Finding Text
Criteria: Special Test – Gramm-Leach-Bliley Act – Student Information Security – The Gramm-Leach- Bliley Act (Public Law 106-102) requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. (16 CFR 314) The Federal Trade Commission considers Title IV-eligible institutions that participate in Title IV Educational Assistance Programs as “financial institutions” and subject to the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi). Under an institution’s Program Participation Agreement with the Department of Education and the Gramm-Leach-Bliley Act , schools must protect student financial aid information, with particular attention to information provided to institutions by the Department or otherwise obtained in support of the administration of the federal student financial aid programs. (16 CFR 314.3; HEA 483(a)(3)(E) and HEA 485B(d)(2)).
Condition: The College must have a written information security program to address the implementation of the minimum safeguards identified in 16 CFR 314.4(c)(1) through (8).
Questioned Costs: None
Context: The College has designated an individual to coordinate the information security program, and
the College has procedures in place to perform a risk assessment and safeguard the security of student information; however, the College does not have a written information security program in accordance with the condition stated above.
Effect: Non-compliance with program requirements.
Cause: Internal controls were not adequately designed and implemented to ensure compliance with
the program’s requirements.
Identification as a Repeat Finding, if Applicable: N/A
Recommendation: We recommend management continue to formalize their written policies and procedures for a information security to ensure program compliance the College complies with the program’s compliance requirements.
Views of Responsible Officials and Planned Corrective Actions: Administration concurs with the finding. See Management’s Corrective Action Plan.