Corrective Action Plan: In response to the findings related to the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule compliance at [Institution Name], we have developed the following Corrective Action Plan to address identified deficiencies and strengthen our information security program.
• Corrective A...
Corrective Action Plan: In response to the findings related to the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule compliance at [Institution Name], we have developed the following Corrective Action Plan to address identified deficiencies and strengthen our information security program.
• Corrective Action: By December 31, 2025, Rockland Community College will complete a comprehensive risk assessment of all systems handling covered financial and student information. Risk assessments will be conducted annually thereafter, with updates documented and reviewed by the Information Security Officer (ISO).
• Corrective Action: A revised Written Information Security Program (WISP) will be finalized by July 31, 2026. It will outline administrative, technical, and physical safeguards, as well as roles and responsibilities for maintaining compliance.
• Corrective Action: A Qualified Individual responsible for overseeing and enforcing the Safeguards Rule compliance program will be designated by December 31, 2025.
• Corrective Action: All vendor agreements will be reviewed and updated by July 31, 2026, to include language requiring providers to safeguard covered data. A vendor management procedure will also be implemented to ensure ongoing oversight.
• An annual GLBA training program will be implemented starting July 31, 2026. Training completion will be monitored and documented through the HR compliance system.
• Corrective Action: Rockland Community College will implement quarterly testing of safeguards and document results. Findings will be reported to the Executive Cabinet and used to continuously improve protections.
All corrective actions will be completed by August 31, 2026. Progress will be tracked by the Information Security Officer and reported quarterly to the Executive Cabinet and the Board of Trustees.
We are committed to protecting sensitive financial and student information and ensuring full compliance with the GLBA Safeguards Rule. Please let us know if additional information is required.