Finding 1227458 (2025-006)

Material Weakness Repeat Finding
Requirement
N
Questioned Costs
-
Year
2025
Accepted
2026-08-20
Audit: 409492
Organization: The Institute of World Politics (DC)
Auditor: RSM US LLP

AI Summary

  • Core Issue: The Institute lacks a written information security program that meets all seven required elements of the Gramm-Leach-Bliley Act (GLBA), leading to noncompliance.
  • Impacted Requirements: Compliance with 2 CFR Part 200 and GLBA is essential for safeguarding student information; failure to address key components like risk assessment and monitoring is a material weakness.
  • Recommended Follow-Up: Develop a comprehensive information security program that includes all GLBA requirements, focusing on risk assessment, safeguards, and ongoing monitoring.

Finding Text

Finding 2025-006: Special Tests and Provisions—GLBA Noncompliance Material Weakness and Material Noncompliance Federal Program: Student Financial Assistance Cluster Federal Agency: Department of Education Federal Award Year: August 1, 2024–July 31, 2025 Criteria: Auditee requirements contained in 2 CFR Part 200, Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards, requires the auditee to comply with federal statues, regulations, terms and conditions of federal awards that may have a direct and material effect on each of its major programs. The Gramm-Leach-Bliley Act over student information security, requires the Institute to have a written information security program that addresses seven specific required elements. Condition: The Institute does not have a written information security program that addresses the seven required elements under the GLBA. Cause: The condition was identified through testing of the GLBA student information security compliance requirement. While the Institute has an existing written information security program, our review determined that the program does not address all required elements, as it omits certain key components, including risk assessment and ongoing monitoring activities. Effect: The Institute is not in compliance with the GLBA. Repeat finding: Yes—see finding 2024-002. Questioned costs: None. Context: While the Institute has a written information security program, it does not include the required seven elements which includes risk assessment and monitoring. Recommendation: We recommend that the Institute develop and implement a comprehensive, formalized written information security program that fully addresses all required elements under the GLBA for student information security. Specifically, management should: • Review current GLBA requirements to ensure the program incorporates all required elements applicable to the safeguarding of student information. • Update the existing information security program to include key components such as risk assessment, identification of foreseeable risks, implementation of safeguards, and ongoing monitoring of controls. Views of Responsible Officials: Management agrees with the finding. See corrective action plan.

Corrective Action Plan

Identifying Number: 2025-006: Special Tests—Gramm-Leach-Bliley Act Noncompliance Finding: - The Institute does not have a written information security program that addresses the seven required elements under the Gramm-Leach-Bliley Act. Corrective Actions Taken or Planned: Management agrees with the finding and has implemented, or is in the process of implementing, the following corrective actions to strengthen compliance with the Gramm-Leach-Bliley Act and Department of Education requirements: 1. Comprehensive Review and Revision of the Written Information Security Program (WISP) • The Institute will conduct a comprehensive review of its existing Written Information Security Program (WISP) to ensure that all required elements of the GLBA Safeguards Rule are incorporated. The revised program will be approved by senior management and maintained as a formal institutional policy. 2. Formal Risk Assessment Process • The Institute will develop and implement a documented risk assessment process to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student information. Risk assessments will be performed periodically and updated as significant operational, or technology changes occur. 3. Implementation of Required Security Safeguards • Management will document and implement administrative, technical, and physical safeguards designed to mitigate identified risks and protect student information. Safeguards will be reviewed periodically to ensure continued effectiveness. 4. Ongoing Monitoring and Testing of Controls • The Institute will establish procedures for ongoing monitoring of information security controls, including periodic evaluations of the effectiveness of safeguards, review of security incidents, vulnerability assessments, and corrective action tracking. Results will be documented and retained for review. 5. Vendor and Service Provider Oversight • The Institute will strengthen oversight procedures for third-party service providers that have access to protected student information. Contracts and vendor management procedures will be reviewed to ensure appropriate security expectations and monitoring requirements are established. 6. Security Awareness Training • Annual information security and data privacy training will be provided to employees with access to student information. Training will address GLBA requirements, cybersecurity risks, data protection responsibilities, incident reporting procedures, and institutional security policies. 7. Designation of Responsible Personnel • Management will formally designate individual(s) responsible for coordinating and overseeing the Information Security Program, including risk assessment activities, monitoring efforts, policy updates, and compliance reporting. 8. Periodic Reporting to Senior Management and the Board • The Information Security Program Coordinator will provide periodic reports to senior management and the Board or appropriate governing committee regarding information security risks, monitoring activities, cybersecurity incidents, and the status of GLBA compliance efforts. 9. Annual Review of the Information Security Program • The Institute will conduct an annual review of its Information Security Program to ensure continued alignment with GLBA requirements, Department of Education guidance, emerging cybersecurity risks, and institutional operations. Identifying Number: 2025-006: Special Tests—Gramm-Leach-Bliley Act Noncompliance (Continued) Responsible Officials: • Executive Vice President – Ariane Sweeney • Chief Information Officer - Dean Lane • Controller/Outsourced Accounting Partner – YPTC Associates Melissa McGuire & Samantha Glass • Director of Financial Aid – Dr Thelbert Snowden Anticipated completion date: The revised Written Information Security Program, formal risk assessment process, monitoring procedures, and training program will be fully implemented by December 31, 2026. Ongoing monitoring, risk assessments, and annual reviews will continue thereafter.

Categories

Subrecipient Monitoring Special Tests & Provisions Allowable Costs / Cost Principles Material Weakness

Other Findings in this Audit

  • 1227454 2025-002
    Material Weakness Repeat
  • 1227455 2025-003
    Material Weakness Repeat
  • 1227456 2025-004
    Material Weakness Repeat
  • 1227457 2025-005
    Material Weakness Repeat
  • 1227459 2025-007
    Material Weakness Repeat

Programs in Audit

ALN Program Name Expenditures
84.268 FEDERAL DIRECT STUDENT LOANS $1.20M