Finding Text
Federal Program: Student Financial Assistance Cluster Federal Assistance Listing Number: 84.063, 84.033, 84.038, 84.007, 84.268, 84.379 Federal Agency: Department of Education (DOE) Federal Award Numbers: P063P242023, P033A243392, Unknown, P007A243392, P268K252023, P379T0972023; Award Year: 2025 Criteria: Under the GLBA Safeguards Rule, entities serving in the capacity of financial institutions must develop, implement, and maintain a comprehensive information security program that includes administrative, technical, and physical safeguards. Condition: The institution has not fully implemented or documented controls as required by the GLBA. Specifically, based on testing we noted that: • Customer data is not encrypted • Periodic inventories of data were not performed for the period 7/1/2024-3/1/2025 • While an annual risk assessment was performed, which included required elements, many of those elements were not found to be satisfactorily implemented for all or part of the year. Cause: The institution did not have adequate internal controls or monitoring procedures in place to ensure compliance with the GLBA Act. Effect: Failure to implement and enforce access controls increases the risk of unauthorized access to sensitive customer data, potentially leading to data breaches, regulatory penalties, and reputational harm. Questioned Costs: None reported Context: Controls did not operate properly for the University to comply with requirements of the GLBA Act. Repeat Finding: Yes Recommendations: We recommend that the University evaluate its processes and controls to ensure all requirements of GLBA are monitored and addressed. Views of Responsible Officials: Management agrees with the finding. See management's corrective action plan.