Finding 1161359 (2025-002)

Material Weakness Repeat Finding
Requirement
N
Questioned Costs
-
Year
2025
Accepted
2025-10-24
Audit: 371249
Organization: Augsburg University (MN)

AI Summary

  • Core Issue: The Written Information Security Program (WISP) is missing key elements required by the Gramm-Leach-Bliley Act (GLBA), specifically on secure disposal of customer information and monitoring user activity.
  • Impacted Requirements: GLBA mandates that institutions with fewer than 5,000 customers must address seven specific elements in their WISP, which were not fully implemented.
  • Recommended Follow-Up: The University should review GLBA requirements and update the WISP to include all necessary elements to protect student personal information.

Finding Text

Federal Agency: Department of Education Federal Program Name: Student Financial Aid Cluster Assistance Listing Number: 84.007, 84.033, 84.063, 84.268 Federal Award Identification Number and Year: N/A Award Period: June 1, 2023 to May 31, 2024 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or specific requirement: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). Institutions are required to develop, implement, and maintain a comprehensive information security program that is written in one or more readily accessible parts. The regulations require the written information security program to include nine elements for institutions with 5,000 or more customers, (16 CFR 314.3(a)). The written information security program for institutions with fewer than 5,000 customers must address seven elements (16 CFR 314.3(a) and 16 CFR 314.6). The elements that an institution must address in its written information security program are at 16 CFR 314.4. At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Condition: There were two items missing entirely from the Written Information Security Program: o Dispose of customer information securely o Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. Questioned costs: None Context: These GLBA requirements were applicable beginning on June 9, 2023 and there were two elements missing from the WISP at the end of the fiscal year. Cause: There was a general lack of capacity in IT staffing to formally implement the WISP fully during the year. Effect: The student personal information could be vulnerable. Repeat Finding: Yes Recommendation: We recommend that the University review the updated GLBA requirements and ensure their WISP includes all required elements and is formally implemented. Views of responsible officials: There is no disagreement with the audit finding.

Corrective Action Plan

Student Financial Assistance Cluster— Assistance Listing Nos. 84.007, 84.033, 84.063, 84.268 Recommendation: We recommend that the University review the updated GLBA requirements and ensure their WISP includes all required elements. Explanation of disagreement with audit finding: There is no disagreement with the audit finding. Action taken in response to finding: Augsburg University will update its Written Information Security Program to: * More fully document the processes and procedures to dispose of customer information securely * Maintain a log of authorized users’ activity and keep an eye out for unauthorized access. Names of the contact persons responsible for corrective action: Scott Krajewski Planned completion date for corrective action plan: May 31, 2026

Categories

Significant Deficiency Internal Control / Segregation of Duties

Other Findings in this Audit

  • 1161348 2025-001
    Material Weakness Repeat
  • 1161349 2025-001
    Material Weakness Repeat
  • 1161350 2025-001
    Material Weakness Repeat
  • 1161351 2025-001
    Material Weakness Repeat
  • 1161352 2025-001
    Material Weakness Repeat
  • 1161353 2025-001
    Material Weakness Repeat
  • 1161354 2025-002
    Material Weakness Repeat
  • 1161355 2025-002
    Material Weakness Repeat
  • 1161356 2025-002
    Material Weakness Repeat
  • 1161357 2025-002
    Material Weakness Repeat
  • 1161358 2025-002
    Material Weakness Repeat
  • 1161360 2025-003
    Material Weakness Repeat
  • 1161361 2025-003
    Material Weakness Repeat
  • 1161362 2025-003
    Material Weakness Repeat
  • 1161363 2025-003
    Material Weakness Repeat
  • 1161364 2025-003
    Material Weakness Repeat
  • 1161365 2025-003
    Material Weakness Repeat
  • 1161366 2025-003
    Material Weakness Repeat
  • 1161367 2025-003
    Material Weakness Repeat

Programs in Audit

ALN Program Name Expenditures
84.379 TEACHER EDUCATION ASSISTANCE FOR COLLEGE AND HIGHER EDUCATION GRANTS (TEACH GRANTS) $19.58M
84.063 FEDERAL PELL GRANT PROGRAM $9.50M
84.038 FEDERAL PERKINS LOAN PROGRAM_FEDERAL CAPITAL CONTRIBUTIONS $948,108
84.007 FEDERAL SUPPLEMENTAL EDUCATIONAL OPPORTUNITY GRANTS $685,822
84.033 FEDERAL WORK-STUDY PROGRAM $513,684
47.050 GEOSCIENCES $364,938
84.042 TRIO STUDENT SUPPORT SERVICES $334,197
84.217 TRIO MCNAIR POST-BACCALAUREATE ACHIEVEMENT $285,688
94.021 AMERICORPS VOLUNTEER GENERATION FUND 94.021 $160,003
47.076 STEM EDUCATION (FORMERLY EDUCATION AND HUMAN RESOURCES) $81,075
93.243 SUBSTANCE ABUSE AND MENTAL HEALTH SERVICES PROJECTS OF REGIONAL AND NATIONAL SIGNIFICANCE $76,681
47.074 BIOLOGICAL SCIENCES $61,237
43.008 OFFICE OF STEM ENGAGEMENT (OSTEM) $24,134
93.242 MENTAL HEALTH RESEARCH GRANTS $21,265
93.853 EXTRAMURAL RESEARCH PROGRAMS IN THE NEUROSCIENCES AND NEUROLOGICAL DISORDERS $21,171
93.307 MINORITY HEALTH AND HEALTH DISPARITIES RESEARCH $21,084