-
Research
and PublicationsStay -
Conferences
and EventsAnnual Conference
October 15–18, 2013
Save the date!Events for all Levels and Interests
Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.
Stay -
Career
DevelopmentEDUCAUSE Institute
Leadership/Management Programs
Explore MoreCareer Center
Leadership and Management Programs
EDUCAUSE Institute
Advanced Programs
Project Management
Jump Start Your Career Growth
Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.
Stay -
Focus Areas
and InitiativesLatest Topics
EDUCAUSE organizes its efforts around three IT Focus Areas
Join These Programs If Your Focus Is
Stay -
Connect
and ContributeFind Others
Get on the Higher Ed IT Map
Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
Stay -
About
EDUCAUSEUncommon Thinking for the Common Good™
EDUCAUSE is the foremost community of higher education IT leaders and professionals.
Stay
Filter by type
- Podcasts (6)
- Blogs (5)
- Articles, Briefs, Papers, and Reports (46)
- Blogs and Wikis (2)
- Certification, Education, Training and Tutorials (3)
- Effective Practices (7)
- Government Documents, Laws, Testimonies or Reports (2)
- Plans and Guidelines (7)
- Policies and Procedures (1)
- Presentations and Seminars (95)
- Programs and Projects (1)
- RFPs (1)
- Surveys (2)
- Tools (8)
- Vendors (1)
Filter by Publications
Filter by Presentations
Filter by Library Taxonomy
- Security Risk Assessment and Analysis [x]
- Cybersecurity (188)
- Security Management (188)
- Information Technology Management and Leadership (76)
- Policy and Law (57)
- Network Security and Applications (47)
- Risk Management (40)
- Data Security (38)
- Campus Policy and Law (37)
- Campus Policies (36)
- Security Planning (34)
- Security Policies (34)
- Security Awareness (30)
- Incident Handling and Response (28)
- Federal Policy and Law (27)
- Identity and Access Management (22)
- Security Implementation (20)
- Cybersecurity Policy (15)
- Network Vulnerability Assessment (14)
- Planning (13)
Resources Developed by the Higher Education Information Security Council (HEISC)
- Information Security Governance
- Information Security Governance Assessment Tool
- Information Security Risk Assessment Consultants List
- Information Security Risk Assessment Sample RFPs
- Risk Assessment Tools
- Risk Management Framework
Risk Analysis and Security Evaluation Tools
- Electronic Risk and Requirements Assessment (E-RA)
- CCTA (Central Computer and Telecommunications Agency) Risk Analysis and Management Method (CRAMM)
- Control Objectives for Information and related Technology (COBIT)
- NIST Recommended Security and Privacy Controls for Federal Information Systems and Organizations (SP 800-53)
- NIST's "An Overview of Issues in Testing Intrusion Detection Systems"
- Operationally Critical Threat, Asset, and Vulnerability EvaluationSM (OCTAVE)
- Security Targeting and Analysis of Risks (STAR)
Updated October 2012
Library Items on this Topic
EDUCAUSE Library Items for Security Risk Assessment and Analysis
-
E07 Podcast: An Interview with Cedric Bennett - Security Concerns and Risk Management
-
November 1, 2007
In this fifteen minute podcast, we feature an interview with Cedric Bennett , Emeritus Director for Information Security Services at Stanford University. Mr. Bennett also serves on the EDUCAUS…
-
E07 Podcast: Bruce Schneier on Information Security: Ten Trends
-
October 31, 2007
In this 43 minute podcast, we feature a keynote speech by Bruce Schneier , author and Chief Technology Officer for BT Counterpane, Inc. This speech was delivered at the EDUCAUSE 2007 Annual Co…
-
2007 Enterprise Conference: The Adaptable University
-
June 15, 2007
This podcast features a keynote address from the 2007 Enterprise Conference in Chicago, Illinois. Our speaker is H. David Lambert , Vice President for Information Services and Chief Informatio…
-
EDUCAUSE Security Conference: Incident Tracking and Reporting
-
April 20, 2007
Summary Incident Tracking and Reporting Kathy Bergsma, University of Florida Joshua Beeman, University of Pennsylvania 2007 EDUCAUSE Security Professionals Conference Thursda…
-
EDUCAUSE Security Conference: Secrets of Superspies
-
April 17, 2007
Summary Secrets of Superspies Ira Winkler, Author of Spies Among Us and President, Internet Security Advisors Group 2007 EDUCAUSE Security Professionals Conferen…
-
EDUCAUSE2006 Podcast: How to Successfully Defend
-
March 31, 2007
In this 36-minute recording from the 2006 EDUCAUSE Annual Conference, we'll hear from Tammy Clark and William Monahan in a session entitled How to Successfully Defend Against IRC Bots, Com…
-
EDUCAUSE Enterprise 2006. Summary: Enterprise-wide Security
-
June 7, 2006
Summary: Enterprise-wide Security Mark Bruhn and Jack Suess Enterprise 2006 May 24, 2006 Chicago, Illinois Abstract: During 2005, more than 50 universities notified th…
-
EDUCAUSE Security Professionals Conference 2006. Summary:System-wide Strategies for Achieving IT Security at Univ. of California
-
April 25, 2006
System-wide Strategies for Achieving IT Security at the University of California Jacqueline Craig, Director of Policy, University of California Office of the President David H. Walker, …

















