Kean University SEC 01 – Information Security Policy
Table of Contents
- 1. Overview
- 2. Purpose
- 3. Scope
- 4. Security Principles
- 5. Roles and Responsibilities
- 6. Security Requirements for Staff
- 7. Exceptions
- 8. Enforcement
- 9. Document Control
1. Overview
Kean University maintains an Information Security Program to protect Institutional Data and University technology resources. This policy defines the requirements staff must follow to safeguard information, systems, and digital services.
2. Purpose
The purpose of this policy is to establish clear expectations and security requirements for Institutional Data and University systems. It ensures consistency across the University and aligns with industry standards and regulations.
3. Scope
This policy applies to:
- All staff, faculty, administrators, student workers, contractors, consultants, and vendors
- All systems, devices, networks, applications, and cloud services used for University business
- All classifications of Institutional Data
- All access methods including on-campus, remote, mobile, or automated
4. Security Principles
4.1 Govern
- Follow all University security policies and standards.
- Ensure compliance with legal, regulatory, and contractual obligations.
- Use only University-approved technologies for official business.
4.2 Identify
- Understand the sensitivity of the data you handle.
- Apply University classification rules for Public, Internal, Confidential, and Restricted data.
- Use only approved systems for storing or transmitting data.
4.3 Protect
- Use multi-factor authentication (MFA) where required.
- Protect Institutional Data using encryption, secure storage, and proper access controls.
- Install only approved software and keep systems updated.
4.4 Detect
- Remain alert for phishing attempts or unusual system behavior.
- Report suspicious activity immediately.
4.5 Respond
- Report cybersecurity incidents promptly.
- Preserve evidence and follow Information Security Office instructions.
4.6 Recover
- Assist in system or data restoration as needed.
- Support post‑incident validation activities.
5. Roles and Responsibilities
5.1 Staff Members
- Protect Institutional Data in all formats.
- Use only approved systems and applications.
- Complete required cybersecurity training.
- Report security concerns immediately.
5.2 Information Security Office (ISO)
- Manage the Information Security Program.
- Monitor for threats and suspicious activity.
- Lead incident response processes.
- Perform security risk assessments.
5.3 Data Owners
- Classify data based on sensitivity.
- Approve access to sensitive data.
- Ensure appropriate business and security controls.
5.4 System Owners
- Apply patches and maintain secure configurations.
- Ensure logging and monitoring remain active.
- Maintain compliance with security requirements.
5.5 Legal and Privacy
- Provide guidance on regulatory obligations.
- Support incident response processes.
5.6 Internal Audit
- Perform independent control assessments.
- Verify compliance with University policy.
6. Security Requirements for Staff
6.1 Identity and Access Management
- Use multi‑factor authentication (MFA) where required.
- Protect authentication devices and credentials.
- Use only assigned University accounts.
- Request timely removal of access when no longer needed.
6.2 Data Protection
Classification
- Public
- Internal
- Confidential
- Restricted
Storage
- Use only University‑approved storage platforms.
- No personal devices or cloud accounts for Institutional Data.
Encryption
- Sensitive and Restricted data encrypted at rest.
- All sensitive data encrypted in transit.
Data Loss Prevention
Do not bypass monitoring or data‑loss prevention controls.
6.3 Data Integrity
The University uses integrity controls such as checksums, tamper‑evident logs, validated backups, and file integrity monitoring. Staff must report corrupted or suspicious data.
6.4 Device and System Security
- Keep devices updated.
- Install only approved software.
- Report lost or stolen devices immediately.
- Do not store Restricted data on personal devices.
6.5 Secure Development and Change Management
- Use secure development practices.
- Conduct code reviews and use version control.
- Follow approved change management procedures.
6.6 Monitoring and Logging
Do not alter, disable, or interfere with monitoring or logging tools.
6.7 Incident Response
Report immediately:
- Suspicious emails
- Unauthorized access attempts
- Malware or unusual activity
- Corrupted, missing, or exposed data
- Lost or stolen devices
Do not delete or modify evidence.
6.8 Artificial Intelligence (AI) and Digital Tools
Approved: Microsoft 365 Copilot, KeanU AI
Not approved: Public AI tools unless formally reviewed
No sensitive data may be entered into unapproved tools.
Review all AI-generated content before use.
6.9 Training and Awareness
- Annual cybersecurity training
- Phishing simulations
- Role-based security training
7. Exceptions
Exception requests must include a justification, risk assessment, compensating controls, and a defined time limit. All exceptions must go through the formal review process.
8. Enforcement
Non‑compliance may result in removal of access, HR disciplinary action, vendor consequences, or regulatory reporting obligations. Severe or repeated violations may trigger additional administrative or legal action.
9. Document Control
This policy is maintained by the Information Security Office and reviewed annually or as required based on technology, regulatory, or risk changes.
``