2023-002 Material Weakness: Gramm-Leach-Bliley Act (GLBA) (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268)
Name of Contact Person
Casey Reagan, Registrar, and Chris Summey, Head of our IT Department, are the Designated Employees in charge of overseeing the GLBA polic...
2023-002 Material Weakness: Gramm-Leach-Bliley Act (GLBA) (U.S. Department of Education, William D. Ford Direct Loan Program, ALN #84.268)
Name of Contact Person
Casey Reagan, Registrar, and Chris Summey, Head of our IT Department, are the Designated Employees in charge of overseeing the GLBA policy.
Corrective Action Planned
During the audit, it was noted that Tusculum did not fully address all of the requirements as described by 16 CFR 314.4. In addition, the application of the comprehensive information security program was not effectively administered by the University for the 2023 year. In fall 2023, IT, the Registrar, and the Director of Financial Aid met to discuss making sure that all of the new pieces of the GLBA policy were being implemented properly. In December of 2023, IT began the latest vulnerability scan and risk assessment to be in compliance with the risk assessment requirements of the GLBA Policy. This assessment should be completed by the end of spring 2024. The University is also working on updating its GLBA policies and procedures to align with the GLBA Policy.
Anticipated Completion Date
This process is currently ongoing and it is the University's goal to have ongoing GLBA policies updated and the risk assessment completed before the end of the 2023-2024 academic year.