Finding Text
Gramm-Leach-Bliley Act (GLBA) Compliance Other Matter
DEPARTMENT OF EDUCATION
ALN #: 84.268, 84.063, 84.007, 84.033, 84.038 and 84.379; Student Financial Assistance Cluster
Federal Award Identification #: 2022-2023 Financial Aid Year
Condition: The University has gaps in two areas with the updated requirements of GLBA.
Criteria: 16 CFR 314.4
Questioned Costs: $0
Context: The University has not implemented multi-factor authentication on one system containing non-financial personally identifiable information (PII). Additionally, the written annual report to the board does not include all the required areas based on the updated regulations.
Cause: The University has made significant progress on GLBA and has a couple of components to be in full compliance with the updated requirements of GLBA. University personnel were unaware of the system’s ability to support MFA.
Effect: The University may have unintended exposure of non-financial student information to security risks.
Identification as repeat finding, if applicable: n/a
Recommendation: We recommend the University implement the remaining components of the revised regulations.
Views of Responsible Officials and Planned Corrective Action: Management agrees with the finding. See corrective action plan.