Finding 2214 (2023-005)

-
Requirement
N
Questioned Costs
-
Year
2023
Accepted
2023-11-20
Audit: 3792
Organization: Bethany Fellowship, Inc. (CO)
Auditor: Capincrouse LLP

AI Summary

  • Core Issue: Bethany is not fully compliant with updated GLBA requirements, risking student information security.
  • Impacted Requirements: Compliance with 16 CFR 314.3 and 16 CFR 314.4 is insufficiently documented and implemented.
  • Recommended Follow-Up: Collaborate with the third party to establish timelines for completing all GLBA requirements.

Finding Text

Gramm-Leach-Bliley Act (GLBA) Compliance DEPARTMENT OF EDUCATION ALN #: 84.268, 84.063, 84.007, and 84.033 - Student Financial Assistance Cluster Federal Award Identification #: 2022-2023 Financial Aid Year Condition: Bethany did not sufficiently comply with the updated requirements of GLBA. Criteria: 16 CFR 314.3, 16 CFR 314.4 Questioned Costs: $-0- Context: Bethany has contracted with a third party to assist with compliance with GLBA. Bethany is in the process of fully documenting its information security program. Bethany has implemented multi-factor authentication (MFA) on some systems that contain personally identifiable information and is working to implement MFA on the remaining systems. Bethany is also working to implement sufficient continuous monitoring, such as penetration testing and vulnerability scanning. Cause: The timing of the contracting by Bethany has not allowed all updated components of GLBA to be addressed and documented during the audit process. Effect: Bethany may have unintended exposure of student information to security risks. Identification as repeat finding, if applicable: Not applicable Recommendation: We recommend Bethany work with the third party and determine timeframes remaining to address all requirements of GLBA. Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.

Corrective Action Plan

Gramm-Leach-Bliley Act (GLBA) Compliance Planned Corrective Action: Multi-Factor Authentication: The University’s Compliance Committee, led by the Chief Financial Officer, now requires that Multi Factor Authentication (MFA) is turned on for all MFA capable software systems that house Sensitive Personally Identifiable Information of students. The Committee will implement policies to ensure that all users who access those systems are required to use Multi Factor Authentication. Any legacy systems without MFA will be retired. Information System Monitoring/Testing: In June of 2023, the University entered into a contract with an outside Managed IT Services provider. This third-party vendor provides the following services: • Firewall to protect network perimeter. • Security updates and critical patches. • Alerts to inform about issues on all endpoints. • Defense agents that scan and monitor external devices. • Agents to actively monitor web traffic and block malicious links. • Tools used for internal and external vulnerability scans. • Alerts to monitor for any malicious activity or events of potential compromise. • Other advanced threat protection. The University's Compliance Committee will assess the effectiveness of the existing continuous monitoring procedures and ascertain whether further vulnerability assessments and penetration testing are necessary to meet the stipulated criteria within Title 16, Chapter I, Subchapter C, Part 314 of the Federal Trade Commission regulations. The Compliance Committee will collaborate with additional IT Security Professionals as deemed necessary and ensure that the University is in compliance with the regulations. Person Responsible for Corrective Action Plan: David Entler, Chief Financial Officer Anticipated Date of Completion: January 31, 2024

Categories

Subrecipient Monitoring

Other Findings in this Audit

Programs in Audit

ALN Program Name Expenditures
84.268 Federal Direct Student Loans $750,832
84.063 Federal Pell Grant Program $627,419
84.033 Federal Work-Study Program $435,550
84.425 Covid-19 Education Stabilization Fund Heerf - Student Aid Portion $390,260
84.425 Covid-19 Education Stabilization Fund Heerf - Institutional Portion $256,895
84.007 Federal Supplemental Educational Opportunity Grants $12,000