-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Save the date!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
Filter by type
- Plans and Guidelines [x]
Filter by Publications
Filter by Library Taxonomy
- Security Risk Assessment and Analysis [x]
- Cybersecurity (7)
- Security Management (7)
- Data Security (4)
- Information Technology Management and Leadership (4)
- Planning (3)
- Business Continuity (2)
- Cybersecurity Policy (2)
- Federal Policy and Law (2)
- Incident Handling and Response (2)
- Network Security and Applications (2)
- Policy and Law (2)
- Risk Management (2)
- Security Planning (2)
- Campus Policies (1)
- Campus Policy and Law (1)
- Health Insurance Portability and Accountability Act (HIPAA) (1)
- Identity and Access Management (1)
- Privacy (1)
- Strategic Planning (1)
Resources Developed by the Higher Education Information Security Council (HEISC)
- Information Security Governance
- Information Security Governance Assessment Tool
- Information Security Risk Assessment Consultants List
- Information Security Risk Assessment Sample RFPs
- Risk Assessment Tools
- Risk Management Framework
Risk Analysis and Security Evaluation Tools
- Electronic Risk and Requirements Assessment (E-RA)
- CCTA (Central Computer and Telecommunications Agency) Risk Analysis and Management Method (CRAMM)
- Control Objectives for Information and related Technology (COBIT)
- NIST Recommended Security and Privacy Controls for Federal Information Systems and Organizations (SP 800-53)
- NIST's "An Overview of Issues in Testing Intrusion Detection Systems"
- Operationally Critical Threat, Asset, and Vulnerability EvaluationSM (OCTAVE)
- Security Targeting and Analysis of Risks (STAR)
Updated October 2012
Library Items on this Topic
EDUCAUSE Library Items for Security Risk Assessment and Analysis
-
Compliance Matrix Poster for IT & Compliance Professionals
-
March 17, 2010
This matrix poster developed by Symantec outlines IT Controls for security and privacy concerns related to regulatory compliance in the workplace. Topics addressed in this poster include: Regu…
-
IT Security Information - IT Risk Management
-
January 11, 2008
The CU-Boulder IT Security Office has developed a risk management framework and risk assessment service to meet campus needs in identifying and mitigating IT related risk. The risk management fra…
-
Security Task Force 2008–2009 Strategic Plan: Safeguarding Our IT Assets, Protecting Our Community’s Privacy
-
September 3, 2008
The EDUCAUSE/Internet2 Computer and Network Security Task Force (STF) provides a focal point for the academic community to join together to strengthen the ability of the higher education sector t…
-
Information Risk Management Policy Template
-
March 17, 2008
The purpose of this policy template is to ensure that risks to University information are identified, analyzed, and managed so that they are maintained at acceptable levels. Risks to the confiden…
-
Security Task Force Strategic Plan 2006-2007 : Making Progress on Data Protection, Risk Assessment, Incident Response and Business Continuity
-
June 20, 2007
This 2006-2007 strategic plan is intended to identify a few key priorities for the next year that will guide and direct the activities of the EDUCAUSE/Internet2 Security Task Force. …
-
Confidential Data Handling Blueprint
-
June 11, 2007
The Confidential Data Handling Toolkit provides a consolidation of resources that are anchored to the overarching themes related to information protection secure data handling. …
-
Georgia State University System Security Plan
-
January 1, 2006
This plan is a sanitized version of the Georgia State University System Security Plan. Specific information on technical controls deployed at GSU is omitted. Information about information security …

















