Finding: 2023-001
Federal Agency Name: U.S. Department of Education
Program Name: Student Financial Assistance Cluster
FAL #: 84.063, 84.007, 84.238, 84.033
Initial Fiscal Year Finding Occurred: 2023
Finding Summary: During the testing over student information security, it was determined the College did not
have all nine elements of the new GLBA requirements in place with written policies and documented follow
through protocols.
Responsible Individuals: Jeremy Taylor, Chief Information Officer and Josh Ogle, former Chief Information Officer.
Corrective Action Plan: : Subsequent to the June 30, 2023 finding the College has already implemented or
updated process to ensure student information security safeguards are in place. This includes a Security
Information and Event Management (SIEM) solution fully equipped to log all user access within our network and
capture detailed information about user activities on the network and their individual PCs. Additionally, it
comprehensively monitors and collects data on all network switch and firewall activity.
This data is stored and analyzed on-premises and reported to Sophos for enhanced monitoring through their
Managed Detection and Response (MDR) service. Rogue Community College has extended its security measures
by integrating our Microsoft 365 tenant and Okta with Sophos, enabling 24/7 user activity monitoring across
these platforms. These integrations and vigilant monitoring practices demonstrate our unwavering commitment
to robust security and adherence to regulatory compliance standards, ensuring meticulous surveillance of
authorized user actions and safeguarding against unauthorized access.
We have contracted with Eide Bailly’s Technology Consulting group. The Statement of Work focuses on creating
an Incident Response Plan which is leading to updated policies and procedure documentation. We are working
on a GLBA specific policy as well.
Anticipated Completion Date: As of December 2023, we believe we have the minimum safeguards in place. By
early 2024, a written GLBA specific policy including how we document follow through on monitoring efforts will
be in place.