The Act (GLBA), also known as the Financial Modernization Act, requires financial institutions such as banks, insurance companies, and brokerage firms, to establish administrative, technological, and physical safeguards to protect the confidentiality and integrity of customer records.
All customers of financial institutions who maintain a relationship or obtain products or services such as those listed above are protected under GLBA. A wide range of non-public personal information and personally identifiable financial information is subject to the privacy controls of GLBA.
To comply with GLBA, you must identify and assess risks, plan and implement solutions to protect sensitive information, and establish measures to continuously monitor security. The following are GLBA key controls:
- Requires logging of all access to personal information
- Requires firewalls as a core component to network security.
- Requires authentication and access control for access to sensitive information.
- Requires encryption in storage and transmission, and integrity controls.
Genie-Soft answers security concerns by keeping backup data always encrypted and immediately available. Detailed reporting gives regulators a clear idea of the chain of custody of the stored information, and rapid access, should it be required.
The data is encrypted before transmission and is always maintained in encrypted state. Access is restricted by password authentication.
Data will remain housed in the Genie-Soft customer storage areas for as long as the client retains it. Genie-Soft does not have access to the contents of the data files stored, so it is up to the client to maintain the data in a manner that is compliant with GLBA.
| Requirments |
How Genie-Soft Complies |
Preserve the records exclusively in a non-rewriteable, non-erasable format
|
Genie-Soft preserves the records exclusively in a non-rewriteable, non-erasable format with Online Backup. |
| Insure the security and confidentiality of customer information |
The data is encrypted before transmission and is always maintained in encrypted state. |
| Protect against any anticipated threats or hazards to the security or integrity of such information |
The data is housed in two separate data centers. Both the primary center and the secondary remote center are heavily secured. |
| Protect against unauthorized access to or use of such information that could result in substantial harm or inconvenience to any customer |
Access is restricted by password authentication. Access to data is date and time-stamped.
|
|