Finding 961205 (2023-001)

Significant Deficiency
Requirement
N
Questioned Costs
-
Year
2023
Accepted
2024-03-26
Audit: 297875
Organization: Milwaukee School of Engineering (WI)

AI Summary

  • Core Issue: The University lacks documented controls to ensure compliance with the updated information security requirements under the GLBA Safeguards Rule.
  • Impacted Requirements: Institutions must have a comprehensive information security program in place by June 9, 2023, as mandated by the FTC's final regulations.
  • Recommended Follow-Up: The University should review and document their policies and procedures to ensure compliance with the Uniform Guidance and the Safeguards Rule.

Finding Text

Agencies: US Department of Education Assistance Listing Numbers: Student Financial Assistance Cluster: 84.033, 84.007, 84.063, 84.268, 84.038 Programs: Federal Work Study Program, Federal Supplemental Educational Opportunity Grant Program, Federal Pell Grant Program, Federal Direct Student Loans, Federal Perkins Loan Program, Criteria: The University is required to have documented internal controls in place to monitor compliance over special tests in accordance with the Uniform Guidance. On December 9, 2021, the Federal Trade Commission issued final regulations for 16 Code of Federal Regulations Part 314 to implement the Gramm-Leach-Bliley Act information safeguarding standards that institutions must implement. These regulations significantly modified the requirements that institutions must meet under GLBA. The regulations established minimum standards that institutions must meet. The FTC stated that it "believes many of the requirements set forth in the Final Rule are so fundamental to any information security program that the information security programs of many financial institutions will already include them if those programs are in compliance with the current Safeguards Rule." Institutions are required to be in compliance with the revised requirements no later than June 9, 2023. Institutions are required to develop, implement and maintain a comprehensive information security program that is written in one or more readily accessible parts. Statement of Condition: The University did not have documented controls in place reviewing that the comprehensive information security program was in compliance with the Safeguards Rule and was prepared and in place by June 9, 2023. Questioned Costs: The amount of any questioned costs could not be determined. Context: The University is required to have documented controls in place to ensure the University has a completed information security program available on or before June 9, 2023. Cause: The University did not have the proper controls in place to ensure that the University was compliant with GLBA Safeguards requirements in the timeframe specified by 16 CFR Part 314. Effect: The ability to adequately safeguard student electronic data may be compromised if the University does not have controls in place to ensure that a timely-prepared information security program to define the various ways in which data is protected is completed. Recommendation: We recommend the University review their policies and procedures in place to ensure that the information security program review is documented to support the University's compliance under the Uniform Guidance. Management's Response: Management agrees with the finding and recommendation. New controls will be implemented in fiscal year 2024 to ensure that the information security review is appropriately documented and there is evidence of review.

Categories

Student Financial Aid Matching / Level of Effort / Earmarking Internal Control / Segregation of Duties Special Tests & Provisions

Other Findings in this Audit

  • 384759 2023-001
    Significant Deficiency
  • 384760 2023-001
    Significant Deficiency
  • 384761 2023-001
    Significant Deficiency
  • 384762 2023-001
    Significant Deficiency
  • 384763 2023-001
    Significant Deficiency
  • 961201 2023-001
    Significant Deficiency
  • 961202 2023-001
    Significant Deficiency
  • 961203 2023-001
    Significant Deficiency
  • 961204 2023-001
    Significant Deficiency

Programs in Audit

ALN Program Name Expenditures
84.268 Federal Direct Student Loans $14.28M
84.063 Federal Pell Grant Program $2.77M
84.038 Federal Perkins Loan $702,240
84.033 Federal Work-Study Program $278,938
84.007 Federal Supplemental Educational Opportunity Grants $255,716
93.350 National Center for Advancing Translational Sciences $111,720
47.070 Computer and Information Science and Engineering $74,496
47.076 Education and Human Resources $36,434
47.041 Engineering $29,680
93.859 Biomedical Research and Research Training $21,040
93.394 Cancer Detection and Diagnosis Research $15,007
43.008 Education $11,492
84.126 Rehabilitation Services_vocational Rehabilitation Grants to States $3,933