Breach Notification Policy (Simplified)
Table of Contents
- 1. Overview
- 2. Who Must Follow This Policy?
- 3. What Systems & Data Are Covered?
- 4. Key Breach Notification Requirements
- 5. Roles & Responsibilities
- 6. Compliance Requirements
- 7. Enforcement
- 8. Exceptions
- 9. Related Policies
1. Overview
The Breach Notification Policy explains what must happen if Kean University data is exposed, accessed without permission, or lost. This policy ensures Kean:
- Detects and reports breaches quickly
- Notifies affected people and regulators on time
- Follows all laws, including FERPA, GLBA, and New Jersey requirements
- Documents incidents thoroughly and communicates accurately
2. Who Must Follow This Policy?
This policy applies to all individuals handling Kean University data, including:
- Faculty and staff
- Students with system access
- Incident Response Team members
- Legal, HR, Communications, Vendor Management
- Third‑party vendors and cloud service providers
3. What Systems & Data Are Covered?
Systems
- All Kean information systems
- Critical academic, financial, and compliance systems
- Cloud and third‑party hosted platforms
Data Types
- Restricted data (FERPA, GLBA‑covered financial data)
- Confidential or internal institutional data
- Personal information (PII) and health information (PHI)
- Research data with confidentiality requirements
Types of Breaches
- Digital breaches (hacking, unauthorized access, data exfiltration)
- Physical breaches (lost laptops, misdirected mail)
- Cloud/SaaS breaches
- Vendor‑originated incidents
4. Key Breach Notification Requirements
Expand Key Breach Requirements
4.1 Detecting & Reporting Breaches
- Suspected or confirmed breaches must be reported within 1 hour.
- Network-related breaches must follow the Incident Response Plan.
- SOC analysts must escalate breach indicators immediately.
4.2 Notification Timelines
- Internal leaders (CIO, Legal, HR) notified within 2 hours.
- Regulator notification must follow legal timelines (e.g., GDPR 72 hours).
- Affected individuals must be notified within 10 business days unless law enforcement delays notification.
4.3 Vendor Requirements
- Vendors must notify Kean within 24 hours of any breach affecting university data.
- Vendor contracts must include breach‑notification requirements.
4.4 Documentation Requirements
All breaches must be documented in the incident management system, including:
- Timeline of events
- Root cause
- Containment and remediation actions
- Corrective actions
4.5 Communications & Public Messaging
- All public statements must be approved by Legal and Communications.
- A single “source of truth” webpage must be maintained during major incidents.
- All messaging must follow Kean’s communications protocol.
5. Roles & Responsibilities
Expand Roles & Responsibilities
Information Security (CISO)
- Oversees breach response
- Coordinates regulator notifications
Incident Response Team
- Detects, contains, and remediates breaches
- Escalates incidents following the IR Plan
Legal Department
- Confirms regulatory requirements
- Provides compliance guidance
Communications Lead
- Approves and manages all internal/external messaging
Vendor Management
- Ensures vendors follow breach notification clauses
- Coordinates vendor escalation
System Owners
- Assist with logs, analysis, and containment activities
Vendors
- Notify Kean quickly about breaches
- Support investigations
6. Compliance Requirements
- NIST CSF 2.0
- ISO 27001
- FERPA & GLBA requirements
- New Jersey Data Breach Notification Act
7. Enforcement
Violations may result in:
- Written warnings
- System access removal
- HR or legal escalation for severe infractions
- Vendor contract penalties for noncompliance
8. Exceptions
Exceptions must follow the Exception Management Policy and require:
- Written request
- Risk analysis & compensating controls
- CIO (and Legal for high‑risk) approval
- Maximum duration of 12 months
- Quarterly review and tracking in the Exception Register
9. Related Policies
- RC01 – Policy Governance Standard
- KU SEC 10 – Cybersecurity & IT Governance
- Incident Response Plan
- Data Classification Policy
- Vendor Management Policy
- Access Management Policy
- Risk Management Policy