KU SEC 9 - Breach Notification Policy


Breach Notification Policy (Simplified)

Table of Contents

1. Overview

The Breach Notification Policy explains what must happen if Kean University data is exposed, accessed without permission, or lost. This policy ensures Kean:

  • Detects and reports breaches quickly
  • Notifies affected people and regulators on time
  • Follows all laws, including FERPA, GLBA, and New Jersey requirements
  • Documents incidents thoroughly and communicates accurately

2. Who Must Follow This Policy?

This policy applies to all individuals handling Kean University data, including:

  • Faculty and staff
  • Students with system access
  • Incident Response Team members
  • Legal, HR, Communications, Vendor Management
  • Third‑party vendors and cloud service providers

3. What Systems & Data Are Covered?

Systems

  • All Kean information systems
  • Critical academic, financial, and compliance systems
  • Cloud and third‑party hosted platforms

Data Types

  • Restricted data (FERPA, GLBA‑covered financial data)
  • Confidential or internal institutional data
  • Personal information (PII) and health information (PHI)
  • Research data with confidentiality requirements

Types of Breaches

  • Digital breaches (hacking, unauthorized access, data exfiltration)
  • Physical breaches (lost laptops, misdirected mail)
  • Cloud/SaaS breaches
  • Vendor‑originated incidents

4. Key Breach Notification Requirements

Expand Key Breach Requirements

4.1 Detecting & Reporting Breaches

  • Suspected or confirmed breaches must be reported within 1 hour.
  • Network-related breaches must follow the Incident Response Plan.
  • SOC analysts must escalate breach indicators immediately.

4.2 Notification Timelines

  • Internal leaders (CIO, Legal, HR) notified within 2 hours.
  • Regulator notification must follow legal timelines (e.g., GDPR 72 hours).
  • Affected individuals must be notified within 10 business days unless law enforcement delays notification.

4.3 Vendor Requirements

  • Vendors must notify Kean within 24 hours of any breach affecting university data.
  • Vendor contracts must include breach‑notification requirements.

4.4 Documentation Requirements

All breaches must be documented in the incident management system, including:

  • Timeline of events
  • Root cause
  • Containment and remediation actions
  • Corrective actions

4.5 Communications & Public Messaging

  • All public statements must be approved by Legal and Communications.
  • A single “source of truth” webpage must be maintained during major incidents.
  • All messaging must follow Kean’s communications protocol.

5. Roles & Responsibilities

Expand Roles & Responsibilities

Information Security (CISO)

  • Oversees breach response
  • Coordinates regulator notifications

Incident Response Team

  • Detects, contains, and remediates breaches
  • Escalates incidents following the IR Plan

Legal Department

  • Confirms regulatory requirements
  • Provides compliance guidance

Communications Lead

  • Approves and manages all internal/external messaging

Vendor Management

  • Ensures vendors follow breach notification clauses
  • Coordinates vendor escalation

System Owners

  • Assist with logs, analysis, and containment activities

Vendors

  • Notify Kean quickly about breaches
  • Support investigations

6. Compliance Requirements

  • NIST CSF 2.0
  • ISO 27001
  • FERPA & GLBA requirements
  • New Jersey Data Breach Notification Act

7. Enforcement

Violations may result in:

  • Written warnings
  • System access removal
  • HR or legal escalation for severe infractions
  • Vendor contract penalties for noncompliance

8. Exceptions

Exceptions must follow the Exception Management Policy and require:

  • Written request
  • Risk analysis & compensating controls
  • CIO (and Legal for high‑risk) approval
  • Maximum duration of 12 months
  • Quarterly review and tracking in the Exception Register
  • RC01 – Policy Governance Standard
  • KU SEC 10 – Cybersecurity & IT Governance
  • Incident Response Plan
  • Data Classification Policy
  • Vendor Management Policy
  • Access Management Policy
  • Risk Management Policy

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.