-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Save the date!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
Subscribe
Filter by type
Filter by Publications
Filter by Presentations
Filter by Library Taxonomy
- Policy and Law [x]
- Risk Management [x]
- Information Technology Management and Leadership (13)
- Cybersecurity (11)
- Security Management (9)
- Security Risk Assessment and Analysis (8)
- Campus Policies (6)
- Campus Policy and Law (6)
- Federal Policy and Law (6)
- Security Policies (5)
- Data Security (4)
- Cybersecurity Policy (3)
- Network Security and Applications (3)
- Audit (2)
- Federal Privacy Law (2)
- Identity and Access Management (2)
- Security Planning (2)
- Compliance (1)
- Intellectual Property (1)
- Privacy (1)
EDUCAUSE Library Items for Risk Management
-
Software-as-a-Service Email Security: Risk vs. Trust
-
May 31, 2012
Many organizations would be interested in treating e-mail as a commodity —cutting costs and resource investments by outsourcing it to a software as a service (SaaS) provider. However, …
-
Identity Finder Case Study
-
June 21, 2010
The University of Pennsylvania enacted a comprehensive Social Security Number policy in May of 2007. The stated purpose of the policy was to protect social security numbers by eliminating them, c…
-
Information Technology Sector Baseline Risk Assessment
-
August 28, 2009
The IT Sector Baseline Risk Assessment evaluates risk to the IT Sector and focuses on critical IT Sector functions. The assessment methodology is not intended to be guidance for individual entiti…
-
Compliance Assessment Template
-
September 24, 2008
This sample Harvard University questionnaire is designed to assist people in understanding if the setup and operation of their systems are in compliance with the Harvard Enterprise Information …
-
Managing IT Risk in Higher Education: A Methodology
-
March 18, 2008
This research bulletin presents a methodology, used successfully at the University of Technology, Sydney (UTS) in Australia, for managing and assessing risks related to information technology sys…
-
GSU's Roadmap for a World-Class Information Security Management System: ISO 27001:2005
-
October 24, 2007
|
A session at the EDUCAUSE 2007 Annual Conference
Georgia State University is one of the first universities to embrace the ISO 27001:2005 standard for establishing an information security management system (ISMS). A systematic and disciplined appr…
-
Information Systems Under Attack: Managing Enterprise Risk
-
February 22, 2007
Today's enterprise information systems are increasingly coming under attack by sophisticated adversaries around the world including nation-states, terrorist organizations, criminals, hackers, …
-
Risk Assessment 101
-
March 13, 2006
|
A session at the EDUCAUSE Midwest Regional Conference 2006
Have you examined how to physically protect your data? With federal requirements imposed such as GLBA, FERPA, and HIPAA and threats of identity theft, where do you start? Learn where we began by as…
-
The Changing Landscape: External Drivers, Risks, and Rewards for Interboundary Authentication
-
February 8, 2006
The ability to uniquely identify who your constituents are forms the basis for regulatory compliance, future federal interaction, online research collaboration, business controls, auditing, network…
-
A Systematic, Comprehensive Approach to Information Security
-
July 6, 2005
Information security is a process of business risk management that must be performed on an ongoing basis. It is critical to take an approach to information security that examines the risks and s…

















