Finding Text
Federal Agency: U.S. Department of Education
Federal Program Name: Student Financial Aid Cluster
Assistance Listing Number: 84.007, 84.033, 84.063, 84.268
Federal Award Identification Number and Year: P007A214563-2023, P033A214563-2023, P063P212632-2023, P268K222632-2023
Award Period: July 1, 2022 through June 30, 2023
Type of Finding:
• Significant Deficiency in Internal Control over Compliance
• Other Matters
Criteria or specific requirement: The District is responsible for the design and implementation of safeguards to control the risks the institution identifies through its risk assessment (16 CFR 314.4(c)). At a minimum, the institution’s written information security program must address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8). The minimum safeguards include eight required written information security program.
Condition: The District's written information security program address 6 of the 8 minimum safeguards identified in the related regulations. The District's policy did not include written documentation for the remaining two required minimum safeguards.
Questioned costs: None
Context: The District's written information security program is in process of continued review and updating. During the year under audit, the required safeguards were not fully updated in the written policies.
Cause: The District's policy reviews for compliance with the noted requirements were not completed prior to the fiscal year.
Effect: The District's polices and procedures may not comply with all applicable requirements.
Repeat Finding: The finding is not a repeat finding.
Recommendation: We recommend the District review and update as necessary the written information security program(s) to include aspects required by regulations.
Views of responsible officials: There is no disagreement with the audit finding. While WCTC has implemented practices that ensure the safeguards are in place, the appropriate documentation had not yet been updated. WCTC has completed the recommended revisions as required by the standards.