KU SEC 08 - Logging and Monitoring Policy


Logging & Monitoring Policy (Simplified)

Table of Contents

1. Overview

The Logging & Monitoring Policy ensures Kean University systems generate logs that support threat detection, investigations, and regulatory compliance. Logging helps Kean:

  • Identify and respond to cybersecurity incidents
  • Maintain audit trails
  • Detect unusual or unauthorized activity
  • Meet FERPA, GLBA, HIPAA, and NIST CSF 2.0 standards

2. Who Must Follow This Policy?

This policy applies to individuals involved in system use, administration, or monitoring, including:

  • Faculty, staff, and students
  • Kean IT – Information Security
  • IT Operations, system administrators, network and cloud administrators
  • Third‑party vendors handling Kean data or systems

3. Systems & Data Covered

Systems

All Kean systems must follow this policy, including:

  • Servers, endpoints, and network devices
  • Cloud platforms and SaaS services
  • Academic, research, and administrative systems

Data Types

Logging applies to all university data classifications:

  • Public
  • Internal
  • Confidential
  • Restricted

When Logging Applies

Logging is required throughout the system lifecycle:

  • Development
  • Deployment
  • Maintenance
  • Decommissioning

4. Key Logging Requirements

Expand Key Logging Requirements

4.1 Log Generation

Systems must generate logs for key activities, including:

  • Logins and authentication attempts
  • Access to sensitive or restricted data
  • Configuration or permission changes
  • System and application errors

Logs must include: timestamp, source IP, user ID, event type, and outcome.

4.2 Centralized Log Collection

  • Logs must be sent securely to Kean’s centralized SIEM platform.
  • Cloud and vendor systems must integrate with centralized logging.
  • Log collection must support redundancy and failover.

4.3 Continuous Monitoring

Monitoring must identify:

  • Unauthorized access
  • Anomalous or unusual activity
  • Threats or suspicious behavior

Monitoring includes:

  • Network traffic
  • Endpoint events
  • User behavior
  • Cloud activity

Alerts must be routed to designated security personnel.

4.4 Retention & Protection

  • Audit logs must be stored for required retention periods.
  • Logs must be protected from unauthorized access or tampering.
  • Archived logs must remain accessible for investigations.

4.5 Support for Incident Response

Logs must support every phase of incident response:

  • Detection
  • Containment
  • Eradication
  • Recovery

4.6 Governance & Review

  • Logging processes must be reviewed annually or after major changes.
  • Personnel must complete annual training on logging and monitoring.
  • Logging practices must meet applicable accessibility standards.

4.7 Risk‑Based Logging Levels

Tier 1 (High Risk) – Restricted or Confidential Data

  • Full logging
  • Real‑time monitoring
  • Minimum 1‑year log retention

Tier 2 (Moderate Risk) – Academic/Admin Systems

  • Standard logging
  • Daily review
  • 6‑month log retention

Tier 3 (Low Risk) – Public‑Facing Systems

  • Basic logging
  • Weekly review
  • 3‑month log retention

5. Roles & Responsibilities

Expand Roles & Responsibilities

Information Security (CISO Office)

  • Maintain the university logging and monitoring strategy.
  • Coordinate audits and oversee monitoring capabilities.

IT Operations & Infrastructure

  • Maintain logging tools and collectors.
  • Ensure systems generate and forward logs correctly.
  • Patch and maintain logging infrastructure.

System & Application Administrators

  • Configure and maintain application logging.
  • Respond to log‑related alerts.

Network & Cloud Administrators

  • Forward logs securely to centralized logging.
  • Monitor network and cloud activity.

Internal Audit & Compliance

  • Audit logging processes and retention practices.

Executive Leadership

  • Review logging and monitoring reports.
  • Support remediation and improvement initiatives.

End Users

  • Follow acceptable use guidelines.
  • Report suspicious activity or unusual system behavior.

6. Enforcement

Failure to follow this policy may result in HR disciplinary action, restricted system access, or escalation for unauthorized log tampering, which is a serious violation.

7. Exceptions

Exceptions must follow the Exception Management Policy and require:

  • Written justification
  • Risk analysis
  • Compensating controls
  • Time‑bound approval (maximum 12 months)
  • CIO approval for high‑risk exceptions
  • Quarterly review in the Exception Register
  • RC01 – Policy Governance Standard
  • KU SEC 10 – Cybersecurity & IT Governance
  • Information Security Policy
  • Data Classification & Handling Policy
  • SIEM & Detection Engineering Policy
  • Incident Response Policy
  • Cloud Computing & Third‑Party Risk Policy

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.