KU IT 03 - Cybersecurity Training and Awareness Policy


Skip to main content

Cybersecurity Training & Awareness Policy (Staff‑Facing Version)

Table of Contents

1. Purpose

This policy describes required cybersecurity training for all Kean University users. It ensures individuals can identify cyber threats and protect University data in alignment with:

  • NIST Cybersecurity Framework (CSF) 2.0
  • CIS Controls v8
  • FERPA (Family Educational Rights and Privacy Act)
  • GLBA (Gramm–Leach–Bliley Act)
  • NIST SP 800‑171 (Controlled Unclassified Information)

Back to top

2. Who Must Follow This Policy

This policy applies to anyone accessing Kean University technology systems, including:

  • Staff
  • Faculty
  • Students with protected system access
  • Contractors and temporary employees
  • Third‑party vendors
  • High‑risk users

Back to top

3. Training Requirements

3.1 Annual Cybersecurity Training

The yearly required course covers topics including:

  • Phishing and social engineering
  • Password and authentication safety
  • Data handling and privacy
  • Safe browsing and device usage
  • Incident reporting procedures

3.2 Required Assessment

You must pass a post‑training assessment. If you fail:

  • Remediation training must be completed within 30 days.
  • Repeated failures may result in escalation or temporary access restrictions.

3.3 Onboarding Training

  • New employees must complete training within 30 days of onboarding.
  • Offboarding may include a security briefing and access reminders.

3.4 Post‑Incident Training

Users involved in a security incident must complete incident‑specific training within 15 days.

3.5 Role‑Based Training

Additional specialized training applies to:

  • IT
  • Human Resources
  • Finance
  • Research
  • Faculty
  • Executives

3.6 High‑Risk User Training

High‑risk users must:

  • Complete advanced training twice per year
  • Participate in targeted phishing simulations

High‑risk designations are reviewed annually.

3.7 Risk‑Triggered Training

Extra training may be required when concerning activity is detected, including:

  • Repeated phishing test failures
  • Security Information and Event Management (SIEM) alerts
  • Other documented unsafe behavior

Back to top

4. Awareness Activities

Quarterly cybersecurity awareness efforts may include:

  • Email campaigns
  • Digital signage and posters
  • Live workshops or training sessions
  • Phishing simulation communications

Back to top

5. Training Tracking & Reporting
  • All training completions are logged.
  • Phishing simulation and training compliance are reported quarterly.
  • Metrics feed into the University's risk dashboard.

Back to top

6. Roles & Responsibilities

Kean IT – Information Security

  • Develop training content
  • Track compliance and maintain logs
  • Manage risk‑triggered and post‑incident training

Managers & Supervisors

  • Ensure employee compliance

Human Resources

  • Integrate training into onboarding and offboarding

Executives

  • Model cybersecurity best practices

All Users

  • Complete required training and assessments

Third‑Party Vendors

  • Meet training requirements defined in contracts

Back to top

7. Enforcement
  • Temporary access suspension
  • Required remediation
  • Escalation to HR or leadership
  • Disciplinary action
  • Regulatory reporting if risk is significant

Back to top

8. Exceptions

All exception requests must:

  • Follow the Exception Management Policy
  • Include justification and risk analysis
  • Provide compensating controls
  • Be approved by Information Security and GRC
  • Not exceed 12 months
  • Be added to the Exception Register

Back to top

10. Review Schedule

This policy is reviewed annually and updated in response to regulatory, institutional, or technological changes.

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.