standards for safeguarding customer information to their student information security policy. We
consider this finding to be a material weakness in relation to Special Tests and Provisions.
Statistical sampling was not used in making sample selections.
Corrective Action Plan: While the school has be...
standards for safeguarding customer information to their student information security policy. We
consider this finding to be a material weakness in relation to Special Tests and Provisions.
Statistical sampling was not used in making sample selections.
Corrective Action Plan: While the school has been following best practices for information
security, including the use of MFA for all online process, we did not have a fully articulated
policy and procedures relating to the GLBA. We created the appropriate documentation for a
fully articulated GLBA policy and have put into place the appropriate safeguards as specified in
that document and in the GLBA.
Responsible Person for Correction Action Plan: Craig Mitchell, President, in conjunction with
the Academic Leadership Team of SIEAM.
Implementation Date for Corrective Action Plan: The fully articulated policy was put into effect
as of May 20, 2024. Because components of the policy involve ongoing training, education, and
pressure testing of the systems, the implementation process will continue to occur and to eveolve
over the next year.