<rss xmlns:a10="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Security Risk Management</title><link>https://library.educause.edu/topics/cybersecurity/security-risk-management</link><description /><language>en</language><item><guid isPermaLink="false">{3DD1812D-6927-47C8-92F0-675D782A3EB4}</guid><link>https://library.educause.edu/resources/2025/7/educause-comments-updated-concerns-about-proposed-circia-regulations</link><title>EDUCAUSE Comments: Updated Concerns About Proposed CIRCIA Regulations</title><description>EDUCAUSE sent a letter to the acting director of CISA in June 2025 that highlights the concerns that we raised about the proposed CIRCIA regulations in 2024 and discusses how Trump administration directives reinforce our conclusion that higher education institutions should not be considered covered entities under the final rules, whenever they are released.</description><pubDate>Thu, 31 Jul 2025 20:06:53 Z</pubDate></item><item><guid isPermaLink="false">{D6783FE4-03A1-4BF2-8F7F-813B1B816D8E}</guid><link>https://library.educause.edu/resources/2021/10/frequently-asked-questions-about-cyber-insurance</link><title>Frequently Asked Questions about Cyber Insurance</title><description>This document contains advice intended for general information only. To learn how cyber insurance applies to your institution, please contact your institution’s risk management office or chief information officer. </description><pubDate>Fri, 16 May 2025 12:14:00 Z</pubDate></item><item><guid isPermaLink="false">{E21ED46F-CFF6-4B31-91E7-2320F2381DD7}</guid><link>https://library.educause.edu/resources/2025/5/2025-educause-horizon-report-teaching-and-learning-edition</link><title>2025 EDUCAUSE Horizon Report | Teaching and Learning Edition</title><description>The 2025 EDUCAUSE Horizon Report profiles key trends and emerging technologies and practices shaping the future of teaching and learning, and envisions a number of scenarios and implications for that future.&lt;br/&gt;</description><pubDate>Wed, 30 Apr 2025 16:49:40 Z</pubDate></item><item><guid isPermaLink="false">{98BF8D9F-57CD-47A8-81D3-F8B35D6D8DF8}</guid><link>https://library.educause.edu/resources/2025/3/2025-horizon-action-plan-supporting-agency-trust-transparency-and-involvement</link><title>2025 EDUCAUSE Horizon Action Plan: Supporting Agency, Trust, Transparency, and Involvement</title><description>This report describes how advancing the future of higher education cybersecurity and privacy will be done by supporting agency, trust, transparency, and involvement among stakeholders.</description><pubDate>Thu, 13 Mar 2025 17:09:12 Z</pubDate></item><item><guid isPermaLink="false">{303EC605-46F9-45B1-95C2-49CEEC0E879D}</guid><link>https://library.educause.edu/resources/2024/9/2024-educause-horizon-report-cybersecurity-and-privacy-edition</link><title>2024 EDUCAUSE Horizon Report | Cybersecurity and Privacy Edition</title><description>The 2024 EDUCAUSE Horizon Report profiles key trends and emerging technologies and practices shaping the future of cybersecurity and privacy, and envisions a number of scenarios and implications for that future.</description><pubDate>Tue, 24 Sep 2024 16:46:52 Z</pubDate></item><item><guid isPermaLink="false">{83C07445-216E-4A6C-AD6C-8838FD21B272}</guid><link>https://library.educause.edu/resources/2024/8/abstract-business-continuity-and-disaster-recovery-toolkit</link><title>Abstract: Business Continuity and Disaster Recovery Toolkit</title><description>Use the guidance and templates in this toolkit to prepare for disruptive events before they happen.</description><pubDate>Thu, 15 Aug 2024 19:34:16 Z</pubDate></item><item><guid isPermaLink="false">{1EC857FB-A830-4173-B22D-D02B4E0C9F16}</guid><link>https://library.educause.edu/resources/2023/6/educause-comments-possible-nsf-development-of-a-rsi-isao</link><title>EDUCAUSE Comments: Possible NSF Development of a Research Security and Integrity Information Sharing and Analysis Organization (RSI-ISAO)</title><description>EDUCAUSE provided a response to the National Science Foundation (NSF) on June 27, 2023, regarding its request for comments on the possible development of a research security and integrity information sharing and analysis organization (RSI-ISAO). </description><pubDate>Fri, 30 Jun 2023 14:17:03 Z</pubDate></item><item><guid isPermaLink="false">{8552FCB0-14BF-4B08-9D43-48CFE9E916BA}</guid><link>https://library.educause.edu/resources/2023/6/educause-comments-nist-research-cybersecurity-resource-development</link><title>EDUCAUSE Comments: NIST Research Cybersecurity Resource Development</title><description>On June 27, 2023, EDUCAUSE submitted a cover letter and comments to the National Institute of Standards and Technology (NIST) in response to its request for input on the resources that it could develop to support research cybersecurity at colleges and universities. </description><pubDate>Fri, 30 Jun 2023 13:57:19 Z</pubDate></item><item><guid isPermaLink="false">{611457BC-A06A-4447-974E-2714FF000FD8}</guid><link>https://library.educause.edu/resources/2022/9/nist-sp-800-171-toolkit</link><title>NIST SP 800-171 Toolkit</title><description>In this toolkit, you will find an overview of NIST SP 800-171 and its implications for higher education, questions to ask during project planning, 7 Things You Should Know About CMMC to use when speaking with stakeholders and leadership, and a customizable control evaluation.</description><pubDate>Wed, 14 Sep 2022 16:00:01 Z</pubDate></item><item><guid isPermaLink="false">{A84348FC-AD6D-401D-98E4-FC19DDDF7003}</guid><link>https://library.educause.edu/resources/2022/9/7-things-you-should-know-about-cybersecurity-maturity-model-certification-cmmc</link><title>7 Things You Should Know About Cybersecurity Maturity Model Certification (CMMC)</title><description>The Cybersecurity Maturity Model Certification (CMMC) is a set of policies and practices that address the protection of federal Controlled Unclassified Information (CUI) data through administrative, physical, and technical controls. &lt;br/&gt;</description><pubDate>Thu, 15 Sep 2022 16:31:19 Z</pubDate></item><item><guid isPermaLink="false">{30E76C51-2E8F-4D9C-85DF-82611FBDA45D}</guid><link>https://library.educause.edu/resources/2021/11/arctic-ews-research-paper</link><title>Arctic EWS Research Paper</title><description>This  is a joint research project of Arctic Security and EDUCAUSE,  The goal was to establish the utility of external cybersecurity monitoring for higher education, and to identify services that could be made easily accessible and boost the cyber defenses of the association’s members. </description><pubDate>Mon, 08 Nov 2021 19:07:53 Z</pubDate></item><item><guid isPermaLink="false">{A572973B-FEFF-4F02-9A4D-C6AA3106D969}</guid><link>https://library.educause.edu/resources/2021/7/higher-education-regulated-research-workshop-series-a-collective-perspective</link><title>Higher Education Regulated Research Workshop Series: A Collective Perspective</title><description>After an eight month effort concluding in June of 2021, 155 participants from 84 research institutions from across the United States gathered in six facilitated, NSF-sponsored workshop sessions to determine if coming together as a community could improve the support of individual programs to secure regulated data in research involving the Department of Defense or health sciences. </description><pubDate>Mon, 12 Jul 2021 19:03:31 Z</pubDate></item><item><guid isPermaLink="false">{CBA8A923-400A-494B-A526-4122A4CF58BE}</guid><link>https://library.educause.edu/resources/2021/5/7-things-you-should-know-about-endpoint-detection-and-response</link><title>7 Things You Should Know About Endpoint Detection and Response</title><description>Endpoint detection and response (EDR) is the process of monitoring endpoint activity in real time, looking for digital threats and implementing measures to halt and remediate those threats. </description><pubDate>Tue, 25 May 2021 16:55:56 Z</pubDate></item><item><guid isPermaLink="false">{68F7DFE6-BEC0-4F2E-B58A-94A9A598D9E4}</guid><link>https://library.educause.edu/resources/2020/11/learning-and-teaching-reimagined-a-new-dawn-for-higher-education</link><title>Learning and Teaching Reimagined: A New Dawn for Higher Education?</title><description>This JISC report is the result of a five-month higher education initiative to understand the response to COVID-19 and explore the future of digital learning and teaching.</description><pubDate>Thu, 05 Nov 2020 16:31:22 Z</pubDate></item><item><guid isPermaLink="false">{76112D0C-C230-4FE7-A5AA-0F3B5DF3D870}</guid><link>https://library.educause.edu/resources/2020/8/higher-education-research-cybersecurity-and-cmmc-compliance</link><title>Higher Education Research, Cybersecurity, and CMMC Compliance</title><description>This brief, a joint effort on the part of EDUCAUSE and PreVeil, was written to clarify the Department of Defense’s (DoD) new Cybersecurity Maturity Model Certification (CMMC) framework and to guide your institution on its journey to CMMC compliance.</description><pubDate>Fri, 07 Aug 2020 16:03:53 Z</pubDate></item><item><guid isPermaLink="false">{28ACE00F-CC91-45EE-B7FB-1B65BE4BA98F}</guid><link>https://library.educause.edu/resources/2020/4/report-on-remote-assessment-procedures</link><title>Report on Remote Assessment Procedures</title><description /><pubDate>Fri, 01 May 2020 20:31:31 Z</pubDate></item><item><guid isPermaLink="false">{2E097886-F95C-471C-9AF9-9AFC8D50AA1D}</guid><link>https://library.educause.edu/resources/2020/1/campus-security-awareness-blogs-2019</link><title>Campus Security Awareness Blogs, 2019</title><description>These 12 EDUCAUSE Review Security Matters column blog posts are part of the 2019 Campus Security Awareness Campaign. </description><pubDate>Thu, 30 Jan 2020 21:02:31 Z</pubDate></item><item><guid isPermaLink="false">{29EE87A3-E057-455D-96B2-08EED3A11D76}</guid><link>https://library.educause.edu/resources/2024/7/cyber-incident-reporting-for-critical-infrastructure-act--circia-reporting-requirements</link><title>EDUCAUSE Comments: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements</title><description>On July 1, 2024, EDUCAUSE joined with the American Association of Collegiate Registrars and Admissions Officers (AACRAO), the Association of American Universities (AAU), the Association of Governing Boards of Universities and Colleges (AGB), the Association of Public and Land-grant Universities (APLU), and the National Association of Independent Colleges and Universities (NAICU) to submit comments regarding the reporting requirements proposed by the Cybersecurity and Infrastructure Security Agency (CISA) under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).</description><pubDate>Mon, 01 Jul 2024 19:51:43 Z</pubDate></item><item><guid isPermaLink="false">{D70FBFA3-266B-4197-8C1C-107F173227A1}</guid><link>https://library.educause.edu/resources/2022/6/effective-cybersecurity-for-research</link><title>Effective Cybersecurity for Research</title><description> This paper describes an approach to cybersecurity for research that is showing great promise in breaking the security versus research impasse. A product of years of effort at Indiana University, it focuses exclusively on the researcher and the research mission, reduces the cybersecurity and compliance burden on the researcher, and aims to secure all research.</description><pubDate>Mon, 20 Jun 2022 22:01:43 Z</pubDate></item><item><guid isPermaLink="false">{824EEC3E-D061-412F-9894-6DBC3B934FFC}</guid><link>https://library.educause.edu/resources/2016/5/infosec-leadership-survey-2016</link><title>InfoSec Leadership Survey 2016</title><description>This survey seeks to understand skills required of information security leaders in higher education.</description><pubDate>Tue, 03 May 2016 17:08:31 Z</pubDate></item></channel></rss>