Executive Summary
{{ posture }}
FERPA Compliance Check (Higher-Ed)
{{ ferpaSub }}
| Area | Requirement | Ref | Score | Status |
| {{ f.domain }} | {{ f.question }} | {{ f.ref }} | {{ f.score }} | {{ f.status }} |
Assessed Entity
Scope: {{ scopeText }}
Assessment Scope Diagram
Logical view of the environment handling student nonpublic personal information (NPI).
Assessment Boundary — Student NPI Environment · {{ coverClient }}
Identity & Access
Microsoft Entra ID · MFA / conditional access · Privileged access management
Core Systems
Ellucian Banner (SIS/ERP) · Financial Aid / Billing · FAFSA / EdConnect & COD
Student NPI Data Stores
File server & Microsoft 365 · Encrypted repositories · Backups (offsite VM + M365)
Security Operations
Logging / monitoring · Vulnerability & patch mgmt · Backup & recovery · SUNY SOC (partial)
▲ managed connections cross the boundary ▲
External Connections
Remote / telework users · Cloud & SaaS · Managed services (Verona) · Third-party / vendor access — through managed, monitored control points.
Out of Scope
Systems that neither store, process, nor transmit student NPI and are separated from the boundary above. Confirm separation before excluding.
Methodology & Scope
This assessment evaluates the organization against {{ fwList }}. Each control was assigned a 0–4 maturity score: 0 Not Implemented, 1 Ad-hoc, 2 Partially, 3 Largely, 4 Fully Implemented.
Scoring. Maturity is the mean 0–4 score per framework, normalized to 100. Any control scored 2 or below is treated as an open gap and carried into the POA&M and roadmap. For higher education, FERPA compliance generally satisfies the GLBA Privacy Rule for student records.
Confidentiality. Prepared by TechGuard Security · GRC Assessment Team for {{ coverClient }}. Contains sensitive security information; handle per the institution's data classification policy.
Maturity Scorecard
Normalized 0–100 maturity across all in-scope controls. Target posture is "Managed" (60%+).
0Target 60100
{{ overallPct }}% · {{ overallLevel }}
| Metric | Value |
| {{ m.label }} | {{ m.value }} |
Maturity Trend
{{ trendSub }}
{{ trendChart }}
| Snapshot | Overall | CSF | GLBA | CIS | Open gaps |
| {{ r.date }} | {{ r.overall }} | {{ r.csf }} | {{ r.glba }} | {{ r.cis }} | {{ r.gaps }} |
N/A — capture at least two dated snapshots in the app's Report tab (Maturity History) to chart a trend over time.
Framework & Domain Breakdown
{{ breakdownSub }}
| Area | Domain | Maturity | Open gaps | Coverage |
| {{ b.group }} | {{ b.label }} | {{ b.pct }}% | {{ b.gaps }} | {{ b.level }} |
Plan of Action & Milestones (POA&M)
Controls not fully implemented, in priority order (highest risk first).
| Source | Ref | Finding | Priority | Owner |
| {{ g.fw }} | {{ g.ref }} | {{ g.title }} | {{ g.priority }} | {{ g.owner }} |
Control Gap Risk Overview
Gap-exposure view derived from unmet controls, scored likelihood × impact (1–5). This exposure drives the phasing of the remediation plan that follows.
| Scenario | Source | L×I | Score | Severity |
| {{ r.title }} | {{ r.src }} | {{ r.li }} | {{ r.score }} | {{ r.severity }} |
Remediation Timeline
Open items phased by priority, with projected overall maturity after each phase closes.
| Phase | Timeframe | Items | Focus | Projected maturity |
| {{ r.name }} | {{ r.timeframe }} | {{ r.count }} | {{ r.focus }} | {{ r.projected }}% |
Remediation Roadmap — Phase Plans
Each phase's open items grouped into workstreams, with the accountable owner and representative control references.
{{ ph.name }}
{{ ph.timeframe }} · {{ ph.count }} items
{{ ph.objective }}
| Workstream | Items | Owner | Control refs |
| {{ d.ws }} | {{ d.count }} | {{ d.owner }} | {{ d.refs }} |
Interview Findings
Key stakeholder responses gathered during assessment interviews, with the assessor's observation and risk flag.
{{ i.topic }}
{{ i.flag }}
Response {{ i.resp }}
Observation {{ i.obs }}
Cyber-Insurance Readiness
Status of the key controls carriers underwrite. Gaps here typically drive higher premiums, coverage exclusions, or declined applications.
| Underwritten control | Status |
| {{ i.ctrl }} | {{ i.status }} |
Carriers increasingly require MFA, EDR, and tested immutable backups as baseline conditions of coverage. Closing the Phase 1 items above materially strengthens renewal position and can reduce premium exposure.
Regulatory Mapping
Statutory and contractual obligations in scope for this institution, mapped to the assessed frameworks.
| Requirement | Core obligation | Framework mapping | Applicability |
| {{ r.req }} | {{ r.obl }} | {{ r.map }} | {{ r.app }} |
Control-by-Control Detail
Full maturity score for every assessed control across the three frameworks. Rows scored 2 or below are open gaps carried into the POA&M.
| Ref | Control / outcome | Area | Score | Maturity |
| {{ r.label }} |
| {{ r.ref }} | {{ r.title }} | {{ r.area }} | {{ r.score }} | {{ r.status }} |
Appendix — Evidence Artifacts by Domain
Representative documentation and technical evidence collected to demonstrate each domain. Actual requirements depend on the environment and implementation.
| Domain | Representative evidence artifacts |
| {{ e.fam }} | {{ e.art }} |
Appendix — Governance Document Inventory
Policies and standards the program requires, their current state, and framework mapping. "Gap" documents are deliverables on the remediation roadmap.
| Document | Maps to | Current state | Status | Action |
| {{ g.doc }} | {{ g.maps }} | {{ g.status }} | {{ g.pillTxt }} | {{ g.note }} |
Glossary of Terms
Key terms and acronyms used throughout this assessment.
How TechGuard Can Help
The findings in this report point to one root cause: no single accountable owner driving the program to done. A fractional CISO (vCISO) closes that gap directly.
TechGuard embeds a named security leader into your team — owning the risk register, holding IT and vendors accountable, and driving the remediation roadmap in this report to closure. Two right-sized engagements:
| Package | Capacity | Investment | What’s included |
| Overseer |
2 hrs / month |
$6,000 / year |
Executive-level advisory voice. Monthly review of open risks with prioritization guidance, validation that initiatives align to business risk, and high-level cyber-insurance & audit-readiness input. No day-to-day program ownership. |
| Advisor |
5 hrs / month |
$12,000 / year |
Everything in Overseer, plus a monthly security review with leadership and tracked actions, a maintained risk register with monthly updates, remediation-priority guidance for IT/MSP, board talking points, and status tracking of overdue items. |
12-month minimum recommended for full gap closure. Larger Leader (10 hrs/mo) and Owner (20+ hrs/mo) engagements are available for deeper program ownership.
Assessment Attestation
The undersigned attest that this assessment accurately reflects the organization's implementation of the assessed controls as of the assessment date.
| |
{{ assessor }} Assessor — TechGuard Security | Authorizing Official — {{ coverClient }} |
| Date: {{ coverDate }} | Date: ______________________ |
TechGuard Security — Cybersecurity Maturity Advisor · CSF 2.0 · GLBA · CIS v8 · Assessment values are self-reported unless independently verified.