Yuba Community College District

EIN: 680447767

UEI: GZJ4C839SNB1

Data as of August 23, 2026

Yuba Community College District9 audit years2 findings1 repeat
9
Audit Years
2
Total Findings
1
Repeat Findings

FY 2020-06-30

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on June 9, 2021. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by December 9, 2021 (1719 days ago).

What is a management decision? →
2020-002
Special Tests & Provisions
REPEAT

FINDING #2020-002 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA after the close of the fiscal year. The District will be in compliance beginning in fiscal year 2020-21. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue to assess any changes to maintain compliance with any changes to GLBA. Management's Response and Corrective Action Plan The District has taken the necessary steps to ensure compliance with the GLBA and as of the audit report date, the district has implemented all areas and will be in compliance for fiscal year 2020-21.

Show full finding ▾
Full finding narrative

FINDING #2020-002 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA after the close of the fiscal year. The District will be in compliance beginning in fiscal year 2020-21. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue to assess any changes to maintain compliance with any changes to GLBA. Management's Response and Corrective Action Plan The District has taken the necessary steps to ensure compliance with the GLBA and as of the audit report date, the district has implemented all areas and will be in compliance for fiscal year 2020-21.

Corrective Action Plan

The District has taken the necessary steps to ensure compliance with the GLBA and as of the audit report date, the district has implemented all areas and will be in compliance for fiscal year 2020-21.

Prior Finding References

2019-004

About Special Tests and Provisions →

FY 2019-06-30

FAC accepted this audit on April 23, 2020 — management decision was due October 23, 2020.

2019-004
Special Tests & Provisions

FINDING #2019-004 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA, with the exception of the final step; the development of the response is currently underway with anticipated completion and implementation during 2019-20. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue towards full implementation of its documented response to the GLBA Safeguards Rule in the 2019-20 year. Management's Response and Corrective Action Plan YCCD District Administrators have designated the Director of IT Infrastructure and Security position as the District?s Information Security Officer and charged the incumbent with the responsibilities of managing the District?s Information Security. Further, the District has identified several external vendors to perform an Information Security Assessment. Findings from this assessment will augment the security controls that have been implemented since 4/2018 and will be utilized to reduce risk of known issues, provide building blocks for the District?s Information Security Program, and act as a baseline for the ongoing evaluation of the program. The District agrees to have completed documented responses to the GLBA Safeguards Rule by 12/31/2020.

Show full finding ▾
Full finding narrative

FINDING #2019-004 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Criteria or Specific Requirement The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. Condition We noted that the District has completed all steps towards compliance with GLBA, with the exception of the final step; the development of the response is currently underway with anticipated completion and implementation during 2019-20. Questioned Costs ? Not applicable. Context Compliance with GLBA requirements. Effect The intent of the GLBA Safeguards Rule is to enhance security over confidential information. Without a documented response to all applicable requirements, the District is more susceptible to IT vulnerabilities than it will be following full implementation. Cause The law was effective towards the end of the fiscal and provided minimal amount of time to administration to implement. Steps taken in response to GLBA compliance requirements will require extensive administrative efforts to implement.Recommendation The District should continue towards full implementation of its documented response to the GLBA Safeguards Rule in the 2019-20 year. Management's Response and Corrective Action Plan YCCD District Administrators have designated the Director of IT Infrastructure and Security position as the District?s Information Security Officer and charged the incumbent with the responsibilities of managing the District?s Information Security. Further, the District has identified several external vendors to perform an Information Security Assessment. Findings from this assessment will augment the security controls that have been implemented since 4/2018 and will be utilized to reduce risk of known issues, provide building blocks for the District?s Information Security Program, and act as a baseline for the ongoing evaluation of the program. The District agrees to have completed documented responses to the GLBA Safeguards Rule by 12/31/2020.

Corrective Action Plan

FINDING #2019-04 ? GRAMM-LEACH-BLILEY ACT COMPLIANCE Finding: The Gramm-Leach Bliley Act (GLBA) requires districts to have a documented response to the Safeguards Rule. Specifically, this response covers key requirements including: ? Designate an information security officer and related oversight responsibilities for the institution?s security. ? Assess the risks to confidential information, assess the level of mitigating controls in place, and identify action plans to accept or further mitigate remaining risks. ? Implement an information security program, including various technical and physical underlying controls, such as data encryption and secure shredding processes. ? Oversee vendor relationships to ensure confidential data are secured at their locations when applicable and access is controlled when vendors connect to the institution. ? Perform an ongoing evaluation of their program to keep content current with an ever-evolving security environment. We noted that the District has completed all steps towards compliance with GLBA, with the exception of the final step; the development of the response is currently underway with anticipated completion and implementation during 2019-20. Recommendation: The District should continue towards full implementation of its documented response to the GLBA Safeguards Rule in the 2019-20 year. Management's Response and Corrective Action Plan: YCCD District Administrators have designated the Director of IT Infrastructure and Security position as the District?s Information Security Officer and charged the incumbent with the responsibilities of managing the District?s Information Security. Further, the District has identified several external vendors to perform an Information Security Assessment. Findings from this assessment will augment the security controls that have been implemented since 4/2018 and will be utilized to reduce risk of known issues, provide building blocks for the District?s Information Security Program, and act as a baseline for the ongoing evaluation of the program. The District agrees to have completed documented responses to the GLBA Safeguards Rule by 12/31/2020.

About Special Tests and Provisions →

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and compliance status.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.