← GLBA · Safeguards Rule (16 CFR 314)

314.4(g) — Evaluate and adjust the program

medium policy-governancerisk-assessment

Requirement

The information security program is evaluated and adjusted in light of testing and monitoring results, material changes to operations or business arrangements, the results of risk assessments, or any other circumstances that may have a material impact on it.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
information security programsecurity programsecurity programmewisp
Required element 2 — any one of
evaluat…adjust…update…review…revis…
Supporting terms — specificity signals
314.4(g)material changetesting results

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
NIST CSF 2.0 GV.OC-01 Organisational mission is understood and informs risk management policy-governance risk-assessment
NIST CSF 2.0 GV.RM-01 Risk management objectives are established and agreed risk-assessment policy-governance
COPPA 312.8 Written information security program for children's data policy-governance risk-assessment
GDPR Art.5(2) Accountability policy-governance
GDPR Art.24 Responsibility of the controller policy-governance
GDPR Art.31 Cooperation with the supervisory authority policy-governance
GDPR Art.35 Data protection impact assessment risk-assessment
GDPR Art.36 Prior consultation with the supervisory authority risk-assessment