How to Use This Checklist: Use this checklist to perform a quick self-assessment against each framework that applies to your business. Check each box when a requirement is substantially met. Unchecked gaps are prime candidates for your risk register and remediation roadmap.
Priority ratings: REQUIRED = mandatory per the framework; RECOMMENDED = strongly advised; BEST PRACTICE = advanced or aspirational.
Organization:
Assessor:
Assessment Date:
Next Review:
FFIEC IT Examination Handbook / GLBA Safeguards Rule
Board/senior management has formally designated information security program oversight responsibility.
Governance
REQUIRED
[ ]
A written Information Security Program (ISP) is in place, reviewed at least annually.
Governance
REQUIRED
[ ]
A formal risk assessment identifies reasonably foreseeable threats to customer information.
Risk Assessment
REQUIRED
[ ]
Risk assessment results are used to implement appropriate safeguards.
Risk Assessment
REQUIRED
[ ]
Access to customer financial data is limited to authorized personnel with a legitimate need.
Access Controls
REQUIRED
[ ]
Multi-factor authentication (MFA) is required for any system accessing customer financial data.
Access Controls
REQUIRED
[ ]
Customer financial information is encrypted in transit (TLS 1.2+) and at rest (AES-256).
Encryption
REQUIRED
[ ]
Encryption key management procedures are documented.
Encryption
REQUIRED
[ ]
Service providers with access to customer data are contractually required to implement appropriate safeguards.
Vendor Mgmt
REQUIRED
[ ]
Service provider security arrangements are reviewed periodically.
Vendor Mgmt
REQUIRED
[ ]
A written Incident Response Plan addresses customer notification within 30 days (GLBA Safeguards Rule).
Incident Response
REQUIRED
[ ]
The IRP is tested at least annually.
Incident Response
RECOMMENDED
[ ]
All employees with access to customer financial data receive security awareness training at onboarding and annually.
Training
REQUIRED
[ ]
Systems are monitored for unauthorized access to or use of customer financial data.
Monitoring
REQUIRED
[ ]
Changes to systems handling customer data follow a documented change control process.
Change Mgmt
RECOMMENDED
[ ]
Penetration tests or vulnerability assessments are conducted at least annually.
Testing
RECOMMENDED
PCI DSS v4.0
Payment Card Industry Data Security Standard
Applies to: Any business that accepts, processes, stores, or transmits credit/debit card data
☑
Requirement / Control
Category
Priority
[ ]
A firewall is installed and maintained between the internet and cardholder data environment.
Network Security
REQUIRED
[ ]
Cardholder data environment is network-segmented from other business systems.
Network Security
REQUIRED
[ ]
Primary Account Numbers (PANs) are not stored after authorization unless absolutely necessary.
Data Protection
REQUIRED
[ ]
Stored PANs are protected by strong cryptography (AES-256) if storage is required.
Data Protection
REQUIRED
[ ]
Full card data (track data, CVV, PIN) is never stored post-authorization.
Data Protection
REQUIRED
[ ]
Cardholder data transmitted over open networks is encrypted (TLS 1.2+).
Transmission
REQUIRED
[ ]
Anti-malware software is deployed on all systems regularly exposed to malware.
Anti-Malware
REQUIRED
[ ]
All systems and software are patched within one month for critical vulnerabilities.
Patch Mgmt
REQUIRED
[ ]
Access to cardholder data is restricted by business need-to-know.
Access Controls
REQUIRED
[ ]
Each user has a unique ID; shared or generic accounts are prohibited.
Access Controls
REQUIRED
[ ]
MFA is required for all non-console administrative access to the cardholder data environment.
Access Controls
REQUIRED
[ ]
Physical access to cardholder data and systems is restricted and logged.
Physical Security
REQUIRED
[ ]
All access to cardholder data and systems is logged and retained for 12 months (3 months online).
Logging
REQUIRED
[ ]
Internal and external vulnerability scans are conducted quarterly.
Vulnerability Mgmt
REQUIRED
[ ]
Annual penetration tests are conducted by a qualified assessor covering network and application layers.
Pen Testing
REQUIRED
[ ]
An information security policy is maintained, reviewed annually, and communicated to all personnel.
Policy
REQUIRED
[ ]
Card data scope is minimized — use a PCI-compliant payment gateway to avoid direct card data handling.
Scope Reduction
BEST PRACTICE
NIST Cybersecurity Framework (CSF) 2.0
National Institute of Standards and Technology — Voluntary Framework
Applies to: All organizations seeking a risk-based cybersecurity baseline; often required for government contractors
☑
Requirement / Control
Function
Priority
[ ]
Cybersecurity roles and responsibilities are formally assigned and documented.
GOVERN
REQUIRED
[ ]
Cybersecurity risk is incorporated into enterprise risk management processes.
GOVERN
REQUIRED
[ ]
A current inventory of hardware, software, and data assets is maintained.
IDENTIFY
REQUIRED
[ ]
Cybersecurity risks to assets and systems are identified and documented.
IDENTIFY
REQUIRED
[ ]
Supply chain and third-party risks are assessed and managed.
IDENTIFY
RECOMMENDED
[ ]
Access to assets is managed and limited to authorized users and devices.
PROTECT
REQUIRED
[ ]
Multi-factor authentication is used for critical systems and remote access.
PROTECT
REQUIRED
[ ]
Data at rest and in transit is protected with current encryption standards.
PROTECT
REQUIRED
[ ]
Security awareness training is provided to all personnel.
PROTECT
REQUIRED
[ ]
Configuration baselines are established and maintained for systems.
PROTECT
RECOMMENDED
[ ]
Backups of critical data are maintained, encrypted, and tested.
PROTECT
REQUIRED
[ ]
Monitoring is in place to detect anomalies, incidents, and indicators of compromise.
DETECT
REQUIRED
[ ]
Security events are logged and reviewed on a defined schedule.
DETECT
RECOMMENDED
[ ]
An incident response plan is documented and tested.
RESPOND
REQUIRED
[ ]
Incidents are reported to appropriate internal and external stakeholders per defined timelines.
RESPOND
REQUIRED
[ ]
Recovery plans for critical systems exist and are tested at least annually.
RECOVER
REQUIRED
[ ]
Lessons learned from incidents are incorporated into governance and process improvements.
RECOVER
BEST PRACTICE
ISO/IEC 27001:2022
International Standard for Information Security Management Systems (ISMS)
Applies to: Organizations seeking formal ISMS certification; often required by enterprise customers and regulated industries globally
☑
Requirement / Control
Clause / Annex
Priority
[ ]
The organization's context (internal/external issues, interested parties, scope) is documented.
Clause 4
REQUIRED
[ ]
Top management demonstrates leadership and commitment to the ISMS.
Clause 5
REQUIRED
[ ]
An Information Security Policy is established, documented, communicated, and reviewed.
Clause 5
REQUIRED
[ ]
Information security objectives are established with plans to achieve them.
Clause 6
REQUIRED
[ ]
A risk assessment process is defined and results are documented in a risk register.
Clause 6
REQUIRED
[ ]
A Statement of Applicability (SoA) identifies applicable Annex A controls.
Clause 6
REQUIRED
[ ]
Employees are aware of the ISMS, their contribution, and consequences of non-conformity.
Clause 7
REQUIRED
[ ]
ISMS documentation is controlled — creation, update, and retention of records.
Clause 7
REQUIRED
[ ]
Access control policies and procedures are implemented and enforced.
Annex A
REQUIRED
[ ]
Cryptographic controls for data protection are in place with a key management policy.
Annex A
REQUIRED
[ ]
Physical and environmental security controls protect facilities and equipment.
Annex A
REQUIRED
[ ]
Operations security includes logging, monitoring, and malware protection.
Annex A
REQUIRED
[ ]
Supplier relationships are managed with documented security requirements.
Annex A
REQUIRED
[ ]
Information security incident management procedures are established and tested.
Annex A
REQUIRED
[ ]
Business continuity management includes information security requirements.
Annex A
REQUIRED
[ ]
Internal audits of the ISMS are conducted at planned intervals.
Clause 9
REQUIRED
[ ]
Management reviews of the ISMS are conducted at planned intervals.
Clause 9
REQUIRED
[ ]
An external certification body audit has been engaged (Stage 1 and Stage 2).
Certification
BEST PRACTICE
SOC 2 (AICPA Trust Services Criteria)
System and Organization Controls 2 — Type I and Type II
Applies to: SaaS companies, cloud providers, MSPs, and any B2B company storing or processing customer data
☑
Requirement / Control
TSC Category
Priority
[ ]
Management has demonstrated a commitment to integrity and ethical values.
CC1 — Control Env.
REQUIRED
[ ]
The board (or equivalent) exercises independent oversight of internal controls.
CC1 — Control Env.
REQUIRED
[ ]
Internal and external communications about security commitments are established.
CC2 — Communication
REQUIRED
[ ]
The organization assesses risks to achieving its objectives, including fraud risk.
CC3 — Risk Assessment
REQUIRED
[ ]
Logical access controls restrict access to systems and data to authorized users.
CC6 — Logical Access
REQUIRED
[ ]
MFA is implemented for remote and privileged access.
CC6 — Logical Access
REQUIRED
[ ]
Access provisioning, modification, and deprovisioning processes are documented.
CC6 — Logical Access
REQUIRED
[ ]
User access is reviewed at least annually.
CC6 — Logical Access
REQUIRED
[ ]
The system environment is monitored for anomalies and security events.
CC7 — Sys. Operations
REQUIRED
[ ]
Security incidents are identified, reported, and responded to.
CC7 — Sys. Operations
REQUIRED
[ ]
Changes to infrastructure and software follow a documented, authorized process.
CC8 — Change Mgmt
REQUIRED
[ ]
Vendor and business partner risks are assessed and managed.
CC9 — Risk Mitigation
REQUIRED
[ ]
System availability commitments are met and performance is monitored.
A1 — Availability
REQUIRED
[ ]
Confidential information is identified and protected per confidentiality commitments.
C1 — Confidentiality
REQUIRED
[ ]
Personal data is collected, used, retained, and disposed of per privacy commitments.
P — Privacy
REQUIRED
[ ]
Controls are designed effectively (Type I) and operating effectively over 6–12 months (Type II).
Audit Scope
BEST PRACTICE
[ ]
A readiness assessment has been conducted prior to engaging the external auditor.
Readiness
BEST PRACTICE
Overall Compliance Summary
Framework
Applicable?
Items Checked
Total Items
Key Gaps / Next Steps
FFIEC / GLBA
[ ] Yes [ ] No
___ /
16
PCI DSS v4.0
[ ] Yes [ ] No
___ /
17
NIST CSF 2.0
[ ] Yes [ ] No
___ /
17
ISO/IEC 27001
[ ] Yes [ ] No
___ /
18
SOC 2
[ ] Yes [ ] No
___ /
17
Not Sure Which Frameworks Apply to You?
IronRoot Risk Consultants helps small businesses identify their compliance obligations, prioritize the highest-risk gaps, and build practical remediation roadmaps — without enterprise overhead.
IronRoot Risk Consultants | chris@ironrootrisk.com | ironrootrisk.com | This checklist is provided for informational purposes only and does not constitute legal or compliance advice.