Endpoint Security Policy

Skip to main content


Kean University Endpoint Security Policy (User‑Facing)

WCAG 2.2 AA Compliant — Accessible for screen readers and keyboard navigation.

Table of Contents


What This Policy Is About (In Plain English)

Kean University uses a lot of devices — laptops, desktops, phones, tablets, servers — and every one of them can become a doorway for cyber threats if not secured properly.

This policy explains how to keep your device (and Kean’s systems) safe. Whether the device is Kean‑owned or personal, if it connects to Kean systems, it must follow this policy.

Back to top


Who Must Follow This Policy

Everyone who uses Kean systems:

  • Faculty & staff
  • Students
  • Contractors
  • Vendors
  • Anyone using a Kean-owned or personal device to access Kean accounts or data

Back to top


What You MUST Do to Keep Your Device Secure

A. Use a properly configured device
  • Your device must use a Kean‑approved operating system.
  • IT manages device settings — do not attempt to bypass them.
  • Local admin access is restricted to IT staff only.
B. Use strong login protection
  • Multi‑Factor Authentication (MFA) is required for all logins.
  • Your password must be strong:
    • At least 12 characters
    • Mix of upper/lowercase letters, numbers, and symbols
  • Your device locks automatically after 15 minutes of inactivity.
  • Your account locks after 5 failed password attempts.
C. Keep your device updated
  • Critical security updates must be installed within 14 days.
  • Patch compliance is checked monthly.
D. Your device must have Kean‑approved protection tools
  • Anti‑malware software installed
  • Endpoint Detection & Response (EDR) enabled
  • Real‑time protection active
  • Daily threat definition updates required
E. Protect sensitive information
  • Kean-owned devices use full‑disk encryption.
  • Do not store sensitive files locally unless approved and encrypted.
F. Expect monitoring (for security only)
  • Kean monitors device activity for security threats only.
  • Logs are kept for 12 months.
  • Security teams review logs monthly.
G. Report security issues immediately (within 1 hour)
  • If something feels suspicious — pop‑ups, random restarts, strange prompts, unexpected MFA requests — contact IT within 1 hour.

Back to top


What You Should NEVER Do

  • Disable antivirus or EDR tools
  • Share passwords or approve MFA prompts you didn’t initiate
  • Store sensitive student or employee data on unencrypted drives
  • Install unapproved apps/programs on Kean-owned devices
  • Connect jailbroken or rooted devices to Kean systems
  • Attempt to gain admin access on your device

These actions weaken campus security and violate policy.

Back to top


If You Think Something Is Wrong

Contact:

[Security_Email]@kean.edu
(Add Service Desk phone number if desired)

Report issues if you notice:

  • Your computer suddenly slows down
  • Antivirus turns off by itself
  • Your device restarts unexpectedly
  • MFA prompts appear when you aren’t logging in
  • You clicked a suspicious link

Back to top


Roles & Responsibilities

You

Follow device security rules and report issues ASAP.

IT Security Team

Sets device standards, monitors threats, and responds to incidents.

Department Heads

Encourage staff compliance and report violations.

Vendors & Third Parties

Must follow the same rules for any connected devices.

Back to top


What Happens if You Don’t Follow This Policy

Kean uses a progressive enforcement model:

  1. First violation → Written warning
  2. Repeat violations → Loss of device or system access
  3. Serious violations → HR or legal action

Back to top


Exceptions

  • Must include a risk analysis
  • Must be approved by the Chief Information Officer (CIO)
  • Reviewed annually
  • Logged in the IT Exceptions Register

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.