2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications
2022-003 ? Special Tests and Provisions ? Gramm-Leach-Bliley Act, Significant Deficiency and Instance of Noncompliance Federal Assistance Listing Number(s): Multiple Federal Agency/Pass-through Entity ? Program Name: Student Financial Assistance Cluster Award Number: Multiple Award Year: Multiple Questioned Costs: Multiple Criteria: Per 16CFR 314.4, the Institute shall base an information security program on a risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assesses the sufficiency of any safeguards in place to control these risks. The risk assessment shall be written and shall include: (i) Criteria for the evaluation and categorization of identified security risks or threats faced; (ii) Criteria for the assessment of the confidentiality, integrity, and availability of information systems and customer information, including the adequacy of the existing controls in the context of the identified risks or threats faced; and (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks. Condition/Context: Per the Gramm-Leach-Bliley Act, the Institute has not completed a risk assessment as required. Cause: The Institute has not completed a risk assessment as required. Effect: Noncompliance with federal regulations. Questioned Costs: Unknown Repeat Finding: This is not a repeat finding. Recommendation: Management should complete a risk assessment to determine the organizational risks and design and implement safeguards to control identified risks. Views of Responsible Officials and Planned Corrective Actions: A risk assessment is currently in process, which will provide a holistic plan that includes Gramm-Leach-Bliley Act requirements. This assessment is scheduled for completion by December 2022, as committed in the fiscal year 2021 audit response. It is currently on track for that completion date. Once the assessment is completed, a technical suitability evaluation will be conducted to provide the most appropriate technical solutions to meet the overall needs based on the assessment findings/determinations. This will address the current deficiencies and control gaps. Responsible Person: Director of Information Technology and Communications