correct answer: D. Develop, implement, and maintain a comprehensive information security program.
The GLBA Safeguards Rule specifically requires financial institutions, including insurance companies, to develop, implement, and maintain a comprehensive information security program designed to protect the security, confidentiality, and integrity of customer nonpublic personal information.
Why the other options are wrong
- A. GLBA doesn't mandate 24-hour public disclosure of all breaches; other state laws may have breach notification requirements, but this is not a GLBA Safeguards Rule specific mandate.
- B. Annual independent audits are a good practice but not a universal, explicit mandate of the Safeguards Rule itself.
- C. While a CPO might be part of an overall program, GLBA doesn't specifically mandate this role for all institutions.
GLBA Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a comprehensive information security program to protect the confidentiality and integrity of customer nonpublic personal information.
- Mandates a written security plan.
- Applies to customer data.
- Covers administrative, technical, and physical safeguards.
Memory trick: GLBA Safeguards: 'SECURE' your customer data.