-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Save the date!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
Subscribe
Filter by type
Filter by Publications
Filter by Presentations
Filter by Library Taxonomy
- Information Technology Management and Leadership [x]
- Security Planning [x]
- Security Risk Assessment and Analysis [x]
- Cybersecurity (16)
- Security Management (16)
- Risk Management (8)
- Policy and Law (7)
- Campus Policies (6)
- Campus Policy and Law (6)
- Data Security (6)
- Security Policies (6)
- Planning (5)
- Security Implementation (4)
- Information Security Governance (3)
- Network Vulnerability Assessment (3)
- Compliance (2)
- IT Effectiveness (2)
- Information Systems and Services (2)
- Institutional Management (2)
- Strategic Planning (2)
EDUCAUSE Library Items for Security Planning
-
Information Security Program Assessment Tool
-
April 15, 2013
This self-assessment tool was created to evaluate the maturity of higher education information security programs using as a framework the International Organization for Standardization (ISO) 2700…
-
Foundations for Effective Security Risk and Program Assessment
-
April 13, 2010
|
A session at the Security 2010
How does an institution assess the risks and effectiveness of something as multifaceted and complex as its risk management and information security programs? An assessment methodology must be valid…
-
Novel Approaches to Developing Governance, Risk, and Compliance Programs
-
April 22, 2009
|
A session at the Security 2009
Legislative requirements are accumulating as rapidly as sophisticated threats to institutional data. How does an institution develop a strategic response that incorporates all necessary requireme…
-
Information Risk Management Policy Template
-
March 17, 2008
The purpose of this policy template is to ensure that risks to University information are identified, analyzed, and managed so that they are maintained at acceptable levels. Risks to the confiden…
-
GSU's Roadmap for a World-Class Information Security Management System: ISO 27001:2005
-
October 24, 2007
|
A session at the EDUCAUSE 2007 Annual Conference
Georgia State University is one of the first universities to embrace the ISO 27001:2005 standard for establishing an information security management system (ISMS). A systematic and disciplined appr…
-
Developing a University Systemwide Information Security Roadmap
-
April 11, 2007
|
A session at the Security 2007
Developing and implementing a common set of baseline information security practices across all the campuses of a very large state university system can be a daunting undertaking. This presentation …
-
Defend IT: Security by Example - Book Review
-
January 1, 2005
Recommended Reading Defend IT: Security by Example Ajay Gupta and Scott Laliberte Addison Wesley Professional, 2004 $34.99 (paper), 384 pp. ISBN 0-321-19767-4 …
-
Two Approaches to PCI DSS Compliance
-
April 11, 2006
|
A session at the Security 2006
The Payment Card Industry Data Security Standard (PCI DSS) poses a unique challenge to institutions of higher education, which often host many diverse credit/debit card merchants on our campuses. L…
-
Security Assessments in an Academic Environment
-
April 11, 2006
|
A session at the Security 2006
Baylor University recently conducted a campus-wide IT security assessment. This session presents the process from choosing a consultant to remediation of the assessments discoveries. The result is …
-
Risk Management Framework
-
January 1, 2006
In recent years, higher education institutions have recognized the importance of developing and implementing strategies to manage information risk. Proper information risk management now translat…

















