Finding 1216237 (2024-010)

Material Weakness Repeat Finding
Requirement
N
Questioned Costs
-
Year
2024
Accepted
2026-06-01
Audit: 402736
Organization: Barclay College (KS)
Auditor: CAPINCROUSE LLC

AI Summary

  • Core Issue: The College is not fully compliant with the updated requirements of the Gramm-Leach-Bliley Act (GLBA), risking student information security.
  • Impacted Requirements: Key areas lacking include security risk assessments, multi-factor authentication, vendor management, incident response plans, and annual reporting.
  • Recommended Follow-Up: Allocate necessary resources to meet GLBA requirements and implement corrective actions as agreed by management.

Finding Text

Gramm-Leach-Bliley Act (GLBA) Compliance Material Weakness DEPARTMENT OF EDUCATION ALN #: 84.268, 84.063, 84.007, 84.033, and 84.379 (Student Financial Assistance Cluster) Federal Award Identification #: 2023-2024 Financial Aid Year Condition: The College did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.4 Questioned Costs: $0 Context: The College has not sufficiently documented its security risk assessment and safeguards, including general threats, multi-factor authentication on systems containing personally identifiable information (PII), or continuous monitoring, such as penetration testing and vulnerability scanning. Additionally, the College has not fully implemented sufficient vendor management policies and reviews, implemented an incident response plan, or provided a written, annual report to the board. Cause: The College has not allocated sufficient resources to address and document compliance with the requirements of GLBA. Effect: The College has not adequately addressed the requirements of GLBA, which may lead to unintended exposure of student information to security risks. Identification as repeat finding, if applicable: 2023-012. Recommendation: We recommend the College allocate sufficient resources to address all requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Corrective Action Plan

2024-010 Gramm-Leach-Bliley Act (GLBA) Compliance Planned Corrective Action: We will review items not fully implemented. Person Responsible for Corrective Action Plan: Lori Larsh, Vice President for Business Services Anticipated Date of Completion: 07/31/2026

Categories

Subrecipient Monitoring Material Weakness

Other Findings in this Audit

  • 1216216 2024-004
    Material Weakness Repeat
  • 1216217 2024-004
    Material Weakness Repeat
  • 1216218 2024-004
    Material Weakness Repeat
  • 1216219 2024-004
    Material Weakness Repeat
  • 1216220 2024-004
    Material Weakness Repeat
  • 1216221 2024-005
    Material Weakness Repeat
  • 1216222 2024-005
    Material Weakness Repeat
  • 1216223 2024-005
    Material Weakness Repeat
  • 1216224 2024-005
    Material Weakness Repeat
  • 1216225 2024-005
    Material Weakness Repeat
  • 1216226 2024-006
    Material Weakness Repeat
  • 1216227 2024-006
    Material Weakness Repeat
  • 1216228 2024-007
    Material Weakness Repeat
  • 1216229 2024-008
    Material Weakness Repeat
  • 1216230 2024-008
    Material Weakness Repeat
  • 1216231 2024-009
    Material Weakness Repeat
  • 1216232 2024-009
    Material Weakness Repeat
  • 1216233 2024-010
    Material Weakness Repeat
  • 1216234 2024-010
    Material Weakness Repeat
  • 1216235 2024-010
    Material Weakness Repeat
  • 1216236 2024-010
    Material Weakness Repeat

Programs in Audit

ALN Program Name Expenditures
84.268 FEDERAL DIRECT STUDENT LOANS $722,969
84.063 FEDERAL PELL GRANT PROGRAM $524,882
84.033 FEDERAL WORK-STUDY PROGRAM $40,692
84.007 FEDERAL SUPPLEMENTAL EDUCATIONAL OPPORTUNITY GRANTS $16,092
84.379 TEACHER EDUCATION ASSISTANCE FOR COLLEGE AND HIGHER EDUCATION GRANTS (TEACH GRANTS) $1,886