Key facts
- An investment advisory company is a financial institution under the FTC Safeguards Rule (16 CFR 314.2(h)(2)(xii)), and the rule reaches the financial institutions over which the FTC has enforcement jurisdiction under the Gramm-Leach-Bliley Act (314.2(s)), which is where a state-registered adviser sits.
- 16 CFR 314.4 lists the elements of the required information security program in paragraphs (a) through (j): qualified individual, risk assessment, safeguards, testing, training, service providers, evaluation, incident response plan, annual report, and FTC notification.
- Multi-factor authentication is required for any individual accessing any information system unless the qualified individual approves an equivalent or stronger control in writing (314.4(c)(5)), and customer information must be encrypted in transit over external networks and at rest (314.4(c)(3)).
- A firm maintaining customer information on fewer than 5,000 consumers is exempt from 314.4(b)(1), (d)(2), (h), and (i) under 16 CFR 314.6.
- A notification event involving the information of at least 500 consumers must be reported to the FTC as soon as possible and no later than 30 days after discovery (314.4(j)); discovery is the first day the event is known to any employee, officer, or agent other than the person committing it.
Answer for your firm
Fourteen questions. The worksheet sorts each element of 16 CFR 314.4 into in place, gap, or exempt as you answer. Everything happens in your browser; nothing is stored or sent.
The worksheet
What the worksheet does not decide
- Whether the FTC rule or a state regulator's rule governs the firm. State-registered advisers answer to their state securities regulator, and many states have adopted their own cybersecurity requirements that sit alongside the federal rule.
- Whether a particular control is adequate. The rule requires safeguards appropriate to the firm's size, complexity, and the sensitivity of the information; the worksheet records whether each element exists, not whether it is sufficient.
- Notice to affected individuals after a breach. The Safeguards Rule's notification runs to the FTC; notice to clients comes from state breach-notification laws, which vary by state and by where each client lives.
- Whether a vendor is a service provider. The service-provider inventory applies the definition, which the Safeguards Rule (16 CFR 314.2(r)) states in nearly the same words as Regulation S-P.
Questions
Does Regulation S-P apply to a state-registered adviser?
No. Regulation S-P's safeguards and breach-notification provisions apply to SEC-registered investment advisers, brokers, dealers, funding portals, and registered investment companies. An adviser registered only with a state is a financial institution under the FTC's jurisdiction and follows the FTC Safeguards Rule, 16 CFR part 314, plus its state's own rules.
What does the small-firm exemption cover?
Under 16 CFR 314.6, a financial institution that maintains customer information on fewer than 5,000 consumers is exempt from the written risk assessment (314.4(b)(1)), the continuous monitoring or annual penetration testing and semiannual vulnerability assessment requirement (314.4(d)(2)), the written incident response plan (314.4(h)), and the annual written report (314.4(i)). Every other element still applies, including multi-factor authentication, encryption, training, and service-provider oversight.
When must a state-registered adviser notify the FTC of a breach?
When a notification event, the unauthorized acquisition of unencrypted customer information, involves the information of at least 500 consumers, the firm must notify the FTC as soon as possible and no later than 30 days after discovery (16 CFR 314.4(j)). The notice is filed on the FTC's form. Notice to affected individuals comes from state breach laws, which the Safeguards Rule does not displace.
Does this page store my answers?
No. The answers are used only in your browser to sort the elements and build the worksheet. Nothing is transmitted, saved, or measured. Print the worksheet before leaving the page.
Primary sources
General information from ValaisOS LLC, not legal, compliance, tax, or investment advice. Confirm requirements for your firm with counsel. See Terms of Use.