Security Policies

Recent resources tagged with Security Policies.

Information Security Governance: Standardizing the Practice of Information Security

Added by the EDUCAUSE Librarian
Title:Information Security Governance: Standardizing the Practice of Information Security (ID: ERB0817)
Author(s):Tammy L. Clark (Georgia State University) and Toby D. Sitko (EDUCAUSE)
Origin:Documents Contributed by ECAR, Research Bulletins (08/19/2008)
Type:Articles, Papers, and Reports
Abstract:

This ECAR research bulletin discusses the trend to use a variety of risk assessment frameworks and standards to create an information security program that is sufficiently comprehensive for colleges and universities. These standards include the Control Objectives for Information and related Technology (CobiT) IT control framework, the Information Technology Infrastructure Library (ITIL) service management framework, and the set of information control objectives now commonly referred to as ISO 27001. In specific, the process of implementing this framework at Georgia State University (GSU) is discussed. In addition, the bulletin provides a rationale for an information security governance framework that enables executives to see the degree to which their information security programs are effective in assessing and mitigating risks, protecting confidential data, aligning goals with institutional academic and business objectives, and continuously improving over time.

View this resource:
This publication is currently password protected. All faculty, staff, and students from institutions that have subscribed to ECAR at the ECAR Participating, Comprehensive Content, Corporate, and Research Bulletins Package levels are authorized to access this publication by using their EDUCAUSE personal profile.

EDUCAUSE Summit: The Role of IT in Campus Security and Emergency Management

Created by Carie Lee Page (EDUCAUSE) on August 15, 2008

Colleges and universities are subject to all-hazards, ranging from natural disasters to man-made events.  Recent shootings at Virginia Tech and Northern Illinois University, coupled with the devastation of floods and hurricanes and the threat of domestic and international terrorism have created a new sense of urgency on our campuses as we continue to explore new practices and policies for security and emergency management, from preparedness through recovery. 

In February, EDUCAUSE joined NACUBO and several other higher education associations to launch a new initiative aimed at helping institutions of higher education to develop comprehensive, all-hazards emergency management plans. This month, EDUCAUSE will bring together campus and IT leaders to continue the dialogue.

Building a Security Program to Include Metrics

Created by Valerie M. Vogel (EDUCAUSE) on August 13, 2008

In "Security Metrics: A Solution in Search of a Problem", a recent EDUCAUSE Quarterly article, Joel Rosenblatt (Manager of Computer and Network Security, Columbia University) describes how the creation and collection of appropriate metrics can enhance an institution's security program. Learn about some potential metrics in the following areas: policy and compliance, network and machine monitoring, outreach and education, legal compliance, authorization and authentication, asset protection, and privacy.

Security Metrics: A Solution in Search of a Problem

Added by the EDUCAUSE Librarian
Title:Security Metrics: A Solution in Search of a Problem (ID: EQM0832)
Author(s):Joel Rosenblatt (Columbia University)
Origin:EDUCAUSE Quarterly Articles (08/04/2008)
Type:Articles, Papers, and Reports
Abstract:

The multifaceted aspects of security programs become clearer with the creation and collection of appropriate metrics.

View this resource:

Podcast: The FTC as an Educational Partner in Improving Data Security and Privacy

Created by Gerry Bayne (EDUCAUSE) on May 19, 2008

This 38 minute podcast features a keynote address by Mary Beth Richards, Deputy Director of the Bureau of Consumer Protection for the Federal Trade Commission. Her speech, "The FTC as an Educational Partner in Improving Data Security and Privacy," was recorded at the EDUCAUSE 2008 Policy Conference in Arlington, Virgina.

IT Security Officer Survey

Added by the EDUCAUSE Librarian
Title:IT Security Officer Survey (ID: ESI08B)
Author(s):Marilu Goodyear (University of Kansas)
Origin:Documents Contributed by ECAR, Survey Instruments (04/09/2008)
Type:Surveys
Abstract:

This April 2008 survey is a critical component of the EDUCAUSE Center on Applied Research (ECAR) study of information security officers in higher education. It seeks to understand the important characteristics and career paths of those engaged in day-to-day IT security management in colleges and universities.

Citation for this work: EDUCAUSE Center for Applied Research. "IT Security Officer Survey" (Survey Instrument). Boulder, CO: ECAR, 2008, available from http://www.educause.edu/ecar.

View this resource:

Managing IT Risk in Higher Education: A Methodology

Added by the EDUCAUSE Librarian
Title:Managing IT Risk in Higher Education: A Methodology (ID: ERB0806)
Author(s):Ian D. Waters (University of Technology, Sydney)
Origin:Documents Contributed by ECAR, Research Bulletins (03/18/2008)
Type:Articles, Papers, and Reports
Abstract:

This research bulletin presents a methodology, used successfully at the University of Technology, Sydney (UTS) in Australia, for managing and assessing risks related to information technology systems and resources. It describes the institutional commitment, background, organizational structure, methodology, implementation, and outcomes of an institutionally inclusive risk assessment that yielded valuable results that can be applied in other colleges and universities.

Citation for this work : Waters, Ian. “Managing IT Risk in Higher Education: A Methodology” (Research Bulletin, Issue 6). Boulder, CO: EDUCAUSE Center for Applied Research, 2008, available from http://www.educause.edu/ecar.

View this resource:
This publication is currently password protected. All faculty, staff, and students from institutions that have subscribed to ECAR at the ECAR Participating, Comprehensive Content, Corporate, and Research Bulletins Package levels are authorized to access this publication by using their EDUCAUSE personal profile.

Incident Response from the Ground Up

Added by the EDUCAUSE Librarian
Title:Incident Response from the Ground Up (ID: NCP08071)
Author(s):Adam Goldstein (Dartmouth College) and Ellen L. Young (Dartmouth College)
Origin:Presented at NERCOMP Conferences (03/10/2008)
Type:Presentations/Speeches
Abstract:

Recognizing that an incident response policy is only as good as the procedures that support it, Dartmouth College developed its approach to incident response from the bottom up. This session will highlight the advantages of establishing procedures first and policy second when it comes to incident response planning.

View this resource:

Standards for Security Categorization of Federal Information and Information Systems (FIPS-199)

Added by the EDUCAUSE Librarian
Title:Standards for Security Categorization of Federal Information and Information Systems (FIPS-199) (ID: CSD5355)
Source:National Institute of Standards and Technology
Origin:Contributed by Organizations or Campuses (02/18/2004)
Type:Government Documents, Laws, Testimonies or Reports
Abstract:

The E-Government Act of 2002 (Public Law 107-347), recognized the importance of information security to the economic and national security interests of the United States. Title III of the E-Government Act, entitled the Federal Information Security Management Act of 2002 (FISMA), tasked NIST with responsibilities for standards and guidelines, including the development of:
- Standards to be used by all federal agencies to categorize all information and information systems collected or maintained by or on behalf of each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels;
- Guidelines recommending the types of information and information systems to be included in each category; and
- Minimum information security requirements (i.e., management, operational, and technical controls), for information and information systems in each such category.

View this resource:

Identity and Access Management: The Big Picture

Added by the EDUCAUSE Librarian
Title:Identity and Access Management: The Big Picture (ID: CAMP08110)
Author(s):Steve Devoti (University of Wisconsin-Madison) and Andrew J. Korty (Indiana University)
Origin:Contributed by EDUCAUSE Grant Programs (CAMP) (02/13/2008)
Type:Presentations/Speeches
Abstract:

Unsure how all the parts of an identity management system fit together and would like to know more? This non-technical, preworkshop seminar offers a functional model of the campus infrastructure and provide attendees a chance to view it through the technology, policy, and business process lenses. Topics covered include technology model, lifecycle of identity, and policy frameworks and governance.

View this resource: