Kean University Access Control Policy
Table of Contents
- About This Policy
- Scope
- Key Principles
- Roles & Responsibilities
- Access Control Requirements
- Monitoring & Logging
- Enforcement
About This Policy
Kean University uses access controls to ensure that only the right people — and only those people — can access University systems, applications, and data. This protects confidentiality, integrity, and availability across all environments, including on‑campus, cloud, and hybrid platforms.
Example: Your role may require access to Banner but not HR financial records. Access controls ensure each user only sees what their role requires.
Scope
This policy applies to all individuals who use Kean systems, including:
- Faculty and staff
- Student workers
- Contractors and consultants
- Vendors supporting Kean systems
This includes all systems owned or managed by Kean University.
Key Principles
Access to Kean University resources must always be:
- Authorized — granted only after appropriate approvals.
- Authenticated — using secure authentication (such as multi-factor authentication).
- Auditable — logged and subject to review.
- Revocable — removed immediately when no longer needed.
Example: If a student worker graduates, their shared folder access must be removed immediately.
Roles & Responsibilities
IT Security Team
Implements access controls, monitors activity, and investigates anomalies or suspicious behavior.
Managers & Supervisors
Approve access requests and ensure that team members follow this policy.
Compliance Team
Ensures access control practices comply with regulations such as the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act (HIPAA).
All Users
Follow access rules, protect credentials, and report suspicious activity immediately.
Access Control Requirements
5.1 Authorization — Getting Access the Right Way
- All requests must be submitted through the official access request system.
- Requests must be approved by the user’s manager and IT Security.
Example: To access a SharePoint site, your manager must approve the request before IT can grant access.
5.2 Authentication — Proving Who You Are
- Multi-factor authentication (MFA) is required for all accounts.
- Passwords must be at least 12 characters and include uppercase, lowercase, numbers, and symbols.
- Sessions must automatically time out after 15 minutes of inactivity.
Example: Logging into Microsoft 365 requires both your password and an authenticator app code.
5.3 Role-Based Access Control (RBAC)
- Access is tied to job responsibilities.
- Privileged accounts (admin, root, etc.) are tightly controlled and monitored.
Example: An advisor may view academic records but cannot access HR salary data.
5.4 Least Privilege — Only What You Need
- Users follow the principle of least privilege and receive only the minimum access needed.
- Access must be removed or adjusted immediately when duties change.
Example: When moving from Finance to Advising, Finance permissions must be removed right away.
5.5 Access Reviews — Keeping Things Current
- All accounts and permissions must be reviewed quarterly.
- Access must be removed immediately for terminated or transferred users.
5.6 Emergency Access — Break Glass Accounts
- Emergency access requires approval from IT Security.
- Emergency access logs must be reviewed within 24 hours.
Example: A database admin may receive temporary emergency access to resolve a critical outage — but all actions must be logged and reviewed.
Monitoring & Logging
All access events must be logged in the Security Information and Event Management (SIEM) system. Alerts must be generated for unauthorized access attempts.
Example: If someone repeatedly tries to access a restricted folder, security analysts receive an automatic alert.
Enforcement
Failure to comply with this policy may result in:
- Loss of system access
- HR disciplinary action
- Contract penalties for vendors
- Legal consequences for severe violations