Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.268, 84.033,
84.007, 84.063
Recommendation: We recommend that the Corporation review each element of GLBA to ensure compliance with all necessary requirements.
Explanation of disagreement with audit finding: There is no...
Title: Student Financial Assistance Cluster – Assistance Listing Nos. 84.038, 84.268, 84.033,
84.007, 84.063
Recommendation: We recommend that the Corporation review each element of GLBA to ensure compliance with all necessary requirements.
Explanation of disagreement with audit finding: There is no disagreement with the audit finding.
Action taken in response to finding: The College will update its Written Information Security Program to include a description of the use of a data inventory that includes how we identify and manage data, personnel, devices and facilities.
Some of these items can be found in the other documents submitted but we will merge them into our WISP. Multi-factor authentication is in use for individuals accessing sensitive information but that also was not clearly identified in the WISP and will be added.
To ensure GLBA compliance going forward, the College has contracted FRSecure to develop a risk assessment and roadmap which will do system scan for issues, an assessor will interview staff including IT, HR, Finance Leaders and others to learn more about the currentstate of overall security program. Compliance with GLBA will be part of their review. Finally,FRSecure will issue an assessment ‘Roadmap Plan’ for the department to review andpending results, implement as feasible.