-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Save the date!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
Subscribe
Filter by type
Filter by Publications
Filter by Presentations
Filter by Library Taxonomy
- Data Security [x]
- Risk Management [x]
- Cybersecurity (13)
- Information Technology Management and Leadership (13)
- Security Management (13)
- Security Risk Assessment and Analysis (8)
- Information Systems and Services (6)
- Policy and Law (4)
- Security Planning (4)
- Data Administration and Management (3)
- High-Performance Computing (HPC) (3)
- Information Security Governance (3)
- Networking and Emerging Technologies (3)
- Campus Policies (2)
- Campus Policy and Law (2)
- Cloud Computing (2)
- Compliance (2)
- Federal Policy and Law (2)
- Planning (2)
- Security Policies (2)
EDUCAUSE Library Items for Risk Management
-
Enterprise Risk Management in Higher Education: Implications for Enterprise IT - Sponsored by Kroll Advisory Solutions
-
April 17, 2013
|
A session at the Security Professionals Conference
Enterprise risk management (ERM) has matured as a discipline within higher education. Colleges and universities are subject to risks to their physical assets, people assets, and cyber assets. The i…
-
Understanding and Managing the Risks of Analytics in Higher Education: A Guide
-
June 29, 2012
This guide provides an introduction to the major risk categories faced by a higher education institution considering investments in time, energy, and money in analytics work . Under the ri…
-
Software-as-a-Service Email Security: Risk vs. Trust
-
May 31, 2012
Many organizations would be interested in treating e-mail as a commodity —cutting costs and resource investments by outsourcing it to a software as a service (SaaS) provider. However, …
-
Application Security for Management, Project Managers, and Architects
-
March 25, 2011
Although Web application security is gradually improving, many project leaders, vendors, and programmers are still unaware of vulnerabilities that can expose confidential institutional data, allo…
-
Application Security for Database Administrators
-
March 25, 2011
Applying multi-layer security to protect sensitive or confidential data is the focus of most application security efforts. Inventorying and securing sensitive data and all applications, software …
-
Practical Strategies for Managing Risk in Cloud Computing
-
March 1, 2011
This ECAR research bulletin identifies some key principles on which to base decisions related to security assurance and compliance capabilities in cloud computing environments. It also illustrate…
-
Securing Institutional Data: Let’s Make It Everyone’s Business
-
May 5, 2009
This ECAR research bulletin discusses the costs of preventing data loss in terms of people, processes, and technology. It focuses on principles to guide decision making in higher education and …
-
Information Technology Security Risk Management (ITS-RM) Program
-
December 12, 2008
This is the University of Virginia's ITC’s Information Technology Security Risk Management (ITS-RM) Program, which is intended to provide University departments with the information and to…
-
Information Risk Management Policy Template
-
March 17, 2008
The purpose of this policy template is to ensure that risks to University information are identified, analyzed, and managed so that they are maintained at acceptable levels. Risks to the confiden…
-
GSU's Roadmap for a World-Class Information Security Management System: ISO 27001:2005
-
October 24, 2007
|
A session at the EDUCAUSE 2007 Annual Conference
Georgia State University is one of the first universities to embrace the ISO 27001:2005 standard for establishing an information security management system (ISMS). A systematic and disciplined appr…

















