Life & Health Insurance Exam (National Portion)Federal RegulationsHard

A life insurance agent is completing an application for a client and needs to understand the implications of the Gramm-Leach-Bliley Act (GLBA) regarding the client's information. Under GLBA's Safeguards Rule, what is an insurance company specifically required to do?

  1. APublicly disclose all internal data security breaches within 24 hours.
  2. BObtain annual audits from an independent third-party cybersecurity firm.
  3. CAppoint a Chief Privacy Officer to oversee all data sharing with nonaffiliated third parties.
  4. DDevelop, implement, and maintain a comprehensive information security program.
Show answer & explanation

Correct answer: D. Develop, implement, and maintain a comprehensive information security program.

The GLBA Safeguards Rule specifically requires financial institutions, including insurance companies, to develop, implement, and maintain a comprehensive information security program designed to protect the security, confidentiality, and integrity of customer nonpublic personal information.

Why the other options are wrong

  • A. GLBA doesn't mandate 24-hour public disclosure of all breaches; other state laws may have breach notification requirements, but this is not a GLBA Safeguards Rule specific mandate.
  • B. Annual independent audits are a good practice but not a universal, explicit mandate of the Safeguards Rule itself.
  • C. While a CPO might be part of an overall program, GLBA doesn't specifically mandate this role for all institutions.

GLBA Safeguards Rule

The GLBA Safeguards Rule requires financial institutions to implement a comprehensive information security program to protect the confidentiality and integrity of customer nonpublic personal information.

  • Mandates a written security plan.
  • Applies to customer data.
  • Covers administrative, technical, and physical safeguards.

Memory trick: GLBA Safeguards: 'SECURE' your customer data.

More Federal Regulations questions