Finding 2025-003: Gramm-Leach-Bliley Act (GLBA) Significant Deficiency in Internal Control over Compliance / Other Matters Views of Responsible Officials and Planned Corrective Actions: Management concurs with the audit finding and acknowledges that, during the fiscal year ended June 30, 2025, the College had not performed penetration testing or completed an IT risk assessment as required under the Gramm-Leach-Bliley Act. Subsequent to fiscal year-end, management has taken decisive corrective action to remediate this deficiency and strengthen the College’s information security control environment: Penetration Testing: Management engaged an independent, qualified third-party cybersecurity firm, Counter Measures Security, LLC, to perform penetration testing. A professional services agreement was executed in August 2025, and penetration testing was completed on October 17, 2025, in accordance with the Penetration Testing Execution Standard (PTES). Management has reviewed the results and is addressing identified recommendations as appropriate. Documentation supporting the completion of these services is retained by the College. IT Risk Assessment and Information Security Program: Management is formalizing an IT risk assessment process consistent with GLBA requirements and incorporating penetration testing results into the College’s broader information security program. Ongoing Monitoring: Management will establish a recurring schedule for penetration testing and IT risk assessments and will maintain documentation of results, remediation efforts, and management review to support ongoing compliance. Penetration testing was completed as of October 17, 2025, and management expects the IT risk assessment process and ongoing monitoring controls to be fully implemented during fiscal year 2026.