Kean University Endpoint Security Policy (User‑Facing)
WCAG 2.2 AA Compliant — Accessible for screen readers and keyboard navigation.
Table of Contents
- What This Policy Is About
- Who Must Follow This Policy
- What You MUST Do to Keep Your Device Secure
- What You Should NEVER Do
- If You Think Something Is Wrong
- Roles & Responsibilities
- What Happens If You Don’t Follow This Policy
- Exceptions
What This Policy Is About (In Plain English)
Kean University uses a lot of devices — laptops, desktops, phones, tablets, servers — and every one of them can become a doorway for cyber threats if not secured properly.
This policy explains how to keep your device (and Kean’s systems) safe. Whether the device is Kean‑owned or personal, if it connects to Kean systems, it must follow this policy.
Who Must Follow This Policy
Everyone who uses Kean systems:
- Faculty & staff
- Students
- Contractors
- Vendors
- Anyone using a Kean-owned or personal device to access Kean accounts or data
What You MUST Do to Keep Your Device Secure
A. Use a properly configured device
- Your device must use a Kean‑approved operating system.
- IT manages device settings — do not attempt to bypass them.
- Local admin access is restricted to IT staff only.
B. Use strong login protection
- Multi‑Factor Authentication (MFA) is required for all logins.
- Your password must be strong:
- At least 12 characters
- Mix of upper/lowercase letters, numbers, and symbols
- Your device locks automatically after 15 minutes of inactivity.
- Your account locks after 5 failed password attempts.
C. Keep your device updated
- Critical security updates must be installed within 14 days.
- Patch compliance is checked monthly.
D. Your device must have Kean‑approved protection tools
- Anti‑malware software installed
- Endpoint Detection & Response (EDR) enabled
- Real‑time protection active
- Daily threat definition updates required
E. Protect sensitive information
- Kean-owned devices use full‑disk encryption.
- Do not store sensitive files locally unless approved and encrypted.
F. Expect monitoring (for security only)
- Kean monitors device activity for security threats only.
- Logs are kept for 12 months.
- Security teams review logs monthly.
G. Report security issues immediately (within 1 hour)
- If something feels suspicious — pop‑ups, random restarts, strange prompts, unexpected MFA requests — contact IT within 1 hour.
What You Should NEVER Do
- Disable antivirus or EDR tools
- Share passwords or approve MFA prompts you didn’t initiate
- Store sensitive student or employee data on unencrypted drives
- Install unapproved apps/programs on Kean-owned devices
- Connect jailbroken or rooted devices to Kean systems
- Attempt to gain admin access on your device
These actions weaken campus security and violate policy.
If You Think Something Is Wrong
Contact:
[Security_Email]@kean.edu
(Add Service Desk phone number if desired)
Report issues if you notice:
- Your computer suddenly slows down
- Antivirus turns off by itself
- Your device restarts unexpectedly
- MFA prompts appear when you aren’t logging in
- You clicked a suspicious link
Roles & Responsibilities
You
Follow device security rules and report issues ASAP.
IT Security Team
Sets device standards, monitors threats, and responds to incidents.
Department Heads
Encourage staff compliance and report violations.
Vendors & Third Parties
Must follow the same rules for any connected devices.
What Happens if You Don’t Follow This Policy
Kean uses a progressive enforcement model:
- First violation → Written warning
- Repeat violations → Loss of device or system access
- Serious violations → HR or legal action
Exceptions
- Must include a risk analysis
- Must be approved by the Chief Information Officer (CIO)
- Reviewed annually
- Logged in the IT Exceptions Register
``