EIN: 386034011
UEI: G36SD7DNM3H6
Data as of August 27, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on March 11, 2020. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by September 11, 2020 (2176 days ago).
What is a management decision? →The College did not complete a risk assessment that addresses the three areas noted in 16 CFR 314.4(b) which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and (3) detecting, preventing, and responding to attacks, intrusions, or other systems failures. Under 16 CFR 314.4(b) the College must also document safeguards for identified risks. Cause: The College uses a third-party IT service provider for IT related tasks and relied on that service provider to ensure that all compliance requirements were met. However, neither the College nor the third-party service provider performed an IT risk assessment tailored specifically to identifying risks or addressing risks as required by GLBA. Effect: The College may not be aware of risks to student information and therefore may not have implemented proper security controls. Recommendation: We recommend that the College formalize a risk assessment which, at a minimum, addresses the required areas. Views of Responsible Officials and Planned Corrective Actions: The College agrees with the findings and is in the process of formalizing a risk assessment to address, at a minimum, the required areas described above.
Show full finding ▾Hide full finding ▴2019-001 Information Security Program and Risk Assessment Student Financial Aid Cluster; Grant period ? year ended June 30, 2019 Criteria: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to safeguard sensitive data in compliance with 16 CFR 314. The Federal Trade Commission considers Title IV institutions that participate in Education Assistance Programs to be ?financial institutions? and subject to the Gramm-Leach-Bliley Act. Under the Gramm-Leach-Bliley Act, institutions must protect student financial aid information, including assessing risks to that information. Condition: The College did not complete a risk assessment that addresses the three areas noted in 16 CFR 314.4(b) which are (1) employee training and management; (2) information systems, including network and software design, as well as information processing, storage, transmission, and disposal; and (3) detecting, preventing, and responding to attacks, intrusions, or other systems failures. Under 16 CFR 314.4(b) the College must also document safeguards for identified risks. Cause: The College uses a third-party IT service provider for IT related tasks and relied on that service provider to ensure that all compliance requirements were met. However, neither the College nor the third-party service provider performed an IT risk assessment tailored specifically to identifying risks or addressing risks as required by GLBA. Effect: The College may not be aware of risks to student information and therefore may not have implemented proper security controls. Recommendation: We recommend that the College formalize a risk assessment which, at a minimum, addresses the required areas. Views of Responsible Officials and Planned Corrective Actions: The College agrees with the findings and is in the process of formalizing a risk assessment to address, at a minimum, the required areas described above.
February 10, 2020 Federal Audit Clearinghouse Corrective Action Plan Fiscal Year Ended June 30, 2019 Finding Number: 2019-001 Information Security Program and Risk Assessment Condition: The College did not complete a risk assessment that addresses the three areas noted in 314.4(b) which are (1) Employee training and management; (2) Information systems, including network and software design, as well as information processing, storage, transmission, and disposal, and (3) Detecting, preventing, and responding to attaches, intrusions, or other systems failures. Under 16 CFR 314.4(b) the College must also document safeguards for identified risks. Planned Corrective Action: The College concurs with the finding and is in the process of developing a team to be responsible for complying with the provisions of the Gramm-Leach-Bliley Act (16 CFR 313.3(k)(2)(vi), including identifying an individual to be responsible for coordinating the information security program to protect sensitive data, performing a risk assessment that addresses the three areas noted in 16 CFR 314.4(b) and documenting safeguards for identified risks. Contact person responsible for corrective action: Sarah Dufresne, Vice President of Business & Finance and Bill Wesolek, Director of Information Technology Services. Anticipated Completion Date: June 2020
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.