US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
Evidence request list. 28 controls, 28 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Applicability to Title IV Institutions
Institutions participating in Title IV federal student aid programmes are financial institutions under GLBA.
- Written information security program (WISP) per 16 CFR 314
- Service provider oversight register and contractual safeguards
- Qualified Individual designation letter
- Risk assessment covering student financial information
- Risk assessment not refreshed within required cadence
- Service provider monitoring limited to onboarding
- Incident response plan does not address FSA notification
- No formal Qualified Individual or unclear authority
Student financial aid records and information constitute customer information under the Safeguards Rule.
- Written information security program (WISP) per 16 CFR 314
- Board or equivalent governing body reporting records
- Encryption and MFA implementation evidence
- Qualified Individual designation letter
- MFA not enforced for all access to customer information
- Service provider monitoring limited to onboarding
- Risk assessment not refreshed within required cadence
- No formal Qualified Individual or unclear authority
Federal Student Aid requires institutions to comply with the amended Safeguards Rule as programme participation condition.
- Qualified Individual designation letter
- Service provider oversight register and contractual safeguards
- Risk assessment covering student financial information
- Encryption and MFA implementation evidence
- Incident response plan does not address FSA notification
- MFA not enforced for all access to customer information
- No formal Qualified Individual or unclear authority
- Risk assessment not refreshed within required cadence
Information security programme must be integrated with the institution's overall governance structure.
- Encryption and MFA implementation evidence
- Board or equivalent governing body reporting records
- Qualified Individual designation letter
- Written information security program (WISP) per 16 CFR 314
- No formal Qualified Individual or unclear authority
- MFA not enforced for all access to customer information
- Service provider monitoring limited to onboarding
- Incident response plan does not address FSA notification
GLBA Higher Education: Title IV and Privacy Notices
Institutions participating in Title IV federal student aid programs must comply with GLBA Safeguards Rule as a condition of the Program Participation Agreement with the Department of Education, and must self assess and remediate findings reported by independent auditors.
- Most recent A 133 or single audit report addressing GLBA
- Self assessment of Safeguards Rule controls
- Remediation evidence for audit findings
- Communications with FSA cybersecurity team
- Single audit covers financial aid administration but not Safeguards Rule
- No self assessment refresh after 2023 rule update
- Audit findings open beyond one year
Although higher education institutions are deemed compliant with the GLBA Privacy Rule when they comply with FERPA, institutions must still ensure privacy notice and opt out practices align with FTC expectations where they perform financial activities beyond student financial aid administration.
- FERPA notification of rights
- Privacy notices for any non Title IV financial services such as employee credit unions or banking partnerships
- Opt out mechanisms where applicable
- Reliance on FERPA without evaluating non Title IV financial activities
- No privacy notices for institution operated lending or banking arrangements
GLBA Safeguards 314.3 to 314.4(b): Programme and Risk Assessment
Develop, implement, and maintain a comprehensive written information security program that contains administrative, technical, and physical safeguards appropriate to the size and complexity of the institution and the nature and scope of activities involving customer information.
- Written information security program (WISP) document
- Board or executive approval minutes
- Annual review evidence
- Scope of customer information covered
- WISP exists only as policy fragments rather than a single program document
- No evidence of periodic review and update
- Scope excludes financial aid systems or third party servicers
Designate a qualified individual responsible for overseeing, implementing, and enforcing the institution's information security program. The qualified individual may be employed by the institution, an affiliate, or a service provider.
- Written designation of Qualified Individual
- Position description with cybersecurity responsibilities
- Reporting line documentation
- Qualifications and credentials evidence
- No formal written designation
- Qualified Individual lacks authority over IT or financial aid systems
- Responsibilities split across roles with no single accountable owner
Conduct a written risk assessment that identifies reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information, and assesses the sufficiency of safeguards in place to control those risks. Update periodically.
- Written risk assessment with criteria for evaluating risks
- Asset inventory covering customer information systems
- Threat and vulnerability analysis
- Risk treatment register
- Periodic update evidence
- Risk assessment is qualitative without defined criteria
- Financial aid SaaS and student information systems excluded from scope
- No reassessment after material changes
GLBA Safeguards 314.4(c): Technical and Physical Safeguards
Implement and periodically review access controls including technical and physical controls to authenticate and permit access only to authorized users and limit authorized users access to customer information that they need to perform their duties.
- Access control policy
- Role based access matrix for student information systems
- Periodic access review records
- Joiner mover leaver evidence
- Privileged access logs
- Shared accounts in financial aid offices
- No periodic recertification of access
- Bursar or registrar staff have access beyond their duties
Identify and manage the data, personnel, devices, systems, and facilities that enable the institution to achieve business purposes in accordance with their relative importance to business objectives and the institution's risk strategy.
- Inventory of systems processing customer information
- Data flow diagrams showing student financial data
- Data classification standard
- Record of authoritative sources for FAFSA data
- Inventory limited to enterprise IT and excludes departmental systems
- No mapping of customer information across cloud services
- Shadow IT in admissions or advancement offices
Encrypt all customer information held or transmitted by the institution both in transit over external networks and at rest. Where encryption is infeasible, compensating controls reviewed and approved by the Qualified Individual must be used.
- Encryption standard and key management policy
- Configuration evidence for TLS on external interfaces
- Disk and database encryption evidence
- Approved exception register signed by Qualified Individual
- Legacy financial aid systems transmit data unencrypted internally
- No evidence of encryption at rest in backup tapes
- Exceptions undocumented or unapproved
Adopt secure development practices for in house developed applications utilized for transmitting, accessing, or storing customer information, and procedures for evaluating, assessing, or testing the security of externally developed applications utilized to access customer information.
- Secure coding standards
- Code review and SAST DAST evidence
- Vendor security assessments for student information systems
- Penetration test reports for student portals
- No SAST or DAST run on internally developed portals
- Procured SaaS not assessed for security before integration
- Departmental web apps outside central SDLC
Implement multi factor authentication for any individual accessing any information system. The Qualified Individual may approve in writing the use of reasonably equivalent or more secure access controls.
- MFA enrollment reports
- Configuration of identity provider
- Coverage report for student information system and ERP
- Written approvals for any equivalent controls
- MFA enforced only for VPN and not for SaaS
- Service accounts excluded with no compensating control
- Adjunct faculty accounts not enrolled
Develop, implement, and maintain procedures for the secure disposal of customer information in any format no later than two years after the last date the information is used in connection with the provision of a product or service to the customer, unless retention is required for legitimate business purposes or by law.
- Retention schedule with categories for customer information
- Certificate of destruction for media and paper
- Automated purge job evidence
- Legal hold exceptions
- No retention schedule for financial aid records beyond regulatory minimums
- Decommissioned servers wiped without certificate
- Departmental backups retained indefinitely
Adopt procedures for change management. Changes to information systems that store, process, or transmit customer information must be tracked, evaluated for security impact, tested, and approved.
- Change management policy
- Change advisory board minutes
- Sample change tickets with security review
- Emergency change records
- No security impact assessment in change tickets
- Shadow changes outside formal process
- No segregation of duties between developer and deployer
Implement policies, procedures, and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, or tampering with, customer information by such users.
- Logging standard
- SIEM use cases for customer information access
- Sample alerts and triage records
- Privileged user session monitoring evidence
- No logging on financial aid database queries
- Logs retained less than 90 days
- No correlation between SIS and identity provider events
GLBA Safeguards 314.4(d) to (i): Testing, Training and Oversight
Regularly test or otherwise monitor the effectiveness of the safeguards key controls, systems, and procedures. Testing must include continuous monitoring or, in its absence, annual penetration testing and biannual vulnerability assessments.
- Annual penetration test report
- Biannual vulnerability scan reports
- Continuous monitoring tooling configuration
- Remediation tracking
- Vulnerability scans run but not reviewed
- Penetration test scope excludes student portals
- No retest of remediated findings
Implement policies and procedures to ensure personnel are able to enact the information security program by providing security awareness training that is updated as necessary to reflect risks identified by the risk assessment, and utilize qualified information security personnel.
- Annual training records with completion rates
- Role based training for financial aid staff
- Phishing simulation results
- Personnel qualifications for security team
- Training completion below 95 percent for student facing staff
- Generic content without higher ed scenarios
- No verification of training currency for contractors
Oversee service providers by taking reasonable steps to select and retain service providers capable of maintaining appropriate safeguards, requiring providers by contract to implement and maintain such safeguards, and periodically assessing service providers based on the risk they present.
- Vendor inventory and tiering
- Security clauses in service provider contracts
- Annual reassessment evidence
- SOC 2 or equivalent reports for material providers
- Loan servicers, FAFSA processors, or LMS vendors not assessed
- No reassessment after initial onboarding
- Contracts predate Safeguards Rule update without amendment
Evaluate and adjust the information security program in light of the results of the testing and monitoring, any material changes to operations or business arrangements, the results of risk assessments, or any other circumstances that may have a material impact on the program.
- Program change log
- Lessons learned from incidents
- Adjustments following merger or acquisition
- Trigger events register
- No formal trigger criteria for re evaluation
- Adjustments not documented
- Program unchanged across multiple risk assessments
Establish a written incident response plan designed to promptly respond to and recover from any security event materially affecting the confidentiality, integrity, or availability of customer information in the institution's control.
- Written incident response plan
- Plan covers goals, internal processes, roles, communications, remediation, documentation, and post incident review
- Tabletop exercise records
- Sample incident records
- IR plan exists but is not customer information specific
- No post incident review documented
- Tabletop exercises do not involve financial aid leadership
Require the Qualified Individual to report in writing, at least annually, to the board of directors, equivalent governing body, or senior officer responsible for the information security program. The report addresses overall program status, risk assessment, risk management decisions, service provider arrangements, testing results, security events, and recommendations.
- Annual written report to board or senior officer
- Board or committee meeting minutes acknowledging report
- Distribution list and review records
- Verbal updates only, no written report
- Report omits required topics such as testing results or service provider arrangements
- No evidence of board acknowledgement
GLBA Safeguards 314.5: Security Event Notification
Notify the FTC as soon as possible, and no later than 30 days after discovery, of any notification event involving unauthorized acquisition of unencrypted customer information of 500 or more consumers.
- Notification procedure
- Determination memo for notification threshold
- FTC notification submission record
- Coordination with Department of Education and state regulators
- No procedure for the 30 day FTC notification timeline
- Threshold determination not documented
- No coordination playbook with DoE PPA contacts
Governance
Per FTC Safeguards Rule 16 CFR Part 314 + GLBA: Qualified Individual designation + Written risk assessment + Board engagement + applicable to higher education through Title IV.
- GLBA Higher Ed evidence for USGLBAHIGHER-1
- QI + risk + MFA partial
Incident
Per 16 CFR 314: incident response + notification to FTC + maintain written IR plan.
- GLBA Higher Ed evidence for USGLBAHIGHER-4
- QI + risk + MFA partial
Monitoring
Per 314.4(d) + (f): continuous monitoring and testing + service provider oversight + program evaluation and adjustment.
- GLBA Higher Ed evidence for USGLBAHIGHER-3
- QI + risk + MFA partial
Technical
Per 16 CFR 314.4(c): access controls + encryption + MFA + asset inventory + secure SDLC + change management.
- GLBA Higher Ed evidence for USGLBAHIGHER-2
- QI + risk + MFA partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule framework page.