Lincoln Land Community College (LLCC) acknowledges and takes seriously the audit findings presented, highlighting areas where compliance requirements were not met. These findings are crucial in ensuring the ongoing enhancement of our Information Security Program.
To address these concerns LLCC has ...
Lincoln Land Community College (LLCC) acknowledges and takes seriously the audit findings presented, highlighting areas where compliance requirements were not met. These findings are crucial in ensuring the ongoing enhancement of our Information Security Program.
To address these concerns LLCC has proactively taken several measures. In June 2022, the College appointed an IT Security and Assurance Manager, tasked with overseeing the Information Security Program and ensuring compliance with the Gramm-Leach-Bliley Act (GLBA). The Manager has played a pivotal role in developing a comprehensive roadmap to guide the continued evolution of our Information Security Program.
This roadmap specifically outlines the steps required to address the identified deficiencies, as detailed in the schedule of findings document received from the CLA. LLCC affirms its agreement with the details provided in the document and has prioritized these findings as top-level concerns in the roadmap.
In the upcoming Fiscal Year 2024 (FY24), LLCC commits to diligently implementing the roadmap, with a focused emphasis on the following key areas:
1. Implementation and Periodic Review of Access Controls: The IT Security and Assurance Manager will lead efforts to establish robust access controls and ensure regular reviews to align with compliance requirements.
2. Encryption of Customer Information: Although informal procedures are in place, a comprehensive strategy for encrypting customer information both within the College’s system and during transit will be implemented to safeguard sensitive data.
3. Security Assessment of Applications: Rigorous evaluations, assessments, and testing procedures for applications transmitting sensitive information will be instituted to bolster the overall security posture.
4. Anticipation and Evaluation of System Changes: Proactive measures will be taken to anticipate and evaluate changes to the information system or network, ensuring a proactive stance against potential vulnerabilities, including the development of a formalized change management process.
5. Regular Testing and Monitoring: LLCC is committed to instituting regular testing, monitoring, and assessing protocols for established safeguards to ensure their ongoing effectiveness.
6. Implementation of Policies and Procedures: Policies and procedures will be refined and enforced to guarantee that personnel can effectively enact the information security program.
7. Monitoring Information System Service Providers: Development of a comprehensive approach to monitoring the College’s information system service providers has been initiated and will be established to ensure compliance with security standards.
Lincoln Land Community College views this as an opportunity for continuous improvement and remains dedicated to upholding the highest standards of information security. The commitment to addressing these findings is integral to our ongoing efforts to safeguard sensitive information and maintain compliance with regulatory requirements.