GLBA Information Security Risk Assessment Checklist Form
GLBA Information Security Risk Assessment Checklist: Use this form to assess your organization's information security risk posture as required by GLBA. All questions are tailored for a comprehensive, checklist-style risk review.
Organization Name
*
Assessment Date
*
-
Month
-
Day
Year
Date
Access Controls
*
User access is reviewed regularly
Multi-factor authentication is implemented
Inactive accounts are disabled promptly
Data Protection Measures
*
Sensitive data is encrypted in transit and at rest
Regular data backups are performed and tested
Physical security controls are in place for data storage
Incident Response Preparedness
*
Incident response plan is documented and accessible
Incident response drills are conducted regularly
Incident response team roles are defined
Employee Security Awareness Training
*
Conducted annually
Conducted semi-annually
Not conducted
Vendor Risk Management
*
Vendors are assessed for security practices
Vendor contracts include security requirements
Vendor access to data is monitored
Overall Security Posture Self-Assessment
*
Low
1
2
3
4
High
5
1 is Low, 5 is High
Risk Area Ratings
*
Rows
Not Implemented
Partially Implemented
Fully Implemented
Access Controls
1
2
3
Data Protection
4
5
6
Incident Response
7
8
9
Vendor Management
10
11
12
Additional Comments or Notes
Submit Assessment
Should be Empty: