Events for all Levels and InterestsStay
Jump Start Your Career GrowthStay
Get on the Higher Ed IT MapStay
Uncommon Thinking for the Common Good™Stay
Filter by type
Filter by Publications
Filter by Presentations
Filter by Library Taxonomy
- Cybersecurity Policy [x]
- Cybersecurity [x]
- Incident Handling and Response [x]
- Federal Policy and Law (28)
- Policy and Law (28)
- Security Management (28)
- Data Security (13)
- Campus Policies (12)
- Campus Policy and Law (12)
- Security Policies (12)
- Data Breach (11)
- Information Technology Management and Leadership (10)
- IT Governance (8)
- Institutional Management (8)
- Network Security and Applications (5)
- Security Awareness (5)
- Intrusion Detection and Prevention (4)
- Audit (3)
- Identity and Access Management (2)
- Privacy (2)
The higher education sector plays an important role in the cybersecurity of America. Through its core mission of teaching and learning, higher education is the main source of future leaders, innovators, and the technical workforce. Through research, higher education is the basic source of much of our new knowledge and future technologies. Colleges and universities also operate some of the world's largest collections of computers and high-speed networks. This resource page provides information related to all aspects of cybersecurity for higher education, with an emphasis on strategies, policies, and other tools that will assist institutions of higher education to prevent, detect, and respond to vulnerabilities that threaten college and university computers and networks.
EDUCAUSE is actively involved with this area through the EDUCAUSE/Internet2 Higher Education Information Security Council (formerly the Security Task Force).
Information Security Guide: Effective Practices and Solutions for Higher Education
The Information Security Guide: Effective Practices and Solutions for Higher Education is now available in wiki format. This resource provides practical approaches to preventing, detecting, and responding to security problems in a wide range of higher education environments. This online service is designed with colleges and universities in mind, balancing our need for security with the need for an open, collaborative networking environment. Also, because one of the overarching concerns in college and university information technology (IT) departments is a lack of resources, an effort is made to provide low-cost solutions. The target audiences are those responsible for information security in colleges and universities and information technology staff who implement and manage security measures. Recognizing that many institutions have initiated or are in the process of developing IT security programs and policies, an effort is made throughout this resource to present practices that are useful at each stage of the developmental process.
As a community-driven, community-serving project, it is important for this initiative to incorporate experiences and perspectives from many different institutions. To contribute case studies that have been effective in your institution, please contact firstname.lastname@example.org.
View past and future security-related events.
InCommon will be heavily involved in a $1.8 million grant awarded to Internet2 to build a consistent and robust privacy infrastructure. Partners include Carnegie Mellon, Brown, University of Texas...
Virginia Tech has become the first identity provider to achieve Bronze and Silver certification as part of the InCommon Assurance Program.
The annual EDUCAUSE Conference in Denver will provide an opportunity to explore the range and depth of issues that campuses must consider as they build...
Find a variety of E12 security and privacy-related sessions in Denver or online.
Find resources and see what other campuses are doing this October for NCSAM.
NCSAM article in the latest EDUCAUSE Review offers resources and suggestions for campuses to support security awareness efforts in October.
Library Items on this Topic
EDUCAUSE Library Items for Cybersecurity
- Incident Management and Response Checklist
May 6, 2013
Rather than waiting for a data breach to happen, consider using an incident checklist to establish a campus incident response team, review your institution's readiness, and develop (or a…
- Podcast: Larry Conrad on IT Security Then and Now
July 17, 2012
Larry D. Conrad serves as the vice chancellor for information technology and chief information officer at UNC Chapel Hill. He has over 40 years experience in the field of information technolo…
- The 3 Rs of Responding to a Major Data Breach
March 26, 2012
A session at the EDUCAUSE Midwest Regional Conference 2012
Responding to a major data breach is an activity that none of us would welcome, yet many feel that having a data breach is not a matter of "if," but "when." In 2011, our campus …
- A Day at the Breach
March 13, 2012
A session at the NERCOMP Annual Conference 2012
It's August 10 at the University of Wisconsin–Milwaukee and the school is not contemplating how to spend a day at the beach. Instead, they are informing approximately 75,000 individuals asso…
- Data Breach Notification: Discussing Reactive Processes and Proactive Strategies
April 5, 2011
A session at the Security Professionals Conference 2011
Data security and privacy are focal points in many institutions' information security programs. There is a complex set of legal and regulatory frameworks for protecting data that we are entrus…
- Compliance Matrix Poster for IT & Compliance Professionals
March 17, 2010
This matrix poster developed by Symantec outlines IT Controls for security and privacy concerns related to regulatory compliance in the workplace. Topics addressed in this poster include: Regu…
- Incident Management
November 4, 2009
In this unique, online-only session, discuss emerging issues around incident management. In this unique, online-only session, discuss emerging is…
- Out of the Breach and into the Fire
September 15, 2008
© 2008 Heidi Wachs, Kent Wada, and Timothy Lance. The text of this article is licensed under the Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License ( http://creat…
- 2008 Data Breach Investigations Report
July 1, 2008
The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data …
- Final Report of the 2007 Cybersecurity Summit
November 30, 2007
This is the final report for the 2007 NSF Cybersecurity Summit, held February 22 & 23rd, 2007, in Arlington, VA. This is the final report fo…