-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Save the date!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
Filter by type
- Tools [x]
Filter by Publications
Filter by Library Taxonomy
- Security Risk Assessment and Analysis [x]
- Cybersecurity (8)
- Security Management (8)
- Information Technology Management and Leadership (6)
- Policy and Law (3)
- Risk Management (3)
- Security Planning (3)
- Campus Policies (2)
- Campus Policy and Law (2)
- Cybersecurity Policy (2)
- Data Security (2)
- Federal Policy and Law (2)
- Information Security Governance (2)
- Network Vulnerability Assessment (2)
- Security Architecture (2)
- Security Policies (2)
- CIO (1)
- Compliance (1)
- Identity and Access Management (1)
- Planning (1)
Resources Developed by the Higher Education Information Security Council (HEISC)
- Information Security Governance
- Information Security Governance Assessment Tool
- Information Security Risk Assessment Consultants List
- Information Security Risk Assessment Sample RFPs
- Risk Assessment Tools
- Risk Management Framework
Risk Analysis and Security Evaluation Tools
- Electronic Risk and Requirements Assessment (E-RA)
- CCTA (Central Computer and Telecommunications Agency) Risk Analysis and Management Method (CRAMM)
- Control Objectives for Information and related Technology (COBIT)
- NIST Recommended Security and Privacy Controls for Federal Information Systems and Organizations (SP 800-53)
- NIST's "An Overview of Issues in Testing Intrusion Detection Systems"
- Operationally Critical Threat, Asset, and Vulnerability EvaluationSM (OCTAVE)
- Security Targeting and Analysis of Risks (STAR)
Updated October 2012
Library Items on this Topic
EDUCAUSE Library Items for Security Risk Assessment and Analysis
-
Information Security Program Assessment Tool
-
April 15, 2013
This self-assessment tool was created to evaluate the maturity of higher education information security programs using as a framework the International Organization for Standardization (ISO) 2700…
-
Compliance Assessment Template
-
September 24, 2008
This sample Harvard University questionnaire is designed to assist people in understanding if the setup and operation of their systems are in compliance with the Harvard Enterprise Information …
-
Risk Assessment Tools List
-
March 14, 2008
This list of Risk Assessment tools has been developed to assist campuses in the risk assessment planning process. The tools are a mix of some sold or licensed by vendors, some provided by colleag…
-
Risk Management Framework
-
January 1, 2006
In recent years, higher education institutions have recognized the importance of developing and implementing strategies to manage information risk. Proper information risk management now translat…
-
Data Incident Notification Toolkit
-
January 1, 2005
The Data Incident Notification Toolkit includes resources that cover a range of issues that commonly arise in the heat of the moment when responding to data incidents. If your institution has a d…
-
Business Impact Analysis/Risk Assessment for Information Assets
-
January 1, 2004
Model templates for Business Impact Analysis/Risk Assessment for Information Assets from Virginia Tech. Model templates for Business Impact Analysis/Ri…
-
The World Bank Technology Risk Checklist (Version 7.3)
-
January 1, 2004
The World Bank Technology Risk Checklist is designed to provide Chief Information Security Officers (CISO), Chief Technology Officers (CTO), Chief Financial Officers (CFO), Directors, Risk Managers…
-
Information Security Governance Assessment Tool
-
January 1, 2004
The Information Security Governance (ISG) Assessment Tool is intended to help institutions of higher education determine the degree to which they have implemented an ISG Framework at the strategi…

















