Finding Text
Finding 2024-003-Student Financial Aid Cluster, ALN#84.007, 84.033, 84.063, 84.268, 84.379 Compliance Requirement: Gramm-Leach-Bliley Act – Student Information Security
Criteria: The University is required to have a written security program that address the seven elements as described in 16 CFR 314.4 (b).
Condition: The University does not have a written security program that address the seven elements as described in 16 CFR 314.4 (b) as of June 30, 2024.
Cause: Although the University meets some of the seven elements as described in 16 CFR 314.4 (b), the University has yet to establish a formalized written policy.
Effect: The University could have risks associated with the safeguarding of sensitive information it is not aware of or does not protect against.
Questioned Costs: None
Context: Not all elements as described in 16 CFR 314.4 (b) have been met, and the University does not have formal written documentation of its program.
Recommendation: The University should implement a written security program that addresses the required elements as described in 16 CFR 314.4 (b).
Management Response: The University concurs with this finding.
Corrective Action Plan: See attached management’s corrective action plan.