Finding Text
2024-002 – Data Breach Reporting Assistance Listing Number: Various – U.S. Department of Education – Student Financial Assistance Cluster Criteria Under the University’s the Student Aid Internet Gateway Agreement, institutions must report actual data breaches as well as suspected data breaches. Institutions must report on the day that a data breach is detected or even suspected. Condition The University failed to report a data breach to the Department of Education, either on the day of detection or at any subsequent time. The breach involved a social engineering attack that happened to the institution’s third-party company, a platform provider, which led to the compromise of user accounts where attackers gained access to the personal identifiable data (PII) of five individuals employed by the University. One of those individuals had user access to the student information system at the time of the breach. Cause The University lacked policies, procedures, and guidelines around handling cybersecurity incidents relating to the Department of Education reporting requirements. Effect The breach was reported internally to management and actions were taken to identify the cause and reporting was made to the individuals concerning the breach however the Department of Education was not notified as required. Questioned Costs There were no questioned costs related to this finding. Recommendation The University should update policies, procedures, and guidelines around handling cybersecurity incidents relating to personally identifiable information (PII), in regards to the Department of Education reporting requirements. Responsible Personnel Marcus D Walton Deputy Chief Operating Officer & CIO