Finding 394949 (2023-004)

-
Requirement
N
Questioned Costs
-
Year
2023
Accepted
2024-04-28

AI Summary

  • Core Issue: The University has not developed a required written information security program (WISP) for protecting student data.
  • Impacted Requirements: This noncompliance violates 16 CFR 314 and the Gramm-Leach-Bliley Act (GLBA).
  • Recommended Follow-Up: Create and implement a WISP immediately to safeguard confidential student information.

Finding Text

Information on the federal program: Student Financial Assistance Cluster; United States Department of Education; Award Year 2022-23: Compliance Requirement – Special Tests and Provisions; Type of Finding: Material Noncompliance. Criteria: 16 CFR 314 requires that higher education institutions develop, implement, and maintain a comprehensive written information security program (WISP) in compliance with the Gramm-Leach-Bliley Act (GLBA). Condition: The University has not established a WISP. Cause: The University’s IT personnel were not made aware of this compliance requirement. Effect: Confidential student financial and other information could be exposed to the risk of outside parties gaining access. Questioned Costs: n/a for this finding. Context: All confidential student financial and other information could be affected if the information security procedures are not adequate. Recommendations: Formulate a WISP and follow its procedures as soon as possible. Responsible Official’s Response and Corrective Action Planned: see corrective action plan.

Categories

Special Tests & Provisions

Other Findings in this Audit

Programs in Audit

ALN Program Name Expenditures
84.268 Federal Direct Student Loans $4.07M
84.063 Federal Pell Grant Program $1.67M
84.031 Higher Education_institutional Aid $596,567
84.033 Federal Work-Study Program $136,300
84.007 Federal Supplemental Educational Opportunity Grants $90,034
84.425 Education Stabilization Fund $31,861
15.364 Competitive State Wildlife Grant $17,179