GLBA-HE-314.3 | Information Security Program | 1 |
GLBA-HE-314.4(a) | Qualified Individual | 1 |
GLBA-HE-314.4(b) | Risk Assessment | 0 |
GLBA-HE-314.4(c)(1) | Access Controls | 1 |
GLBA-HE-314.4(c)(2) | Data Inventory and Classification | 1 |
GLBA-HE-314.4(c)(3) | Encryption of Customer Information | 1 |
GLBA-HE-314.4(c)(4) | Secure Development Practices | 1 |
GLBA-HE-314.4(c)(5) | Multi-Factor Authentication | 1 |
GLBA-HE-314.4(c)(6) | Secure Disposal | 1 |
GLBA-HE-314.4(c)(7) | Change Management | 1 |
GLBA-HE-314.4(c)(8) | Logging and Monitoring of Authorized Users | 1 |
GLBA-HE-314.4(d) | Testing and Monitoring of Safeguards | 1 |
GLBA-HE-314.4(e) | Security Awareness Training | 1 |
GLBA-HE-314.4(f) | Service Provider Oversight | 1 |
GLBA-HE-314.4(g) | Program Evaluation and Adjustment | 1 |
GLBA-HE-314.4(h) | Incident Response Plan | 1 |
GLBA-HE-314.4(i) | Annual Report to Board | 0 |
GLBA-HE-314.5 | Notification of Security Event | 1 |
GLBA-HE-DoE-PPA | Title IV Program Participation Agreement Compliance | 0 |
GLBA-HE-Privacy-Notice | Privacy Notices and Opt Out | 0 |
HE-1 | Financial institution status of higher education | 6 |
HE-2 | Student financial information as customer information | 0 |
HE-3 | FSA compliance requirements | 64 |
HE-4 | Institutional governance integration | 0 |
USGLBAHIGHER-1 | Qualified Individual and Risk Assessment | 97 |
USGLBAHIGHER-2 | Access Controls, Encryption, MFA, Inventory | 0 |
USGLBAHIGHER-3 | Continuous Monitoring, Testing, Vendor Oversight | 130 |
USGLBAHIGHER-4 | Incident Response and Notification | 87 |