KU ID 04 - Privileged Access Management



Kean University Privileged Access Management Policy

Table of Contents

1. What This Policy Is About

The Privileged Access Management (PAM) Policy explains how Kean University manages accounts with elevated permissions. These accounts pose higher security risk, so additional controls, approvals, and monitoring are required.

[Link to authoritative KU ID 04 Word document]

Back to top

2. Why This Matters for Staff

This policy helps staff understand:

  • What privileged access is
  • How privileged accounts are approved and reviewed
  • Your responsibilities when using elevated access
  • Emergency (break‑glass) access rules
  • Compliance with FERPA, HIPAA, GLBA, and NIST CSF 2.0

Back to top

3. Who This Policy Covers

This policy applies to individuals requiring elevated permissions, including:

  • Employees
  • Contractors
  • Third‑party vendors

It covers privileged access across systems such as servers, cloud platforms, enterprise apps, and network infrastructure.

Back to top

4. Types of Privileged Access

  • Administrator / root accounts
  • Domain or directory admins
  • Database administrators
  • Application administrators
  • Elevated service accounts
  • Emergency (break‑glass) accounts

Back to top

5. Key Policy Requirements

5.1 Requesting Privileged Access

  • Least privilege must be followed
  • Requires System Owner AND CISO approval
  • Provisioned only through IAM workflows

5.2 Authentication Requirements

  • Passwords and MFA follow KU ID 02‑ST

5.3 Session Management

  • Privileged sessions must use PAM tools or jump servers
  • Session recording must be enabled when possible

5.4 Logging & Monitoring

  • All privileged activity must feed into the SIEM
  • Alerts required for unusual activity

5.5 Periodic Reviews

  • Quarterly privileged access reviews required
  • 30‑day inactive privileged accounts must be disabled

5.6 Emergency (Break‑Glass) Access

  • Stored in a secure vault
  • Requires CISO + CIO approval
  • Use must be reviewed within 24 hours

5.7 Removing Privileged Access

  • Removed immediately when employment ends
  • Removed when duties change
  • Vendor access removed when engagement ends

Back to top

6. Staff Responsibilities

Staff with privileged access must:

  • Use elevated access only for authorized work
  • Follow authentication and MFA requirements
  • Use PAM tools and jump servers
  • Report suspicious activity immediately
  • Work with IAM and supervisors when access needs change
  • Ensure vendor elevated access is reviewed and removed as needed

Back to top

7. Key Roles Supporting Privileged Access

CISO

  • Approves privileged access and oversees governance.

IAM Lead

  • Manages provisioning, reviews, and privileged workflows.

System Owners

  • Approve privileged access to their systems.

Security Operations

  • Monitors logs, alerts, and unusual privileged activity.

Internal Audit

  • Verifies compliance with controls.

Back to top

8. Compliance & Regulatory Alignment

  • NIST CSF 2.0 PR.AC
  • FERPA
  • HIPAA
  • GLBA
  • NJ State privileged access requirements

Back to top

9. Exceptions

  • Follow KU SEC 05
  • Must include risk analysis and compensating controls
  • Requires CISO + GRC approval
  • Tracked in the Exception Register
  • Valid for max 12 months

Back to top

10. Enforcement

  • Privileged access removal
  • Disciplinary action (up to termination)
  • Vendor contract termination
  • Legal or regulatory penalties

Back to top

  • RC01 – Policy Standard
  • KU SEC 10 – Governance & Precedence
  • KU ID 01 – Identity & Authentication Policy
  • KU ID 02 – Access Control Policy
  • KU ID 03 – Account Management Policy
  • KU SEC 03 – Incident Response
  • KU ID 02‑ST – Password & Authentication Standard
  • Privileged Access SOP

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.