Skip to content
Tidebreak Advisory

Vertical crosswalk · Financial services

The Safeguards Rule your CCO carries, mapped to the controls your examiner recognizes.

CIS Controls v8.1.2 × FTC Safeguards Rule (16 CFR Part 314)

Introduction and methodology

The FTC Safeguards Rule does not read like a technical standard. The §314.4(b) written risk assessment asks the firm to identify reasonably foreseeable risks. The eight safeguard elements at §314.4(c) name the outcomes the qualified individual has to be able to defend for access control, encryption, multi-factor authentication, and the rest. The Rule describes the safeguard a firm must have in place; it does not prescribe the controls that satisfy it.

This crosswalk is element-first. Each row names a Safeguards Rule element and the obligation it carries, then lists the CIS Controls v8.1.2safeguards that support that obligation in a firm's IT environment. CIS Controls v8.1.2is the security framework a firm's cyber-insurance carrier, outside auditor, and examiner already recognize. The mapping is how a control finding lands in a compliance-program artifact the qualified individual can sign and an examiner can read.

The mapping is directional, not exhaustive. A safeguard listed against an element supports compliance with that element; it does not, on its own, establish it. Where no meaningful mapping exists, the absence is information. The crosswalk is a reference tool, not an opinion.

The crosswalk

Ten representative element rows. The FTC Safeguards Rule element is the organizing column; the CIS Controls v8.1.2 safeguards are the supporting column.

FTC Safeguards Rule elements mapped to supporting CIS Controls v8.1.2 safeguards.
FTC Safeguards Rule elementObligationSupporting CIS Controls v8.1.2 safeguards
16 CFR 314.3; 314.4Written information security programMaintain a written program with administrative, technical, and physical safeguards appropriate to the firm's size, complexity, and the sensitivity of customer information.17.1 Designate Incident-Handling Personnel · program governance across Controls 3, 5, 6, 8
16 CFR 314.4(a)Qualified individualDesignate a single qualified individual responsible for overseeing, implementing, and enforcing the program.17.1 Designate Incident-Handling Personnel · 14.9 Role-Specific Security Training
16 CFR 314.4(b)Written risk assessmentConduct and document a written risk assessment that identifies reasonably foreseeable internal and external risks, and base the program's safeguards on it.3.1 Data Management Process · 3.7 Data Classification Scheme · 1.1 Enterprise Asset Inventory · 2.1 Software Inventory · 3.2 Data Inventory
16 CFR 314.4(c)(1)Access controlsPlace access controls on information systems to authenticate and permit access only to authorized users, and limit access to customer information to those who need it.6.1 Access Granting Process · 6.2 Access Revoking Process · 6.8 Role-Based Access Control · 3.3 Data Access Control Lists
16 CFR 314.4(c)(2)EncryptionEncrypt customer information at rest and in transit, or document a qualified-individual-approved compensating control where encryption is infeasible.3.10 Encrypt Sensitive Data in Transit · 3.11 Encrypt Sensitive Data at Rest
16 CFR 314.4(c)(5)Multi-factor authenticationRequire multi-factor authentication for any individual accessing any information system, unless the qualified individual approves an equivalent control in writing.6.3 MFA for Externally-Exposed Applications · 6.4 MFA for Remote Network Access · 6.5 MFA for Administrative Access
16 CFR 314.4(e)Security awareness trainingProvide security awareness training to personnel and verify that key personnel maintain current knowledge of changing threats and countermeasures.14.1 Security Awareness Program · 14.3 Train on Authentication Best Practices · 14.9 Role-Specific Security Training
16 CFR 314.4(f)Service-provider oversightSelect and retain service providers capable of maintaining appropriate safeguards, and require those safeguards by contract; periodically assess providers based on the risk they present.15.1 Inventory of Service Providers · 15.2 Service Provider Management Policy · 15.4 Service Provider Contracts Include Security Requirements
16 CFR 314.4(h)Incident responseEstablish a written incident-response plan addressing roles, internal processes, communication, remediation, and post-incident evaluation.17.1 Designate Incident-Handling Personnel · 17.4 Incident Response Process · 17.7 Routine Incident Response Exercises
16 CFR 314.4(i)Reporting to the boardHave the qualified individual report in writing, at least annually, to the board or a senior officer on the program's status and material matters.17.1 Designate Incident-Handling Personnel · governance reporting across the program

Worked examples

Two representative findings drawn from financial-services assessments, each dual-mapped to a CIS Controls v8.1.2 safeguard set and the FTC Safeguards Rule element it implicates.

Worked example

Critical

"Industry best practices" ISP language with no specific control map

Security mapping

CIS Safeguards 3.1 · 3.7

Professional-standard mapping

FTC Safeguards §314.4(b) Written Risk Assessment

Evidence 2, 8, 14

The RIA's written information security program referenced "industry best practices" and "reasonable safeguards" but mapped no specific controls to the Safeguards Rule's elements. The annual written risk assessment under §314.4(b) had been performed by the firm's IT vendor, not the qualified individual, and was not signed. No documented basis for an encryption compensating control under §314.4(c)(2) existed.

Recommended action. Have the qualified individual own and sign the written risk assessment, map a specific control to each Safeguards Rule element, and document the basis for any compensating control approved in place of encryption.

Worked example

Moderate

Service-provider safeguards not required by contract or assessed on a cadence

Security mapping

CIS Safeguards 15.1 · 15.4

Professional-standard mapping

FTC Safeguards §314.4(f) Service-Provider Oversight

Evidence 17, 23

The firm relied on an outsourced IT provider and a custodial data feed, but no inventory of service providers existed, contracts did not require the providers to maintain specific safeguards, and no periodic assessment had been performed since onboarding. The §314.4(f) element asks the firm to select capable providers, require safeguards by contract, and assess them on the risk they present.

Recommended action. Build and maintain an inventory of service providers, add safeguard requirements to provider contracts, and assess each provider periodically against the risk it presents, with the review recorded.

Regulatory variation

The FTC Safeguards Rule is the federal baseline for many RIAs and broker-dealers, but it is not the only regime a firm carries. SEC Reg S-P and, for New York-connected firms, NYDFS 23 NYCRR 500 layer obligations on top of the Part 314 elements this crosswalk maps. A firm should map to every applicable regime before relying on this crosswalk.

  • SEC Reg S-P (2024 amendments). The amended rule adds an incident-response program and a customer-notification obligation with tiered compliance dates, which means the firm must be able to detect, respond to, and disclose a compromise on a defined clock, beyond protecting customer information.
  • NYDFS 23 NYCRR 500 (Second Amendment). For New York-licensed firms, the second amendment adds governance expectations, senior-officer certification, and continuous-monitoring requirements that go past the federal baseline, including a written program approved by the board or a senior officer and periodic written risk assessment.
  • Firm scope. Whether a given firm is reached by the Safeguards Rule, Reg S-P, NYDFS 500, or some combination depends on its registrations, customers, and jurisdiction. A firm should confirm which regimes apply to it before relying on this crosswalk.

Disclaimers

  1. Not legal advice. This document does not constitute legal advice. Firm leadership and the firm's counsel make all legal and compliance determinations.
  2. Not the written risk assessment. Tidebreak does not perform the §314.4(b) written risk assessment that the firm's qualified individual is obligated to sign. Our findings inform that assessment; they do not replace it.
  3. Not your compliance consultant or examiner. Tidebreak performs assessments, not attest audits, and is not your compliance consultant or SEC examiner. This crosswalk is a reference mapping, not an opinion, certification, or attestation.
  4. Framework currency. Framework references are to the editions identified in this document: CIS Controls v8.1.2 (2024), NIST CSF 2.0 (2024), and the FTC Safeguards Rule at 16 CFR Part 314 as amended 2023. SEC Reg S-P (2024 amendments) and NYDFS 23 NYCRR 500 (Second Amendment) overlays are noted in the Regulatory Variation section where they apply. Frameworks are reviewed annually and on material changes.
  5. Distribution. This document is provided for the use of the client and its designated advisors. Further distribution, in whole or part, requires written permission.

Tidebreak performs independent assessments.