Finding Text
Finding: 2025-002 U.S. Department of Education Student Financial Assistance Cluster Gramm Leach Bliley Act (GLBA) Criteria Institutions participating in the Student Financial Assistance (SFA) program are required to comply with GLBA. Context Based on review of the College's information security program and related documentation, it was identified that multiple required elements of the GLBA were not implemented or documented. Condition The College has implemented certain information security policies and procedures; however, several key requirements of the GLBA have not been met or are not regularly updated. Specifically, the College has not performed a documented risk assessment and its written information security program has not been updated in multiple years and does not include all of the eight minimum safeguards. In addition, the College does not perform documented monitoring or testing of security safeguards, and it has not established a formal vendor management program in accordance with GLBA. Cause The College has not established formal policies to ensure compliance with the GLBA requirements. Resource constraints and competing priorities were contributing factors. Effect The College is not fully compliant with GLBA requirements. Questioned Costs Not applicable because the finding consisted solely of noncompliance with the reporting type of compliance requirements. Recommendation We recommend that the College develop and implement formal written policies for all minimum elements required by GLBA. Views of Responsible Officials The College acknowledges the recommendation and is committed to implementing formal written policies for all minimum elements required by GLBA.