Leanpub Header

Skip to main content

CampusCISO IT Policy Bundle

Most universities have IT policies. Few have a formal strategy behind them. This bundle pairs Building IT Policy Programs for Higher Education, which carries the strategy and the Inspection method, with the CampusCISO IT Policy Framework, which carries the per-item reference detail, both grounded in annual research across 400+ colleges and universities.

Bought separately

$59.98

Minimum price

$29.99

$39.99

You pay

Author earns

$

Also available for 2 book credits with a Reader Membership

The following 2 books are included in this bundle...

These books have a total suggested price of $59.98. Get them now for only $29.99!
About

About

About the Bundle

Higher education IT policy isn't a documentation problem. It's a governance problem. This bundle gives you both halves of the answer: the strategy and the reference.

Building IT Policy Programs for Higher Education carries the strategy and the method. It explains why higher education security programs differ from corporate and government approaches, walks through the three diagnostic patterns from the 2026 study, and shows how to measure your Governance Debt with a two-tier inspection and turn the findings into a phased annual roadmap.

The CampusCISO® IT Policy Framework carries the per-item detail you reach for at the workbench: the complete inventory of 17 policies and 24 standards, each with key elements, common variations, regulatory drivers, framework alignment, and the field-tested failure mode to avoid, plus the 0 to 100 Diagnostic Score methodology and seven sector-wide gaps.

The evidence base: Both books are built from the 2026 CampusCISO IT Policy Study, a systematic review of policy libraries at 410 colleges and universities, including every R1 research university in the United States. The framework is updated annually as new research data becomes available.

How they fit together: The book interprets the framework. Read the guide to understand where the sector's gaps are and how to run the Inspection; keep the framework open beside it for the detail on each policy and standard. The framework's Community Edition is free on Leanpub; this bundle includes the paid edition alongside the guide.

What's included:

  • Building IT Policy Programs for Higher Education (2026 Edition)
  • CampusCISO IT Policy Framework (2026 Edition, paid edition)
  • The CampusCISO IT Policy Self-Assessment as a formatted, printable PDF, in your Leanpub downloads

Who it's for: CIOs, CISOs, IT leadership, and governance committees at higher education institutions of any size, and the consultants and advisors who serve them.

More from CampusCISO: Other resources in the CampusCISO IT Policy family are available at campusciso.com/it-policy-guide.

Books

About the Books

Building IT Policy Programs for Higher Education

Building IT Policy Programs for Higher Education

Higher education IT policy isn't a documentation problem. It's a governance problem.

The distance between what should be documented and what actually exists creates Governance Debt, and it compounds the same way deferred maintenance does. When it comes due during a ransomware attack, a compliance audit, or a federal grant review, it transforms from a documentation gap into a direct financial and legal liability.

The evidence base: We reviewed the policy libraries of 410 colleges and universities, including every R1 research university in the United States, and studied what they actually published, where the gaps were, and how institutions across the sector are addressing them. The results form the 2026 CampusCISO® IT Policy Study. This study is incorporated into a series of resources, including this book and the CampusCISO IT Policy Framework (free Community Edition on Leanpub).

Three diagnostic patterns emerged from the 2026 study: an Authentication Floor that proves consensus is possible. A Ransomware Cliff where documented response procedures drop from 57% at large research institutions to 2% at baccalaureate institutions. And an Oral Tradition Liability where critical technical practices live in people's heads instead of written standards.

What you'll find inside:

  • The three diagnostic patterns and the prevalence data behind them
  • Why higher education security programs are fundamentally different from corporate and government approaches, and how to design for shared governance, academic freedom, and decentralized IT
  • A framework of 17 policies and 24 standards grounded in observed practice, built to work alongside NIST, ISO, and other guidance
  • Regulatory context for common higher education requirements, including FERPA, GLBA, HIPAA, CMMC, export controls, and state breach laws
  • A two-tier inspection methodology to measure your Governance Debt: a 20-hour Quick Inspection for fast triage, or the full Inspection that you can complete in 70-130 staff hours
  • A template for phased improvements with a stakeholder briefing template and guidance on prioritizing gaps
  • The CampusCISO IT Policy Self-Assessment as a formatted, printable PDF, included with your purchase

Who it's for: CIOs, CISOs, IT leadership, and governance committees at higher education institutions of any size.

More from CampusCISO: Other resources in the CampusCISO IT Policy family are available at campusciso.com/it-policy-guide.

CampusCISO IT Policy Framework

CampusCISO IT Policy Framework

2026 Edition

The CampusCISO® IT Policy Framework is a reference for IT policy in higher education, grounded in annual research.

What it is: An inventory of 17 policies and 24 standards, with prevalence data showing what large research institutions actually publish and support. Each item is classified as Universal, Common, or Emerging based on observed adoption patterns at research universities, so you can see at a glance which items are sector-wide expectations and which are still emerging.

The evidence base: The framework is built from the 2026 CampusCISO IT Policy Study, a systematic review of policy libraries at 410 colleges and universities including a complete census of all 187 R1 research universities in the United States. The framework is updated annually as new research data becomes available.

What's inside the 2026 Edition:

  • The complete inventory of 17 policies and 24 standards organized by prevalence (Universal, Common, Emerging)
  • Insights into seven sector-wide gaps where higher education consistently falls behind regulatory or threat-driven expectations
  • How to determine your 0 to 100 Diagnostic Score combining quantitative coverage and qualitative governance assessment, with four relative maturity levels (Mature, Developing, Foundational, Minimal)
  • An overview of the framework's design philosophy and the annual research that validates and updates it
  • Edition history documenting how the framework has evolved
  • A Self-Assessment method institutions can use to baseline their own policy programs

How to use it: The framework is designed to be used as a reference for self-directed work. Institutions can complete the appended Self-Assessment themselves to identify and prioritize gaps. Paid editions include the Self-Assessment as a formatted, printable PDF. Other resources in the CampusCISO IT Policy family, including the companion guide and paid advisory engagements, are available at campusciso.com/it-policy-guide.

Who it's for: CIOs, CISOs, IT leadership, and governance committees at higher education institutions of any size. Consultants and advisors who serve the sector will find the framework useful as a vendor-neutral reference grounded in peer data.

Updated annually. The 2026 Edition reflects the 2026 CampusCISO IT Policy Study. Subsequent editions will incorporate new data and reclassify items as sector practices evolve.

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub