Finding 2022-001: Gramm-Leach Bliley Act (GLBA) Recommendation: The University should perform and document an annual risk assessment to determine the University's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the University should have at least one risk...
Finding 2022-001: Gramm-Leach Bliley Act (GLBA) Recommendation: The University should perform and document an annual risk assessment to determine the University's specific risks relevant to protecting consumer nonpublic personal information. At a minimum, the University should have at least one risk statement aligned or referenced to each of the three required areas noted in the GLBA law at 16 CFR 314.4 (b). Finally, the University should identify and document at least one safeguard (i.e., control) for each of the risks identified and document in the risk assessment. Each control should be aligned or referenced to the risk(s) to which the safeguard applies. Action Taken: The University has taken the following steps to address the risks identified during the audit: 1. Employee Training and Management a. The University deployed the Knowbe4 Security Awareness Program to all full time staff. The program provides training for managing user data and email messages. To date the University has distributed two campaigns to combat email phishing attempts. 2. Information systems, including network and software design, as well as information processing, storage, transmission and disposal a. The University has formulated a digital transformation strategy to reduce on premises systems and applications. All the critical business systems are hosted at a colocation or are SaaS solutions. b. The University performs backups of all on premises systems using technology that creates immutable storage. c. The University leverages the cybersecurity experience of resellers and manufacturers to ensure all core network technology is installed and configured to minimize any attack surface. 3. Detecting, preventing, and responding to attacks, intrusions, or other systems failures and document safeguards for identified risks as required by the Gramm-Leach Bliley Act (GLBA). a. The University has deployed a redundant pair of Fortinet Advanced Firewalls to monitor and block traffic with suspicious payloads. b. The University has updated to the latest version of Microsoft Advanced Threat Defender to serve as optimal end point protection for managing email traffic. c. The University contracted with the Cybersecurity and Infrastructure Security Agency (CISA) to perform vulnerability scans and penetration testing. The IT department evaluates the weekly reports and remediates highlighted deficiencies. d. The University has removed all admin rights from school managed computers, eliminating the ability to install local software. e. The University has deployed an updated VPN client to all school managed computers providing a secure tunnel for access network services. f. The University manages web browsers of all school managed computers. The University will take the results of the security assessment that was completed and draft the GLBA policy in conformity with the DOE requirements by June 2023. Responsible Individual for Corrective Action: Chief Information Officer ? Gregg Chottiner Anticipated Completion Date: June 30, 2023