The Gramm-Leach-Bliley Act

Executive Commitment

St. John’s University is committed to protecting the confidentiality, integrity, and availability of customer financial information. In alignment with the Federal Trade Commission (FTC)’s Safeguards Rule under the Gramm‑Leach‑Bliley Act (GLBA), the University maintains a comprehensive, institution‑wide, information security program designed to identify, assess, and mitigate risks to covered data.

The Gramm-Leach-Bliley Act

The Gramm-Leach-Bliley Act, effective May 23, 2003, establishes requirements for safeguarding and maintaining the confidentiality of customer information held by financial institutions, including banks and investment companies. GLBA does not provide an exemption for colleges or universities. In 2021, the Federal Trade Commission (FTC) issued amendments that revised compliance obligations for higher education institutions with a financial relationship to the Title IV Program. Accordingly, educational entities that engage in financial activities, including the processing of student loans, are subject to GLBA compliance requirements. GLBA, together with other emerging legislation, may establish applicable standards of care for information security across all data management practices, including employee, student, customer, alumni, and donor information maintained in both electronic and physical formats. The changes outlined below will directly affect existing compliance policies. Current Compliance Policies will have a direct impact from the changes listed below:

  • designate a qualified individual to oversee their information security program;
  • develop a written risk assessment;
  • limit and monitor who can access sensitive customer information;
  • encrypt all sensitive information;
  • train security personnel;
  • develop an incident response plan; and
  • periodically assess the security practices of service providers and implement multifactor authentication or another method with equivalent protection for any individual accessing customer information.

These updates to current compliance policies at St. John’s University are for certain highly critical and private financial and related information. This Compliance Program applies to customer financial information (covered data) that the University receives in the course of business as required by GLBA, as well as other confidential financial information included within its scope.

GLBA Compliance Program

The GLBA Compliance Program covers the entirety of the activities and practices of the following offices and individuals:

  • Academic and administrative offices that handle electronic or printed personnel records, financial records, transactional records, or student records.

  • Academic and administrative offices that transmit confidential information (protected data) to off-site locations as part of a periodic review or submission requirement.

  • Centers and institutes that provide services and acquire personal or financial information from participants or constituents.

  • Faculty serving as directors, coordinators, principal investigators, or program directors for programs collecting protected data.

  • Faculty, administrators, and staff with contracts to use, access, or provide protected data to or receive from a non-campus entity (e.g., government databases, science databases).

Categories of Information Under the Plan

Information covered under the plan is defined by three categories:

  • Personal Identifiable Information (PII) – Also known as protected data, PII includes first and last name, social security number, date of birth, home address, home telephone number, academic performance record, physical description, medical history, disciplinary history, gender, and ethnicity.

  • Financial Information – Information that the University has obtained from faculty, staff, students, alumni, auxiliary agencies, and patrons in the process of offering financial aid or conducting a program. Examples include bank and credit card account numbers, and income and credit histories.

  • Student Financial Information – Information that the University has obtained from a student in the process of offering a financial product or service, or such information provided to the University by another financial institution. Examples include student loans, income tax information received from a student’s parent when offering a financial aid package, bank and credit card account numbers, and income and credit histories.

Key Points

  • The Compliance Program is a continuous process that is undertaken at periodic intervals.

  • The GLBA Compliance Program Coordinator is responsible for implementing this Compliance Program.

  • The Office of Information Technology, with the collaboration of Human Resources, develop appropriate training programs to ensure administrators and staff are aware of protocols for protecting customer information.

  • All contracts with service providers that access covered customer information must (i) obligate providers to maintain safeguards consistent with GLBA, (ii) permit St. John’s to assess or obtain reasonable assurance of controls (e.g., SOC 2, HECVAT), and (iii) require prompt notice of security events impacting covered data.

  • The Coordinator, working with responsible units and offices, monitors, evaluates, and adjusts the Compliance Program in light of the results of the risk management process.

Purpose

To continue protecting private information and data and to comply with the Federal Trade Commission’s safeguard rules implementing the GLBA, the University has adopted this Compliance Program for certain highly critical and private financial and related information. The Compliance Program forms part of the University’s overall strategic information security program.

This page describes many of the activities undertaken by the University to maintain the security and privacy of the covered data in accordance with GLBA requirements.

Scope and Applicability

This program protects covered customer information processed by St. John’s in connection with Title IV financial activities and other financial services, consistent with the FTC Safeguards Rule (16 CFR Part 314). The Compliance Program forms part of the University’s overall strategic information security program. This program applies to customer financial information (covered data) the University receives during business as required by GLBA, as well as other confidential financial information the University has voluntarily chosen as a matter of policy to include within its scope.

The following table illustrates the mapping of the departments that fall under the scope of the GLBA Safeguard Rules.

GLBA Safeguard Rules Scope for Title IV Schools

  • Student loans (St. John’s loans, bank loans, and federal loans)

  • Private Student loans

  • Personal Identifiable Information - SSN, Billing Information, Credit Card, Account Balance, Citizenship, Passport Information, Tax Return Information, Bank Account Information, Driver’s License and Date of Birth

  • Disbursement of Financial Aid

  • Payment Plans

  • 1098

  • Financial Aid

  • Bursar

  • Office of Admission

  • Office of the Registrar

  • International Student and Scholar Services Office

  • The Language Connection

  • The School of Law

     

  • Personal Identifiable Information - SSN, Billing Information, Credit Card, Account Balance, Passport Information, Tax Return Information, Bank Account Information, Driver’s License and Date of Birth

  • Office of the General Counsel
  • 403(b) loans
  • Emergency faculty loans
  • Emergency staff loans
  • Payroll W2s
  • Human Resources (HR)
  • G5 drawdown of federal funds

  • Refunds and T & E payments

  • Reconciliations

  • Coordination of Audits

  • 1099

  • Business Affairs

This section discusses the main roles and responsibilities required to effectively execute the GLBA Compliance program.

RolesResponsibilities
Chief Information Officer

· Designates or serves as the GLBA Compliance Plan Coordinator.

· Responsible for systemwide compliance with the GLBA Safeguarding Rule through appropriate communication with and coordination among applicable groups.

· Designates individuals who have the responsibility and authority for information technology resources.

Information Technology Security Office

· Establishes and disseminates enforceable rules regarding access to and acceptable use of information technology resources.

· Establishes reasonable security policies and measures to protect data and systems.

· Monitors and manages system resource usage.

· Investigates problems and alleged violations of University information technology policies and report violations to appropriate University offices such as the Office of the General Counsel and Human Resources Department for resolution or disciplinary action.

Deans, Department Heads and other Managers

 

· Keep employees informed about policies and programs that pertain to their work, including those that govern GLBA compliance and ensure that they successful complete the required training.

 

Employees with access to covered data

· Abide by University policies and procedures governing covered data as well as any additional practices or procedures established by their unit heads or directors.

· Report concerns to their supervisor

Campus Controller· Assist units with setting risk evaluation schedules and processes as requested.
University Auditors and Cross-department GLBA working team· Review conformance to the GLBA Compliance Plan as part of routine internal audits.

The GLBA Compliance Program Coordinator (Coordinator) serves as the University’s FTC‑designated ‘Qualified Individual,’ with authority and expertise to develop, implement, and oversee the information security program required under 16 CFR Part 314.

The GLBA Compliance Program Coordinator (Qualified Individual) implements and reports on the program and may delegate specific elements to appropriate offices while maintaining overall accountability. The Coordinator is appointed by the Vice President for Business Affairs.

The Coordinator:

  • Works closely with the University Registrar, Human Resources, the Office of the General Counsel, the Office of the Bursar, the Office of Student Financial Aid, the Internal Audit Department, and such other offices and units as they have an interface with or control over covered data.

  • Consults with responsible offices to identify units and areas of the University with access to covered data. As part of this Compliance Program, the Coordinator has identified University units and areas with access to covered data.

  • Conducts surveys or utilizes other reasonable measures to confirm that all areas with covered information are included within the scope of this Compliance Program. The Coordinator maintains a list of University areas and units with access to covered data.

  • Ensures that risk assessments and monitoring are carried out for each unit or area that has covered data and that appropriate controls are in place for the identified risks.

  • Works to ensure adequate training and education are developed and delivered for all employees with access to covered data.

  • Verifies that existing policies, standards, and guidelines that provide for the security of covered data are reviewed and adequate.

  • Makes recommendations for revisions to policy, or the development of new policy, as appropriate.

  • Updates this Compliance Program, including this and related documents, from time to time.

  • Ensures the written security plan is maintained and makes the plan available to the University community.

Keeping security risks at a low is St. John’s priority. The University’s information security structure ensures that risks of any kind are minimized. There is quality assurance that comprehensive processes are in place for best practices and information protection. The areas are listed below:

  • Risk Assessment
    • Third-party Risk Management
  • Vulnerability Assessment and Penetration Testing
  • Vulnerability and Patch Management
  • Access Control
  • Acceptable Use
  • Cryptography
  • Security Awareness, Training, and Education
  • Incident Response

The Compliance Program identifies the flow of the data processed throughout the University to assist in the identification of risks to privacy and security. This activity includes determining

  • The types of data being processed by the various business units
  • The format of the data processed, and the location of the data being used and stored
  • The purpose of the data being processed
  • Identifies reasonably foreseeable external and internal risks to the security, confidentiality, and integrity of covered data that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromises of such information; and
  • Assesses the sufficiency of any safeguards in place to control these risks.
  • The Coordinator works with all relevant departments to carry out comprehensive risk assessments

Risk assessments are conducted at least annually and upon material changes to business processes, technology, or the threat landscape. Assessments identify reasonably foreseeable internal and external threats, evaluate likelihood and impact, and document decisions regarding risk mitigation, acceptance, or remediation. Findings drive the design, testing, and monitoring of safeguards.

This process includes system-wide risks as well as risks unique to each area with covered data, and the effectiveness of management practices currently in place to ensure compliance and security enhancement. Risk assessments shall include consideration of risks in each relevant area of operations and cover processes for handling, storing, and disposing of the paper records; processes for detecting, preventing, and responding to security failures; and employee training and management, including the appropriateness and frequency of staff and management security awareness training.

As a result of the risk assessment, recommendations are made as necessary to change management practices to improve business controls and/or to implement information safeguards. The University has developed a set of policies and procedures to guide the security and privacy of data covered by GLBA.

St. John’s University is diligent in its routine testing and monitoring of its systems, and the safeguards implemented are based on the outcomes of the risk assessment.

The University ensures vulnerability assessment on systems that transmit, process, or store covered data.

Access control is St. John’s University’s ability to maintain, implement, and control its policies, standards, and procedures.

To control the integrity and privacy of data that is processed, stored, and transmitted, the University uses industry acceptable and approved encryption algorithms and solutions for access control. St. John’s encrypts covered customer information both in transit and at rest. Where encryption is not feasible, documented compensating controls are approved by the qualified individual and reviewed routinely.

Multifactor Authentication is required for all users accessing systems that store or process covered customer information.

St. John’s University is diligent in its data collection, retention, and disposal efforts. The University’s record retention process is in accordance with the GBLA. The program

  • Removes the maintenance of unnecessary documents from the onset of data collection to the end of the retention process.

  • Supports the maintenance of records filing systems to better facilitate retrieval and use.

  • Protects most important, up-to-date information while less valueless information is disposed of or transferred to the appropriate secured storage area.

  • Safeguards information essential to St. John’s daily business operations.

The following shall guide the training and management of employees:

  • St. John’s University implements required training programs to ensure administrators and staff are aware of protocols for protecting customer information.
  • All training programs or materials incorporate concepts relevant to both electronic and paper-based customer information.
  • Department managers and supervisors keep employees informed about policies and programs that pertain to their work, including those that govern GLBA compliance.
  • Managers and supervisors ascertain which positions deal with customer information and assess whether these positions should be classified as “critical positions” requiring background checks, as provided for by St. John’s personnel policy.
  • Department managers and supervisors ensure employees complete the mandatory core security training and specific GLBA training as assigned.
  • All University employees who interact with the covered PII data during their daily activities are required to complete the GLBA Compliance training course describing their responsibilities while handling the personally identifiable information (PII).
    • Annual cybersecurity training for all personnel;
    • Role‑based GLBA training for staff handling covered customer information;
    • Phishing exercises that have been designed and implemented by the IT department (and approval from security governance) to help employees to identify fake emails from authentic ones and not respond to questionable emails or communications;
    • Informative campus-wide communications regarding phishing, spear phishing, and other types of spam email; and
    • Mandatory security training for specific users working with electronic protected health information (EPHI).

St. John’s University’s documented and outlined Incident Response Plan and Procedures address possible threats that could arise concerning information technology, privacy, and cyber incidents. The University’s preparation in planning regarding these threats includes instruction for University employees to take against potential threats. These steps are listed below:

  1. Formal and detailed documented responses/reports for investigative purposes or for resolving cyber issues.
  2. Detection tools that readily identify cyberattacks or system anomalies.
  3. Official tabletop exercises to prepare teams for common and emerging threats.
  4. Incident Response Tickets that capture status, impact, assessment, evidence, containment, eradication, recovery, and postincident actions.

The University may appropriately share covered data with third parties. When third-party business is conducted, however, appropriate risk management activities are in place to minimize any corresponding potential risks. These activities include, but are not limited to, reputational, financial, operational, strategic, and compliance risks. The decision to engage with third parties must be consistent with the University’s business objectives, and they must be made after careful consideration of the risks involved are contracted for implementing and maintaining such safeguards.

The Coordinator, working with responsible units and offices, monitors, evaluates, and adjusts the Compliance Program in light of the results of testing and monitoring of the risks identified, as well as in response to any material changes to operations or business arrangements and any other circumstances which may reasonably have an impact on the Compliance Program. This program document will be reviewed, at a minimum, annually by the CIO and GLBA working committee.