Finding 2024-001: Gramm-Leach Bliley Act-Student Information Security
Finding: The institution revised its information security policies in response to the revised requirements, however, these policies were not formally approved and adopted until January 2024. The policies implemented as of Januar...
Finding 2024-001: Gramm-Leach Bliley Act-Student Information Security
Finding: The institution revised its information security policies in response to the revised requirements, however, these policies were not formally approved and adopted until January 2024. The policies implemented as of January 2024 contained all required elements, however, the College’s existing information security policies as of June 9, 2023 did not contain certain elements required by regulation as agreed to in the Program Participation Agreement.
Cause: The institution was in the process of modifying existing policies to comply with federal requirements. These policies were not approved and adopted until January 2024.
Corrective Actions Taken or Planned:
1. In July 2023, Lake Forest College established a dedicated “Information Security Manager” (ISM) position to oversee the implementation and compliance of GLBA requirements. This role includes the responsibilities of the GLBA-mandated “Qualified Individual,” ensuring clear oversight and accountability for maintaining the security of customer information.
2. In September 2023, the College’s CIO and the newly appointed ISM conducted a comprehensive review of all existing IT policies, procedures, and practices. This review identified gaps in compliance and resulted in the development of new policies and substantial revisions to existing ones, ensuring comprehensive alignment with GLBA requirements.
3. From October to December 2023, the newly drafted and revised policies underwent a detailed review and collaborative refinement process, incorporating feedback from the College’s IT Governance group.
4. In January 2024, the College’s Senior Leadership Team formally approved the new and revised policies, demonstrating the institution’s commitment to full GLBA compliance and establishing a robust information security management framework.
5. Moving forward, these policies will undergo annual reviews (per policy) and updates by the CIO, ISM, and the IT Governance committee to ensure ongoing compliance with evolving regulatory requirements and to proactively address any new risks or operational changes.
Contact Person Responsible:
Eric Wacker, Information Security Manager
ewacker@lakeforest.edu
Completion Date: January 2024