Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
FISAP Reporting DEPARTMENT OF EDUCATION
ALN #: 84.038
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not accurately report certain items relating to Perkins reporting on the FISAP report.
Criteria: 34 CFR 668.24(e)
Questioned Costs: $0
Context: The College did not properly report Perkins cash on hand information on the most recent FISAP.
Cause: Oversight by management.
Effect: FISAP cash on hand was overstated which potentially leads to the College returning more cash to the Department of Education than required.
Identification as repeat finding, if applicable: Not applicable.
Recommendation: We recommend the College work with the Department of Education to correct errors in the Perkins portion of the FISAP.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
Gramm-Leach-Bliley Act (GLBA) Compliance Significant Deficiency
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, 84.379 Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats or implemented multi-factor authentication on all systems containing personally identifiable information (PII). Additionally, the College has not sufficiently implemented continuous monitoring, such as penetration testing and vulnerability scanning, implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board that covers all areas required by GLBA.
Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA.
Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Not applicable
Recommendation: We commend the College for all work completed on GLBA. We recommend the College allocate sufficient resources to address all requirements of GLBA.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.
FISAP Reporting DEPARTMENT OF EDUCATION
ALN #: 84.038
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The College did not accurately report certain items relating to Perkins reporting on the FISAP report.
Criteria: 34 CFR 668.24(e)
Questioned Costs: $0
Context: The College did not properly report Perkins cash on hand information on the most recent FISAP.
Cause: Oversight by management.
Effect: FISAP cash on hand was overstated which potentially leads to the College returning more cash to the Department of Education than required.
Identification as repeat finding, if applicable: Not applicable.
Recommendation: We recommend the College work with the Department of Education to correct errors in the Perkins portion of the FISAP.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.