2023-006 – Gramm-Leach-Bliley Act – Student Information Security – Material Weakness in Internal
Controls over Compliance and Material Noncompliance
Student Financial Assistance Cluster
U.S Department of Education
Federal Assistance Listing Number: 84.063, 84.268, 84.007, 84.033, 84.379
Federal Prog...
2023-006 – Gramm-Leach-Bliley Act – Student Information Security – Material Weakness in Internal
Controls over Compliance and Material Noncompliance
Student Financial Assistance Cluster
U.S Department of Education
Federal Assistance Listing Number: 84.063, 84.268, 84.007, 84.033, 84.379
Federal Program Name: Federal Pell Grant Program, Federal Direct Student Loans, Federal Supplemental
Educational Opportunity Grants, Federal Work-Study Program
107
Finding Summary: Staffing shortages have contributed to the delay in the implementation of this standard. The
absence of a well-designed and documented policy addressing the standards set forth under the act could put the
security, confidentiality, and integrity of student information at risk.
Responsible Individuals: Andrew Burke, Chief Information Officer
Corrective actions Plan: The college released a Request for Proposal (RFP) to contract with outside information
technology services to guide the development and implement a comprehensive information security program and
address staffing gaps. Outside Chief Information Officer, information security, and technical partnership
completed and contracted effective April 2024. Outside service will guide the college in the review and
implementation of procedures and policies necessary for the required controls to be completed through the
following phase:
Assessment and gap analysis of current infrastructure and cybersecurity measures.
Develop necessary policies and procedures based on NIST guidelines and GLBA requirements.
Detect and respond to ongoing training and incident response planning.
Anticipated Completion Date: to be completed by June 30, 2024