Finding 2023-06 – Special Tests and Provisions: Gramm-Leach-Bliley Act–Student Information Security
Recommendation
The College should develop and implement a comprehensive GLBA information security program that includes risk assessments, safeguards, and regular testing and monitoring of the effectiveness of these safeguards. A qualified individual with the necessary expertise and authority to oversee the GLBA information security program should also be designated. Provide training to relevant staff on GLBA requirements and the importance of information security. Conduct periodic reviews and updates of the information security program to ensure ongoing compliance with GLBA requirements.
Response
The college acknowledges the finding and will strengthen its student information security by implementing the following:
1) Designate a qualified Information Security Officer from within the IT Division or recruit externally if internal capacity is limited. 2) Develop a GLBA compliance program that includes:
• Annual risk assessments
• Implementation of administrative, technical, and physical safeguards
• Staff training on data privacy
• Annual testing of the security protocols
Contact: Vice President for Institutional Effectiveness & Quality Assurance (VPIEQA)
Completion Date: September 30, 2025