I know the other ones for healthcare and financial institutions as well as PCI but in the US what law governs schools, universities and technical schools if any.
Data breach laws if the state has any is a big one. Schools collect that kind of personal information. Also, child protection laws. At a minimum, for a school, I would advise firewalls (desktop and hardware) and shut down any ports not needed. Wireless should not publicly broadcast unless it is a public network. Treat this like any other business with sensitive information.
I've never truly ran across one other than anything that involves child safety/protection, because schools collect that kind of information on their students. So making sure student information is secure is key.
If you find any other laws concerning schools, I'd seriously love to know about them.
One thing you can do is produce an industry specific check list, so when you walk in to a business you know what you/they need to do. I currently only do this for my HIPAA clients.
Edit: there ya go. I knew someone would post the CIPA link eventually.