Finding 370799 (2023-001)

Significant Deficiency
Requirement
N
Questioned Costs
-
Year
2023
Accepted
2024-02-27

AI Summary

  • Core Issue: The college is missing key requirements from the Gramm-Leach-Bliley Act (GLBA), despite having a Written Information Security Program (WISP).
  • Impacted Requirements: Essential elements of the WISP, including risk assessment procedures and safeguards, were not fully implemented as of the June 9, 2023 deadline.
  • Recommended Follow-Up: The college should review and update its WISP to include all GLBA requirements to protect student personal information effectively.

Finding Text

Criteria or Specific Requirement: The Gramm-Leach Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data (16 CFR 314). The regulation states that the college must designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program. (16 CFR 314.4(a)). The entity shall have a Written Information Security Program (WISP) that outlines the design and implementation of the risk assessment procedures. (16 CFR 314.4(b)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8) including: Assess apps developed by the institution. In addition, the written security program provides for the institution to regularly test or otherwise monitor the effectiveness of the safeguards it has implemented (16 CFR 314.4(d)). Condition: The college was missing all the requirements from the Gramm-Leach-Bliley Act except for having a Written Information Security Program, approval by appropriate individual, implement and periodically review access controls, and proper disposal of customer information securely. These GLBA requirements were applicable beginning on June 9, 2023, and there were multiple elements missing from their Written Information Security Program. Context: The institution has been in compliance with previous iterations of GLBA compliance. The Written Information Security Program (WISP) which was required as of June 9, 2023 had missing elements. Some controls were in place whereas others were not. They did, however, have a WISP as of the deadline but it was missing some required information. Questioned Costs: N/A Cause: There was not a formal process in place to review against all the new GLBA requirements to ensure compliance.Effect: Student personal information could be vulnerable. Repeat Finding: No Recommendation: We recommend that the College review the updated GLBA requirements and ensure their Written Information Security Program (WISP) includes all required elements. Views of Responsible Officials: Management agrees with the finding and has developed a plan to correct the finding.

Categories

Subrecipient Monitoring

Other Findings in this Audit

  • 370797 2023-001
    Significant Deficiency
  • 370798 2023-001
    Significant Deficiency
  • 370800 2023-001
    Significant Deficiency
  • 370801 2023-002
    Significant Deficiency
  • 370802 2023-002
    Significant Deficiency
  • 370803 2023-002
    Significant Deficiency
  • 370804 2023-002
    Significant Deficiency
  • 947239 2023-001
    Significant Deficiency
  • 947240 2023-001
    Significant Deficiency
  • 947241 2023-001
    Significant Deficiency
  • 947242 2023-001
    Significant Deficiency
  • 947243 2023-002
    Significant Deficiency
  • 947244 2023-002
    Significant Deficiency
  • 947245 2023-002
    Significant Deficiency
  • 947246 2023-002
    Significant Deficiency

Programs in Audit

ALN Program Name Expenditures
84.063 Federal Pell Grant Program $4.88M
84.268 Federal Direct Student Loans $4.72M
84.425 Covid-19 Higher Education Emergency Relief Fund $2.69M
84.047 Trio--Upward Bound $364,534
84.042 Trio--Student Support Services $316,167
84.031 Success and Cultural Center $304,869
84.031 Higher Education Institutional Aid-Serving the New Majority $302,491
93.558 Temporary Assistance for Needy Families - Allied Jobs Program $157,809
84.007 Federal Supplemental Educational Opportunity Grants $150,500
84.002 Adult Education - Basic Grant to States $132,234
84.033 Federal Work-Study Program $130,016
10.559 Summer Food Service Program for Children - Child Nutrition Program $87,477
93.575 Scholars for Excellence in Child Care $74,816
93.788 Opioid Str $47,772
84.335 Childcare Access Means Parents in School $44,192
84.048 Career and Technical Education - Basic Grants to States - Carl D. Perkins $42,318