EIN: 680447767
UEI: GZJ4C839SNB1
Data as of August 23, 2026
Management decision deadline — for entities that funded this organization
The FAC accepted this audit on June 9, 2021. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by December 9, 2021 (1719 days ago).
What is a management decision? →FINDING #2020-002 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA after the close of the fiscal year. The District will be in compliance beginning in fiscal year 2020-21. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue to assess any changes to maintain compliance with any changes to GLBA. Management's Response and Corrective Action Plan The District has taken the necessary steps to ensure compliance with the GLBA and as of the audit report date, the district has implemented all areas and will be in compliance for fiscal year 2020-21.
Show full finding ▾Hide full finding ▴FINDING #2020-002 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA after the close of the fiscal year. The District will be in compliance beginning in fiscal year 2020-21. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue to assess any changes to maintain compliance with any changes to GLBA. Management's Response and Corrective Action Plan The District has taken the necessary steps to ensure compliance with the GLBA and as of the audit report date, the district has implemented all areas and will be in compliance for fiscal year 2020-21.
The District has taken the necessary steps to ensure compliance with the GLBA and as of the audit report date, the district has implemented all areas and will be in compliance for fiscal year 2020-21.
2019-004
FAC accepted this audit on April 23, 2020 — management decision was due October 23, 2020.
FINDING #2019-004 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA, with the exception of the final step; the development of the response is currently underway with anticipated completion and implementation during 2019-20. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue towards full implementation of its documented response to the GLBA Safeguards Rule in the 2019-20 year. Management's Response and Corrective Action Plan YCCD District Administrators have designated the Director of IT Infrastructure and Security position as the District?s Information Security Officer and charged the incumbent with the responsibilities of managing the District?s Information Security. Further, the District has identified several external vendors to perform an Information Security Assessment. Findings from this assessment will augment the security controls that have been implemented since 4/2018 and will be utilized to reduce risk of known issues, provide building blocks for the District?s Information Security Program, and act as a baseline for the ongoing evaluation of the program. The District agrees to have completed documented responses to the GLBA Safeguards Rule by 12/31/2020.
Show full finding ▾Hide full finding ▴FINDING #2019-004 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA, with the exception of the final step; the development of the response is currently underway with anticipated completion and implementation during 2019-20. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue towards full implementation of its documented response to the GLBA Safeguards Rule in the 2019-20 year. Management's Response and Corrective Action Plan YCCD District Administrators have designated the Director of IT Infrastructure and Security position as the District?s Information Security Officer and charged the incumbent with the responsibilities of managing the District?s Information Security. Further, the District has identified several external vendors to perform an Information Security Assessment. Findings from this assessment will augment the security controls that have been implemented since 4/2018 and will be utilized to reduce risk of known issues, provide building blocks for the District?s Information Security Program, and act as a baseline for the ongoing evaluation of the program. The District agrees to have completed documented responses to the GLBA Safeguards Rule by 12/31/2020.
FINDING #2019-04 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Finding: The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. We noted that the District has completed all steps towards compliance with GLBA, with the exception of the final step; the development of the response is currently underway with anticipated completion and implementation during 2019-20. Recommendation: The District should continue towards full implementation of its documented response to the GLBA Safeguards Rule in the 2019-20 year. Management's Response and Corrective Action Plan: YCCD District Administrators have designated the Director of IT Infrastructure and Security position as the District?s Information Security Officer and charged the incumbent with the responsibilities of managing the District?s Information Security. Further, the District has identified several external vendors to perform an Information Security Assessment. Findings from this assessment will augment the security controls that have been implemented since 4/2018 and will be utilized to reduce risk of known issues, provide building blocks for the District?s Information Security Program, and act as a baseline for the ongoing evaluation of the program. The District agrees to have completed documented responses to the GLBA Safeguards Rule by 12/31/2020.
Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.
Track your findings and corrective action plans across audit cycles.
Start tracking findings →Monitor subrecipient audit findings and compliance status.
Start monitoring →© 2026 Single Audit Intelligence. All data is public domain.