The College agrees with the finding. While many GLBA-required safeguards are operationally in place, documentation and a formal enterprise risk assessment have not been fully completed. The College will engage a qualified third party to perform a comprehensive GLBA-aligned risk assessment using a re...
The College agrees with the finding. While many GLBA-required safeguards are operationally in place, documentation and a formal enterprise risk assessment have not been fully completed. The College will engage a qualified third party to perform a comprehensive GLBA-aligned risk assessment using a recognized framework such as NIST. Based on the results, the College will document identified risks, existing safeguards, and remediation plans. Additionally, the College will formalize and update its Written Information Security Program, including policies addressing vendor management, user access controls, data transmission and destruction, change management, and data inventory. Policies will be reviewed and approved through the College’s governance process. Responsible Party: Kyle Brown, Executive Director of Technology, Jamestown Community College, kylebrown@sunyjcc.edu, 716.338.1118 Anticipated Completion Date: August 31, 2026