Full text

Turn on search term navigation

© 2013. This work is published under http://creativecommons.org/licenses/by-sa/1.0/legalcode (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.

Abstract

The 2013 EDUCAUSE Center for Analysis and Research (ECAR) report on measuring IT costs in higher education found that only 10 percent of the responding institutions reported very effective IT governance programs; 61 percent of institutions reported having an ineffective or only somewhat effective IT governance program.1 Many institutions have information security governance, data governance, enterprise system governance, and identity governance programs. Almost half of the C-level executives responding to that survey indicated that risk management is essential for adding business value to their organizations, and nearly 40 percent of the respondents said that risk management considerations are often factored into the organization's overall strategic planning decisions.2 There is a gradual movement at colleges and universities to embrace enterprise IT risk management as a more holistic approach to understanding a variety of risks across the institution and prioritizing strategic resource allocation accordingly. In May 2013, for example, a state university agreed to pay $400,000 to the U.S. Department of Health & Human Services (HHS) to settle alleged violations of Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule due to a breach of unsecured electronic protected health information at an outpatient clinic operated by the university.3 Ironically, legislative, regulatory, and contractual compliance issues are burdening colleges and universities at the same time that higher education institutions are under increased pressure to reduce costs. Notes * Eden Dahlstrom, Assessing Your Fiscal Bandwidth: Current Practices for Measuring IT Costs in Higher Education, ECAR research report (Louisville, Colo.: EDUCAUSE, 2013), p. 6. * KPMG International, Expectations of Risk Management Outpacing Capabilities—It's Time for Action: Top Eight Risk Management Imperatives for the C-suite in 2013 (January 2013), p. 12 (chart 1), p. 13 (chart 4). * U.S. Department of Health & Human Services (HHS), "Idaho State University Settles HIPAA Security Case for $400,000," press release, May 21, 2013. * IT Governance, EDUCAUSE Library; Ronald Yanosky, with Jack McCredie, Process and Politics: IT Governance in Higher Education, ECAR research study, volume 5 (Boulder, Colo.: EDUCAUSE, 2008); Cybersecurity Initiative web page; EDUCAUSE Policy web page. * EDUCAUSE, "Top-Ten IT Issues: 2000–2013" (interactive graphic). © 2013 Joanna Lyn Grama and Rodney Petersen.

Details

Title
Governance, Risk, and Compliance: Why Now?
Author
Grama, Joanna; Petersen, Rodney
Section
In Print
Publication year
2013
Publication date
Dec 6, 2013
Publisher
EDUCAUSE
Source type
Scholarly Journal
Language of publication
English
ProQuest document ID
3224617346
Copyright
© 2013. This work is published under http://creativecommons.org/licenses/by-sa/1.0/legalcode (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.