-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Save the date!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
Subscribe
Filter by type
- Articles, Briefs, Papers, and Reports (1)
- Plans and Guidelines [x]
Filter by Publications
Filter by Library Taxonomy
- Policy and Law [x]
- Security Management [x]
- Cybersecurity (9)
- Data Security (6)
- Campus Policies (5)
- Campus Policy and Law (5)
- Federal Policy and Law (5)
- Cybersecurity Policy (4)
- Data Classification Policies (3)
- Data Breach (2)
- Federal Privacy Law (2)
- Incident Handling and Response (2)
- Information Technology Management and Leadership (2)
- Network Security and Applications (2)
- Networking and Emerging Technologies (2)
- Privacy (2)
- Security Planning (2)
- Security Policies (2)
- Security Risk Assessment and Analysis (2)
- Health Insurance Portability and Accountability Act (HIPAA) (1)
Information technology policy is impacted by a wide range of perspectives from international, national, state, and campus levels. This resource page underscores the connections among these different levels and how international organizations, Congress, federal agencies, state governments, and the courts all play a role in shaping IT policy and law, as well as why this matters to higher education. Campus policies, whether developed to comply with legal mandates or to formalize institutional norms and processes, are under constant development and review as a result of changes precipitated by the introduction of new information technologies.
Featured Resources
Latest News
PCI compliance, privacy, InCommon implementation, and legal issues in IT are just a few of the preconference seminar topics offered at the EDUCAUSE Annual Conference, November 6-9 in Denver....
Library Items on this Topic
EDUCAUSE Library Items for Policy and Law
-
Compliance Matrix Poster for IT & Compliance Professionals
-
March 17, 2010
This matrix poster developed by Symantec outlines IT Controls for security and privacy concerns related to regulatory compliance in the workplace. Topics addressed in this poster include: Regu…
-
Higher Education Information Security Council 2012–2013 Strategic Plan
-
February 24, 2012
The HEISC mission is to improve information security, data protection, and privacy programs across the higher education sector through its working groups of volunteers and professional EDUCAUSE s…
-
Enterprise Information Security Program
-
March 26, 2009
The University of Iowa’s program for information security is a combination of policy, security architecture modeling, and descriptions of current IT security services and control practices. …
-
Guidelines for Responding to Compulsory Legal Requests for Information
-
May 11, 2007
Law enforcement requests for electronic records generally should be handled in the same way as other legal requests for other documents and by the same people. This is a guideline on how to handl…
-
Practical Information Media Sanitization Guidelines for Higher Education
-
October 6, 2006
When these storage and media devices become obsolete or are no longer needed the sensitive or private data must be effectively removed from the storage media or be destroyed before the devices ar…
-
Confidential Data Handling Blueprint
-
June 11, 2007
The Confidential Data Handling Toolkit provides a consolidation of resources that are anchored to the overarching themes related to information protection secure data handling. …
-
Yale University Data Breach Containment Procedure
-
January 1, 2006
Disclosure Notification Flow Chart for the Yale University Data Breach Containment Procedure. Disclosure Notification Flow Chart for the Yale Universit…
-
University of Washington Network Security Credo
-
January 1, 2002
Incidents of unauthorized access to networked computer systems in an enterprise are growing at fearful rates. The purpose of this document is to identify general design principles and practices for…
-
University Institutional Data Management
-
December 1, 2010
Indiana University Institutional Data Management program is the development and execution of principles, architectures, policies, practices and procedures that ensure broad appropriate availabili…

















