Identifying Number: 2025-006: Special Tests—Gramm-Leach-Bliley Act Noncompliance Finding: - The Institute does not have a written information security program that addresses the seven required elements under the Gramm-Leach-Bliley Act. Corrective Actions Taken or Planned: Management agrees with the finding and has implemented, or is in the process of implementing, the following corrective actions to strengthen compliance with the Gramm-Leach-Bliley Act and Department of Education requirements: 1. Comprehensive Review and Revision of the Written Information Security Program (WISP) • The Institute will conduct a comprehensive review of its existing Written Information Security Program (WISP) to ensure that all required elements of the GLBA Safeguards Rule are incorporated. The revised program will be approved by senior management and maintained as a formal institutional policy. 2. Formal Risk Assessment Process • The Institute will develop and implement a documented risk assessment process to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of student information. Risk assessments will be performed periodically and updated as significant operational, or technology changes occur. 3. Implementation of Required Security Safeguards • Management will document and implement administrative, technical, and physical safeguards designed to mitigate identified risks and protect student information. Safeguards will be reviewed periodically to ensure continued effectiveness. 4. Ongoing Monitoring and Testing of Controls • The Institute will establish procedures for ongoing monitoring of information security controls, including periodic evaluations of the effectiveness of safeguards, review of security incidents, vulnerability assessments, and corrective action tracking. Results will be documented and retained for review. 5. Vendor and Service Provider Oversight • The Institute will strengthen oversight procedures for third-party service providers that have access to protected student information. Contracts and vendor management procedures will be reviewed to ensure appropriate security expectations and monitoring requirements are established. 6. Security Awareness Training • Annual information security and data privacy training will be provided to employees with access to student information. Training will address GLBA requirements, cybersecurity risks, data protection responsibilities, incident reporting procedures, and institutional security policies. 7. Designation of Responsible Personnel • Management will formally designate individual(s) responsible for coordinating and overseeing the Information Security Program, including risk assessment activities, monitoring efforts, policy updates, and compliance reporting. 8. Periodic Reporting to Senior Management and the Board • The Information Security Program Coordinator will provide periodic reports to senior management and the Board or appropriate governing committee regarding information security risks, monitoring activities, cybersecurity incidents, and the status of GLBA compliance efforts. 9. Annual Review of the Information Security Program • The Institute will conduct an annual review of its Information Security Program to ensure continued alignment with GLBA requirements, Department of Education guidance, emerging cybersecurity risks, and institutional operations. Identifying Number: 2025-006: Special Tests—Gramm-Leach-Bliley Act Noncompliance (Continued) Responsible Officials: • Executive Vice President – Ariane Sweeney • Chief Information Officer - Dean Lane • Controller/Outsourced Accounting Partner – YPTC Associates Melissa McGuire & Samantha Glass • Director of Financial Aid – Dr Thelbert Snowden Anticipated completion date: The revised Written Information Security Program, formal risk assessment process, monitoring procedures, and training program will be fully implemented by December 31, 2026. Ongoing monitoring, risk assessments, and annual reviews will continue thereafter.