Cybersecurity Training & Awareness Policy (Staff‑Facing Version)
Table of Contents
- 1. Purpose
- 2. Who Must Follow This Policy
- 3. Training Requirements
- 4. Awareness Activities
- 5. Training Tracking & Reporting
- 6. Roles & Responsibilities
- 7. Enforcement
- 8. Exceptions
- 9. Related Documents
- 10. Review Schedule
1. Purpose
This policy describes required cybersecurity training for all Kean University users. It ensures individuals can identify cyber threats and protect University data in alignment with:
- NIST Cybersecurity Framework (CSF) 2.0
- CIS Controls v8
- FERPA (Family Educational Rights and Privacy Act)
- GLBA (Gramm–Leach–Bliley Act)
- NIST SP 800‑171 (Controlled Unclassified Information)
2. Who Must Follow This Policy
This policy applies to anyone accessing Kean University technology systems, including:
- Staff
- Faculty
- Students with protected system access
- Contractors and temporary employees
- Third‑party vendors
- High‑risk users
3. Training Requirements
3.1 Annual Cybersecurity Training
The yearly required course covers topics including:
- Phishing and social engineering
- Password and authentication safety
- Data handling and privacy
- Safe browsing and device usage
- Incident reporting procedures
3.2 Required Assessment
You must pass a post‑training assessment. If you fail:
- Remediation training must be completed within 30 days.
- Repeated failures may result in escalation or temporary access restrictions.
3.3 Onboarding Training
- New employees must complete training within 30 days of onboarding.
- Offboarding may include a security briefing and access reminders.
3.4 Post‑Incident Training
Users involved in a security incident must complete incident‑specific training within 15 days.
3.5 Role‑Based Training
Additional specialized training applies to:
- IT
- Human Resources
- Finance
- Research
- Faculty
- Executives
3.6 High‑Risk User Training
High‑risk users must:
- Complete advanced training twice per year
- Participate in targeted phishing simulations
High‑risk designations are reviewed annually.
3.7 Risk‑Triggered Training
Extra training may be required when concerning activity is detected, including:
- Repeated phishing test failures
- Security Information and Event Management (SIEM) alerts
- Other documented unsafe behavior
4. Awareness Activities
Quarterly cybersecurity awareness efforts may include:
- Email campaigns
- Digital signage and posters
- Live workshops or training sessions
- Phishing simulation communications
5. Training Tracking & Reporting
- All training completions are logged.
- Phishing simulation and training compliance are reported quarterly.
- Metrics feed into the University's risk dashboard.
6. Roles & Responsibilities
Kean IT – Information Security
- Develop training content
- Track compliance and maintain logs
- Manage risk‑triggered and post‑incident training
Managers & Supervisors
- Ensure employee compliance
Human Resources
- Integrate training into onboarding and offboarding
Executives
- Model cybersecurity best practices
All Users
- Complete required training and assessments
Third‑Party Vendors
- Meet training requirements defined in contracts
7. Enforcement
- Temporary access suspension
- Required remediation
- Escalation to HR or leadership
- Disciplinary action
- Regulatory reporting if risk is significant
8. Exceptions
All exception requests must:
- Follow the Exception Management Policy
- Include justification and risk analysis
- Provide compensating controls
- Be approved by Information Security and GRC
- Not exceed 12 months
- Be added to the Exception Register
10. Review Schedule
This policy is reviewed annually and updated in response to regulatory, institutional, or technological changes.