Privileged Access Management (PAM) Policy


Kean University Privileged Access Management (PAM) Policy

Table of Contents


About This Policy

Kean University uses privileged access controls to protect sensitive systems, critical infrastructure, and high-impact data. Privileged accounts have elevated capabilities — such as installing software, modifying configurations, accessing restricted data, and managing security tools. Because these accounts pose high risk if misused or compromised, they require enhanced protections.

Example: A database administrator (DBA) can view or update thousands of records. If their account is compromised, attackers could steal or corrupt large volumes of data instantly.

Back to top

Scope

This policy applies to all individuals with privileged or administrative access, including:

  • Employees with elevated or administrative permissions
  • IT administrators
  • System owners
  • Contractors and vendors managing Kean systems

This policy covers all platforms, including servers, applications, databases, networks, and cloud services.

Back to top

Core Principles

Kean University’s approach to privileged access is based on four essential principles:

  • Authorized only: Privileged access is granted strictly based on legitimate business needs.
  • Secured tightly: Privileged accounts require strong authentication and secure session controls.
  • Monitored closely: Admin actions are logged, reviewed, and monitored for suspicious behavior.
  • Revoked quickly: Access must be removed immediately when no longer necessary.

Example: When a system engineer transfers into a non-technical position, their elevated access must be removed the same day.

Back to top

Detailed Policy Requirements

4.1 Access Control — Least Privilege Always

  • Privileged access must follow the principle of least privilege — users receive only the minimum permissions required.
  • All privileged access must be approved by both:
    • The system owner
    • The Information Security Office (ISO)

Example: A contractor hired for one project should not receive full domain admin access — only the specific rights required for the defined assignment.

Back to top

4.2 Authentication — Strong Access Protection

  • Multi-factor authentication (MFA) is required for every privileged account — without exception.
  • Privileged account passwords must follow Kean’s Password Policy.

Example: Logging in as a server administrator requires both a password and an MFA token or authenticator app approval.

Back to top

4.3 Session Management — Secure Admin Sessions

All privileged sessions must:

  • Be accessed through approved Privileged Access Management (PAM) tools or secure jump servers
  • Record all administrative actions

Example: When working on production servers, administrators must use the approved jump server, not connect directly from a personal workstation.

Back to top

4.4 Logging & Monitoring — Every Action Leaves a Trail

  • All privileged activity must be logged into the Security Information and Event Management (SIEM) system.
  • Alerts must be generated for:
    • Unauthorized privilege escalation
    • Abnormal administrator behavior

Example: If an administrator attempts to change hundreds of file permissions at midnight, the SIEM system alerts security analysts automatically.

Back to top

4.5 Periodic Review — Quarterly Check-ups

  • ISO must conduct quarterly reviews of all privileged accounts.
  • Privileged accounts unused for 30 days must be disabled.

Example: A developer’s admin account is disabled if unused for 30 days, reducing unneeded attack surface.

Back to top

4.6 Emergency Access — Break Glass Procedures

Emergency privileged access is allowed only when:

  • Credentials are stored in a secure vault
  • ISO and the Chief Information Officer (CIO) approve the request
  • A post-event review is completed within 24 hours

Example: During a critical outage, a break-glass account may be used — but ISO must review all actions performed.

Back to top

4.7 Deprovisioning — Remove Rights Immediately

Privileged access must be revoked:

  • Immediately upon termination
  • Immediately upon role change
  • Immediately when a contract ends

Example: When an administrator leaves the University, all privileged access must be disabled before their final day.

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.