Finding Text
Criteria : The BOCES is required to, per the GLBA, develop, implement, and maintain a comprehensive
information security program that is written in one or more readily accessible parts and that addresses the seven
elements required within the act. Condition: The BOCES did not implement all seven of the required elements.
Cause: The written policies and procedures did not contain all the required elements as outlined in the GLBA.
Effect: The BOCES was not in compliance with all aspects of the GLBA.
Context: Inquiry, observation and examination of information received from the BOCES related to compliance
with GLBA.
Auditor's Recommendation : The BOCES should review the GLBA requirements as soon as practical and
implement and document all the required elements of GLBA.