Finding 972179 (2023-002)

-
Requirement
N
Questioned Costs
-
Year
2023
Accepted
2024-05-02
Audit: 305378
Organization: Hudson Valley Community College (NY)
Auditor: Uhy LLP

AI Summary

  • Core Issue: The College missed the June 9, 2023 deadline to implement multi-factor authentication (MFA) for the WIReD system.
  • Impacted Requirements: This delay puts the College out of compliance with the Safeguards Rule under the Gramm-Leach-Bliley Act.
  • Recommended Follow-Up: Implement MFA for all systems promptly and update the Information Security Program to reflect this, along with enhancing training for future compliance.

Finding Text

CFDA Number: Various – SFA Cluster Criteria: Per 16 CFR 314.4 (c)(5), the College is required to implement multi-factor authentication for any individual accessing any information system, unless the Qualified Individual has approved in writing the use of reasonably equivalent or more secure access controls. Per the FSA Electronic Announcement GENERAL-23-09, institutions were required to implement this rule by June 9, 2023. Condition: The College did not fully implement multi-factor authentication by June 9, 2023, which was the effective deadline. Cause: The College is currently still in the process of implementing multi-factor authentication on the WIReD system. Effect: The College is not in compliance with the requirement set by the Safeguards Rule under the Gramm-Leach-Bliley Act. Prevalence: Implementing multi-factor authentication proved to be more complicated and timeconsuming for the student information system WIReD. Multi-factor authentication or equivalent access controls are in place for all other systems containing student information, and all other elements of the Safeguards Rule appear to be in place as required. Recommendation: The College should implement multi-factor authentication for all systems as soon as possible and reference MFA in the written Information Security Program. The College should also enhance its training and procedures to ensure that any future adjustments to Gramm Leach Bliley Act continue to be met in a timely manner. Management’s Response and Planned Corrective Action: Management acknowledged that implementation of multi-factor authentication for the WIReD system has taken more time due to the complexity of the systems in place. The multi-factor authentication on the WIReD system was implemented and went into effect on March 26, 2024.

Categories

No categories assigned yet.

Other Findings in this Audit

Programs in Audit

ALN Program Name Expenditures
84.063 Federal Pell Grant Program $11.77M
84.268 Federal Direct Student Loans $11.04M
84.048 Career and Technical Education -- Basic Grants to States $563,302
84.007 Federal Supplemental Educational Opportunity Grants $295,614
84.033 Federal Work-Study Program $175,556
47.076 Education and Human Resources $160,717
64.027 Post-9/11 Veterans Educational Assistance $148,245
84.126 Rehabilitation Services_vocational Rehabilitation Grants to States $41,930
84.425 Education Stabilization Fund $1,753
17.285 Apprenticeship USA Grants $-1,050