2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.
2024-002 (Significant Deficiency)
U.S. Department of Education
Student Financial Assistance Cluster
Gramm Leach Bliley Act (GLBA)
Criteria
Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. GLBA requires institutions to implement certain written policies.
Condition
The College does not have all required written policies, nor does the risk assessment meet the criteria that are required under GLBA.
Cause and Effect
The College has not established formal policies to ensure compliance with GLBA requirements. Resource constraints and competing priorities were contributing factors. As a result, the College is not fully compliant with GLBA requirements.
Recommendation
We recommend that the College develop and implement a comprehensive written information security program that fully addresses all minimum requirements outlined by GLBA. Additionally, the College should establish a formal written policy to provide staff with regular training on data security and privacy. A vendor management policy should also be developed and implemented to ensure third-party service providers adequately protect customer information. Finally, the College should ensure that its risk assessment process meets all GLBA criteria and that all related plans and policies are reviewed and updated annually.