From Fragmentation to Framework: Rebuilding University Security Standards That Actually Work

Wednesday, April 29, 2026 | 11:30AM–12:30PM PT | Pacific Ballroom A, Second Floor
Session Type: Breakout Session
Delivery Format: Presentation/Panel
Higher education security programs often suffer from the same problem: dozens of disconnected policies, inconsistent ownership, unclear applicability, and compliance documents that look good to auditors but fail in practice. Arizona State University undertook a full rebuild of its cybersecurity standards portfolio—not by adding more controls, but by rethinking how standards are designed, written, governed, and consumed across a highly decentralized institution. This session walks through the end-to-end process used to design, rationalize, and operationalize a comprehensive cybersecurity standards suite aligned to NIST CSF, NIST RMF, CMMC, HIPAA, FERPA, GLBA, PCI DSS, and GDPR—without turning the effort into a compliance-only exercise. Attendees will learn: (1) how to design standards that are enforceable without being unrealistic; (2) how to align multiple regulatory frameworks into a single, coherent control structure; (3) how to write standards that both engineers and auditors can use; and (4) what broke, what slowed us down, and what we would do differently next time. This is not a theoretical framework talk. It is a candid case study from a large public university that had to make security governance work at scale.

Presenters

  • Ali Abdel-Fattah

    Information Security Specialist, Sr., Arizona State University
  • Ben Archer

    Associate Director, Technology Privacy and Compliance, Arizona State University
  • Keith Swanson

    Manager of Cyber Risk, Arizona State University

Resources & Downloads

  • 2026 Educause Standards Presentation

    Updated on 7/25/2026