Finding Number: 2025-002 – Special Tests and Provisions – Gramm Leach Bliley Act Missing Compliance Requirements Auditor Description of Condition and Effect: The Gramm Leach Bliley Policy, in effect at time of audit, failed to explicitly state how the university addressed the implementation of multi...
Finding Number: 2025-002 – Special Tests and Provisions – Gramm Leach Bliley Act Missing Compliance Requirements Auditor Description of Condition and Effect: The Gramm Leach Bliley Policy, in effect at time of audit, failed to explicitly state how the university addressed the implementation of multi-factor authentication for anyone accessing customer information on the institution's system, conducting a periodic inventory of data that notes where it is collected, stored, or transmitted, encrypting customer information on the institution's system and when it's in transit, and anticipating and evaluating changes to the information system or network. The University did not have a review process in place for ensuring all required safeguard were written in the information security program in accordance with the Gramm Leach Bliley Act. Auditor Recommendation: We recommend that the University implement procedures to ensure that all Gramm Leach Bliley policies are met and verified by a second individual. Views of Responsible Officials and Planned Corrective Action: Beginning in fiscal year 2026, Office of Information Technology (OIT) implemented an updated policy/procedure aligned with the Gramm Leach Bliley Act (GLBA) Information Security Program requirements. The updates include: implementation of multi-factor authentication (MFA) for anyone accessing customer information on the institution's system; conducting a periodic inventory to identify where customer information is collected, stored, or transmitted; encryption of customer information both on institutional systems and during transmission; procedures to anticipate and evaluate changes to the information system or network that may impact data security. Although not fully documented, the following measures were already implemented and operational at the time of audit: Multi-Factor Authentication (MFA): MFA has been in place for all systems that access customer financial information, in accordance with FTC Safeguards Rule updates effective June 2023; Encryption: Both data at rest and in transit have been encrypted using industry-standard protocols, consistent with GLBA requirements; and Data Inventory: A periodic inventory of systems and data flows has been conducted, identifying where customer information is collected, stored, and transmitted. This is part of our broader risk assessment and information security program. Internal Audit reviewed the policy and associated processes against the applicable regulation (16 CFR 314) and concluded that we were in compliance based on the regulatory guidance available. It was not until the release of the final 2025 Compliance Supplement in late November 2025 that clarification was provided indication that all eight minimum safeguards must be explicitly documented within the written information security program. Additionally, the University has established a formal review process to ensure all GLBA safeguard policies are met. Key personnel and leadership within OIT will conduct regular compliance reviews to verify adherence and promote operational efficiency. Contact person responsible for corrective action: Jerry Todd, Chief Information Security Officer, Office of Information Technology Information Security Anticipated Completion Date: 12/1/2025