Finding 1218112 (2025-003)

Material Weakness Repeat Finding
Requirement
N
Questioned Costs
-
Year
2025
Accepted
2026-06-22
Audit: 404302
Organization: Chestnut Hill College (PA)

AI Summary

  • Core Issue: The College failed to conduct required penetration testing and IT risk assessments, risking student data security under the Gramm-Leach-Bliley Act.
  • Impacted Requirements: Compliance with the Gramm-Leach-Bliley Act mandates safeguarding sensitive student financial aid information.
  • Recommended Follow-Up: The College should implement annual penetration testing and conduct IT risk assessments to enhance data protection.

Finding Text

2025-003: Gramm-Leach-Bliley Act Federal Agency: U.S. Department of Education Federal Program Name: Federal Supplemental Educational Opportunity Grants; Federal Pell Grant Program; Federal Direct Student Loans; Federal Work Study Program Assistance Listing Number: 84.007, 84.063, 84.268, Federal Award Identification Number and Year: P063P242088; P007A243557; P268K252088; P033A243557 - 2025 Award Period: July 01, 2024 - June 30, 2025 Type of Finding: • Significant Deficiency in Internal Control over Compliance • Other Matters Criteria or Specific Requirement: The Gramm-Leach-Bliley Act (Public Law 106-102) requires institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi)). Condition: Under an institution’s Program Participation Agreement with the U.S. Department of Education and the Gramm-Leach-Bliley Act, schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. Questioned Costs: None Context: During our audit procedures, it was noted that the College had not performed penetration testing and did not have an IT risk assessment performed.. Cause: The College did not perform penetration testing and did not have an IT risk assessment performed as required by the Gramm-Leach-Bliley Act. Effect: The students’ personal information could be vulnerable. Repeat Finding: Yes, 2024-005. Recommendation: The College should develop and implement annual penetration testing and perform IT risk assessment. Views of Responsible Officials: There is no disagreement with the audit finding.

Corrective Action Plan

Finding 2025-003: Gramm-Leach-Bliley Act (GLBA) Significant Deficiency in Internal Control over Compliance / Other Matters Views of Responsible Officials and Planned Corrective Actions: Management concurs with the audit finding and acknowledges that, during the fiscal year ended June 30, 2025, the College had not performed penetration testing or completed an IT risk assessment as required under the Gramm-Leach-Bliley Act. Subsequent to fiscal year-end, management has taken decisive corrective action to remediate this deficiency and strengthen the College’s information security control environment:  Penetration Testing: Management engaged an independent, qualified third-party cybersecurity firm, Counter Measures Security, LLC, to perform penetration testing. A professional services agreement was executed in August 2025, and penetration testing was completed on October 17, 2025, in accordance with the Penetration Testing Execution Standard (PTES). Management has reviewed the results and is addressing identified recommendations as appropriate. Documentation supporting the completion of these services is retained by the College.  IT Risk Assessment and Information Security Program: Management is formalizing an IT risk assessment process consistent with GLBA requirements and incorporating penetration testing results into the College’s broader information security program.  Ongoing Monitoring: Management will establish a recurring schedule for penetration testing and IT risk assessments and will maintain documentation of results, remediation efforts, and management review to support ongoing compliance. Penetration testing was completed as of October 17, 2025, and management expects the IT risk assessment process and ongoing monitoring controls to be fully implemented during fiscal year 2026.

Categories

Student Financial Aid

Other Findings in this Audit

  • 1218108 2025-002
    Material Weakness Repeat
  • 1218109 2025-002
    Material Weakness Repeat
  • 1218110 2025-003
    Material Weakness Repeat
  • 1218111 2025-003
    Material Weakness Repeat

Programs in Audit

ALN Program Name Expenditures
84.268 FEDERAL DIRECT STUDENT LOANS $11.96M
84.063 FEDERAL PELL GRANT PROGRAM $3.03M
84.031 HIGHER EDUCATION INSTITUTIONAL AID $451,047
93.575 CHILD CARE AND DEVELOPMENT BLOCK GRANT $360,477
84.033 FEDERAL WORK-STUDY PROGRAM $224,948
84.007 FEDERAL SUPPLEMENTAL EDUCATIONAL OPPORTUNITY GRANTS $113,744
84.038 FEDERAL PERKINS LOAN PROGRAM_FEDERAL CAPITAL CONTRIBUTIONS $11,800