Finding Text
Gramm-Leach-Bliley Act (GLBA) Compliance DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038, and 84.379 - Student Financial Assistance Cluster
Federal Award Identification #: 2023-2024 Award Year
Condition: The University did not sufficiently comply with the updated requirements of GLBA.
Criteria: 16 CFR 314.3, 16 CFR 314.4
Questioned Costs: $0
Context: The University has not implemented multi-factor authentication on all systems containing personally identifiable information (PII) or documented an exception and has not updated it policy related to data deletion or documented an exception.
Cause: The University was not able to fully address all prior year items with transition at the University in order to address and document compliance with the updated requirements of GLBA.
Effect: The University has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks.
Identification as repeat finding, if applicable: Yes, 2023-004
Recommendation: We recommend the University allocate sufficient resources to address all updated requirements of GLBA. We commend the University for the work completed on GLBA in the past year.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.