<rss xmlns:a10="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Federal Cybersecurity Policy</title><link>https://library.educause.edu/topics/policy-and-law/federal-cybersecurity-policy</link><description /><language>en</language><item><guid isPermaLink="false">{3DD1812D-6927-47C8-92F0-675D782A3EB4}</guid><link>https://library.educause.edu/resources/2025/7/educause-comments-updated-concerns-about-proposed-circia-regulations</link><title>EDUCAUSE Comments: Updated Concerns About Proposed CIRCIA Regulations</title><description>EDUCAUSE sent a letter to the acting director of CISA in June 2025 that highlights the concerns that we raised about the proposed CIRCIA regulations in 2024 and discusses how Trump administration directives reinforce our conclusion that higher education institutions should not be considered covered entities under the final rules, whenever they are released.</description><pubDate>Thu, 31 Jul 2025 20:06:53 Z</pubDate></item><item><guid isPermaLink="false">{6D209CC1-AAA6-414B-932B-1C64435E499E}</guid><link>https://library.educause.edu/resources/2025/3/educause-comments-proposed-cui-rules-for-federal-contracting</link><title>EDUCAUSE Comments: Proposed CUI Rules for Federal Contracting</title><description>On March 17, 2025, EDUCAUSE, COGR, the American Council on Education (ACE), the Association of American Universities (AAU), and the Association of Public and Land-grant Universities (APLU) submitted comments in response to proposed regulations for incorporating controlled unclassified information (CUI) marking, handling, and security requirements into federal contracting rules and processes. </description><pubDate>Wed, 19 Mar 2025 13:21:51 Z</pubDate></item><item><guid isPermaLink="false">{DCDD0BF3-6117-4527-AF5D-8AD0E613EDE5}</guid><link>https://library.educause.edu/resources/2024/12/educause-comments-incorporating-cmmc-requirements-into-dod-contracting-regulations</link><title>EDUCAUSE Comments: Incorporating CMMC Requirements Into DOD Contracting Regulations</title><description>On October 15, 2024, EDUCAUSE submitted comments to the U.S. Department of Defense (DOD) regarding its proposed changes to the department’s contracting regulations (i.e., the Defense Federal Acquisition Regulation Supplement, or DFARS) to incorporate Cybersecurity Maturity Model Certification (CMMC) requirements into the defense contracting process.</description><pubDate>Fri, 06 Dec 2024 15:12:55 Z</pubDate></item><item><guid isPermaLink="false">{303EC605-46F9-45B1-95C2-49CEEC0E879D}</guid><link>https://library.educause.edu/resources/2024/9/2024-educause-horizon-report-cybersecurity-and-privacy-edition</link><title>2024 EDUCAUSE Horizon Report | Cybersecurity and Privacy Edition</title><description>The 2024 EDUCAUSE Horizon Report profiles key trends and emerging technologies and practices shaping the future of cybersecurity and privacy, and envisions a number of scenarios and implications for that future.</description><pubDate>Tue, 24 Sep 2024 16:46:52 Z</pubDate></item><item><guid isPermaLink="false">{A731E0A5-81D3-4DF6-8ABF-21833759D73C}</guid><link>https://library.educause.edu/resources/2024/2/educause-comments-cmmc-2-regulations</link><title>EDUCAUSE Comments: CMMC 2.0 Regulations</title><description>EDUCAUSE joined COGR, AAU, APLU, and ACE in submitting comments to the U.S. Department of Defense (DoD) on February 26, 2024, regarding the DoD’s second-round of proposed regulations to implement its Cybersecurity Maturity Model Certification (CMMC) Program. </description><pubDate>Wed, 28 Feb 2024 21:04:48 Z</pubDate></item><item><guid isPermaLink="false">{FFE47D4F-2DA6-4B85-A979-0C546A57A3DC}</guid><link>https://library.educause.edu/resources/2024/2/educause-comments-far-cyber-incident-reporting</link><title>EDUCAUSE Comments: FAR Cyber Incident Reporting</title><description>On February 2, 2024, EDUCAUSE was joined by COGR and the Association of American Universities (AAU) in submitting comments on proposed changes to the Federal Acquisition Regulation (FAR) that could impose cyber incident reporting and software bill of materials (SBOM) development/maintenance obligations on all federal contractors, including colleges and universities. </description><pubDate>Mon, 19 Feb 2024 17:29:33 Z</pubDate></item><item><guid isPermaLink="false">{F72618E4-9C62-4B77-8AB1-C93E54987C58}</guid><link>https://library.educause.edu/resources/2024/2/educause-comments-nist-sp-800-171-revision-3</link><title>EDUCAUSE Comments: NIST SP 800-171, Revision 3</title><description>EDUCAUSE submitted comments to the National Institute of Standards and Technology (NIST) on January 26, 2024, regarding the near-final draft of the NIST Special Publication (SP) 800-171 cybersecurity guidelines for controlled unclassified information (CUI) held in non-federal information systems (such as those of colleges and universities). </description><pubDate>Mon, 19 Feb 2024 17:06:01 Z</pubDate></item><item><guid isPermaLink="false">{C0B38D95-E66E-4ADB-8B03-45A4F3E72010}</guid><link>https://library.educause.edu/resources/2014/3/columbia-university-administrative-policy-library-computing-and-technology</link><title>Columbia University Administrative Policy Library: Computing and Technology</title><description>Columbia University:  Administrative Policy Library Computing and Technology website</description><pubDate>Tue, 22 Dec 2015 17:36:26 Z</pubDate></item><item><guid isPermaLink="false">{1EC857FB-A830-4173-B22D-D02B4E0C9F16}</guid><link>https://library.educause.edu/resources/2023/6/educause-comments-possible-nsf-development-of-a-rsi-isao</link><title>EDUCAUSE Comments: Possible NSF Development of a Research Security and Integrity Information Sharing and Analysis Organization (RSI-ISAO)</title><description>EDUCAUSE provided a response to the National Science Foundation (NSF) on June 27, 2023, regarding its request for comments on the possible development of a research security and integrity information sharing and analysis organization (RSI-ISAO). </description><pubDate>Fri, 30 Jun 2023 14:17:03 Z</pubDate></item><item><guid isPermaLink="false">{8552FCB0-14BF-4B08-9D43-48CFE9E916BA}</guid><link>https://library.educause.edu/resources/2023/6/educause-comments-nist-research-cybersecurity-resource-development</link><title>EDUCAUSE Comments: NIST Research Cybersecurity Resource Development</title><description>On June 27, 2023, EDUCAUSE submitted a cover letter and comments to the National Institute of Standards and Technology (NIST) in response to its request for input on the resources that it could develop to support research cybersecurity at colleges and universities. </description><pubDate>Fri, 30 Jun 2023 13:57:19 Z</pubDate></item><item><guid isPermaLink="false">{9164310F-0321-47AE-87DC-AE8788E74064}</guid><link>https://library.educause.edu/resources/2023/6/educause-comments-draft-cybersecurity-provisions-for-research-security-programs</link><title>EDUCAUSE Comments: Draft Cybersecurity Provisions for Research Security Programs</title><description>EDUCAUSE submitted comments to the White House Office of Science and Technology Policy (OSTP) on June 5, 2023, concerning the draft requirements for research security programs under National Security Presidential Memorandum 33 (NSPM-33). </description><pubDate>Wed, 14 Jun 2023 22:16:58 Z</pubDate></item><item><guid isPermaLink="false">{0392F002-E765-4CA6-977D-06F4AA625629}</guid><link>https://library.educause.edu/resources/2022/9/nist-sp-800-171-overview</link><title>NIST SP 800-171 Overview</title><description>This overview provides a review of the timeline that introduced NIST SP 800-171 "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations" as a compliance framework, an overview of the control families for the 110 controls and a discussion of the impacts and concerns for higher education.</description><pubDate>Wed, 14 Sep 2022 16:00:01 Z</pubDate></item><item><guid isPermaLink="false">{611457BC-A06A-4447-974E-2714FF000FD8}</guid><link>https://library.educause.edu/resources/2022/9/nist-sp-800-171-toolkit</link><title>NIST SP 800-171 Toolkit</title><description>In this toolkit, you will find an overview of NIST SP 800-171 and its implications for higher education, questions to ask during project planning, 7 Things You Should Know About CMMC to use when speaking with stakeholders and leadership, and a customizable control evaluation.</description><pubDate>Wed, 14 Sep 2022 16:00:01 Z</pubDate></item><item><guid isPermaLink="false">{A84348FC-AD6D-401D-98E4-FC19DDDF7003}</guid><link>https://library.educause.edu/resources/2022/9/7-things-you-should-know-about-cybersecurity-maturity-model-certification-cmmc</link><title>7 Things You Should Know About Cybersecurity Maturity Model Certification (CMMC)</title><description>The Cybersecurity Maturity Model Certification (CMMC) is a set of policies and practices that address the protection of federal Controlled Unclassified Information (CUI) data through administrative, physical, and technical controls. &lt;br/&gt;</description><pubDate>Thu, 15 Sep 2022 16:31:19 Z</pubDate></item><item><guid isPermaLink="false">{D6D42435-05DE-4EEB-A49F-FA4CC52A6358}</guid><link>https://library.educause.edu/resources/2016/9/nist-sp-800-171-compliance-template</link><title>NIST SP 800-171 Compliance Template</title><description>Higher education institutions continue to refine their understanding of the impact of NIST Special Publication 800-171 on their IT systems and the data they receive from the federal government.  This compliance template will help institutions map the NIST SP 800-171 requirements to other common security standards used in higher education, and provides suggested responses to controls listed in NIST SP 800-171.</description><pubDate>Fri, 30 Sep 2016 16:20:41 Z</pubDate></item><item><guid isPermaLink="false">{4DE3CF90-68BD-4D48-92F5-690A9B33D904}</guid><link>https://library.educause.edu/resources/2022/2/educause-comments-ftc-safeguards-rule-proposed-reporting-requirement</link><title>EDUCAUSE Comments: FTC Safeguards Rule Proposed Reporting Requirement</title><description>EDUCAUSE joined the American Council on Education (ACE) and eleven other higher education associations in submitting comments to the Federal Trade Commission (FTC) regarding its proposal to add a reporting requirement to the FTC Safeguards Rule. </description><pubDate>Mon, 14 Feb 2022 23:39:55 Z</pubDate></item><item><guid isPermaLink="false">{573E2118-CFFA-4728-9554-64F12C5CC75A}</guid><link>https://library.educause.edu/resources/2021/2/2021-educause-horizon-report-information-security-edition</link><title>2021 EDUCAUSE Horizon Report® | Information Security Edition</title><description>The 2021 EDUCAUSE Horizon Report profiles key trends and emerging technologies and practices shaping the future of information security, and envisions a number of scenarios and implications for that future.</description><pubDate>Wed, 05 Jul 2023 16:33:24 Z</pubDate></item><item><guid isPermaLink="false">{05CA7A0B-5DEE-4835-A87C-CAA5A31C25EF}</guid><link>https://library.educause.edu/resources/2020/11/educause-comments-dod-interim-rule-on-cmmc-and-800-171-assessment</link><title>EDUCAUSE Comments: DOD Interim Rule on CMMC and 800-171 Assessment</title><description>EDUCAUSE joined others in commenting on the U.S. Department of Defense (DOD) interim rule that seeks to formally incorporate the Cybersecurity Maturity Model Certification (CMMC) Framework and the DOD assessment methodology and requirements for NIST SP 800-171 compliance by defense contractors into the DOD contracting regulations. </description><pubDate>Tue, 08 Dec 2020 19:46:33 Z</pubDate></item><item><guid isPermaLink="false">{29EE87A3-E057-455D-96B2-08EED3A11D76}</guid><link>https://library.educause.edu/resources/2024/7/cyber-incident-reporting-for-critical-infrastructure-act--circia-reporting-requirements</link><title>EDUCAUSE Comments: Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements</title><description>On July 1, 2024, EDUCAUSE joined with the American Association of Collegiate Registrars and Admissions Officers (AACRAO), the Association of American Universities (AAU), the Association of Governing Boards of Universities and Colleges (AGB), the Association of Public and Land-grant Universities (APLU), and the National Association of Independent Colleges and Universities (NAICU) to submit comments regarding the reporting requirements proposed by the Cybersecurity and Infrastructure Security Agency (CISA) under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA).</description><pubDate>Mon, 01 Jul 2024 19:51:43 Z</pubDate></item><item><guid isPermaLink="false">{576B96A3-A177-4CDF-815D-46365B2E822A}</guid><link>https://library.educause.edu/resources/2020/10/educause-comments-fsa-strategic-plan-2020-24-draft</link><title>EDUCAUSE Comments: FSA Strategic Plan, 2020-24 (Draft)</title><description>The Office of Federal Student Aid (FSA) at the U.S. Department of Education (ED) recently invited public comments on its draft strategic plan for 2020 through 2024. EDUCAUSE encouraged FSA to rewrite the relevant sections of its plan to focus on current and potential collaboration between the agency and higher education information security leaders on clarifying and publicly documenting compliance guidance as well as bolstering the dissemination of jointly sourced effective information security practices.</description><pubDate>Mon, 26 Oct 2020 15:52:42 Z</pubDate></item></channel></rss>