Information Security Program Assessment Tool

Information Security Program Assessment Tool

This self-assessment tool was created to evaluate the maturity of higher education information security programs using as a framework the International Organization for Standardization (ISO) 27002:2013 “Information Technology Security Techniques. Code of Practice for Information Security Management.” This tool was intended for use by an institution as a whole, although a unit within an institution may also use it to help determine the maturity of its individual information security program. Unless otherwise noted, it should be completed by chief information officer, chief information security officer or equivalent, or a designee. There are a total of 101 questions and on average it takes about 2 hours for an information security officer or equivalent, familiar with their environment, to complete this tool.

Related Resources

  • Website

    Privacy News from Around the World

    Aug 1, 2019

    This resource intends to increase privacy awareness around the world. In particular this page updates on youth and education privacy news.

    Learn More
  • Website

    SDPC Resource Registry

    May 19, 2019

    The Student Data Privacy Consortium (SDPC) is an unique collaborative of schools, districts, regional, territories and state agencies, policy makers, trade org…

    Learn More
  • Website

    Utah State Board of Education Data Dictionary

    May 19, 2019

    This resource provides an overview of the types of data elements that the Utah State Board of Education collects and how those elements are defined.

    Learn More