Finding Text
Student Financial Assistance Cluster
Federal Pell Grants, ALN 84.063
Federal Direct Student Loans, ALN 84.268
U.S. Department of Education Program Year 2023 - 2024
Criteria or Specific Requirement - Special Tests: Gramm-Leach-Bliley Act - Student Information Security 16 CFR 314.4(c)(1) - (8), 16 CFR 314.4(e)
Condition - The University does not have a written information security program that addresses all required elements of the Gramm-Leach-Bliley Act.
Questioned costs - None
Context - On December 9, 2021, the Federal Trade Commission issued final regulations for 16 CFR Part 314 to implement the Gramm-Leach-Bliley Act information safeguarding standards that institutions must implement. The regulations established minimum standards that institutions must meet. Institutions were required to be in compliance with the revised requirements no later than June 9, 2023. The University's written information security program did not contain 9 of the 14 elements required by the revised Gramm-Leach-Bliley Act regulations.
Effect - The University's written information security program does not address all required written statement elements of the Gramm-Leach-Bliley Act.
Cause - The University did not update its written information security program by June 9, 2023 for the revised requirements of 16 CFR Part 314.
Identification as a repeat finding - N/A
Recommendation - The University should revise its written information security program to be compliant with the current requirements of 16 CFR Part 314.