From Fragmentation to Framework: Rebuilding University Security Standards That Actually Work
Higher education security programs often suffer from the same problem: dozens of disconnected policies, inconsistent ownership, unclear applicability, and compliance documents that look good to auditors but fail in practice. Arizona State University undertook a full rebuild of its cybersecurity standards portfolio—not by adding more controls, but by rethinking how standards are designed, written, governed, and consumed across a highly decentralized institution. This session walks through the end-to-end process used to design, rationalize, and operationalize a comprehensive cybersecurity standards suite aligned to NIST CSF, NIST RMF, CMMC, HIPAA, FERPA, GLBA, PCI DSS, and GDPR—without turning the effort into a compliance-only exercise. Attendees will learn: (1) how to design standards that are enforceable without being unrealistic; (2) how to align multiple regulatory frameworks into a single, coherent control structure; (3) how to write standards that both engineers and auditors can use; and (4) what broke, what slowed us down, and what we would do differently next time. This is not a theoretical framework talk. It is a candid case study from a large public university that had to make security governance work at scale.
Presenters
-
Ali Abdel-Fattah
Information Security Specialist, Sr.,
Arizona State University
-
Ben Archer
Associate Director, Technology Privacy and Compliance,
Arizona State University
-
Keith Swanson
Manager of Cyber Risk,
Arizona State University
Resources & Downloads
-
2026 Educause Standards Presentation
Updated on 7/25/2026