Find out which rules apply to you, and how you'll prove you meet them.
Pick your industry to see which rules usually apply, which apply only in certain situations, and which framework fits. Every quarter, a Compliance Posture Report for each framework shows the evidence without you having to ask.
s90 runs the security controls that rules like SEC Regulation S-P, GLBA, the FTC Safeguards Rule, HIPAA and NIST SP 800-171 call for, keeps the documentation current, and sends a Compliance Posture Report for each framework every quarter showing the evidence. We work out which rules apply to you before anything is set up. The person in charge of compliance at your organization decides whether you're compliant.
What kind of organization are you?
For Financial Services
Your regulators expect proof. Which rules apply depends on what your firm does.
Your clients' financial information comes with rules attached: how it's protected, who can see it, and what happens if it's ever exposed.
Common for financial services firms
Add the ones that apply to your firm.
SEC Regulation S-P
Regulated
The SEC's rule for protecting your clients' personal information, including how you respond and notify clients when it's exposed (Regulation S-P, 17 CFR 248.30).
Applies if …
you're an SEC-registered adviser, broker-dealer, investment company or transfer agent.
The federal law that requires financial institutions, including firms that prepare tax returns, to protect their customers' personal information (Gramm-Leach-Bliley Act).
Applies if …
you hold customers' nonpublic personal information as a financial institution.
The FTC's rule for how non-bank financial institutions, including tax preparers, must secure customer information (FTC Safeguards Rule, 16 CFR Part 314).
Applies if …
you're a non-bank financial institution, such as a mortgage lender.
The SEC's rule for protecting your clients' personal information, including how you respond and notify clients when it's exposed (Regulation S-P, 17 CFR 248.30).
The federal law that requires financial institutions, including firms that prepare tax returns, to protect their customers' personal information (Gramm-Leach-Bliley Act).
The FTC's rule for how non-bank financial institutions, including tax preparers, must secure customer information (FTC Safeguards Rule, 16 CFR Part 314).
The Department of Defense program that verifies contractors actually meet the security requirements in their contracts (Cybersecurity Maturity Model Certification, 32 CFR Part 170).
California's privacy law, which requires reasonable security for personal information and applies to firms that meet its thresholds (California Consumer Privacy Act, as amended by the CPRA).
For Financial Services
If an examiner asked tomorrow, could your firm show the evidence?