KU ID 02 – Access Control Policy (Staff‑Facing Version)
Table of Contents
- 1. Purpose
- 2. Who Must Follow This Policy
- 3. Systems Covered
- 4. Types of Access Covered
- 5. Key Responsibilities for Staff
- 6. Roles & Responsibilities
- 7. Compliance Requirements
- 8. Enforcement
- 9. Exceptions
- 10. Review Cycle
1. Purpose
This policy defines how access to Kean University systems is requested, approved, monitored, and removed. It ensures users receive only the access they need and lose access promptly when it’s no longer required.
All authentication rules (passwords, MFA, lockouts, timeouts) are defined in the KU ID 02‑ST – Password & Authentication Standard.
2. Who Must Follow This Policy
This policy applies to anyone granted access to University systems, including:
- Employees
- Contractors
- Third‑party vendors
3. Systems Covered
- Kean‑owned or managed applications
- On‑premise systems
- Cloud and hybrid services
4. Types of Access Covered
- User access (employees, faculty, students)
- Administrative / privileged access
- Emergency access
- Service/system accounts
5. Key Responsibilities for Staff
5.1 Requesting Access
To receive access, you must:
- Submit an official access request
- Obtain manager approval
- Undergo security review when required
5.2 Authentication Requirements
Authentication controls (passwords, MFA, lockouts) are defined in the Password & Authentication Standard.
5.3 Role‑Based Access
Access is based on your job role and limited to duties you must perform.
5.4 Least Privilege
- Use only minimum access required
- Notify IT when access is no longer needed
5.5 Access Reviews
Quarterly reviews ensure your access is still appropriate.
5.6 Emergency Access
Emergency access must:
- Be approved
- Be fully logged
- Be reviewed within 24 hours
5.7 Monitoring & Logging
All access events are logged in Kean’s SIEM. Unauthorized attempts generate alerts.
6. Roles & Responsibilities
CISO
- Oversees access governance
IAM Lead
- Manages provisioning & deprovisioning
- Oversees quarterly reviews
Managers
- Approve access requests
Security Operations
- Monitor access logs and alerts
System Owners
- Validate permission levels for their applications
Internal Audit
- Review access control compliance
Users
- Follow access processes
- Protect credentials
- Report suspicious activity
7. Compliance Requirements
- NIST CSF 2.0 PR.AC (Access Control)
- FERPA
- HIPAA
- GLBA Safeguards Rule
- New Jersey access governance requirements
8. Enforcement
- Access may be revoked
- Employees may face corrective or disciplinary action
- Vendors may face legal or contractual penalties
9. Exceptions
- Must follow KU SEC 05 – Exception Management
- Require documented risk analysis
- Must include compensating controls
- Must receive CISO + GRC approval
- Expire after 12 months
- Logged in the Exception Register
10. Review Cycle
This policy is reviewed annually and after significant regulatory or system changes.