Kean University DG – Data Access Request & Authorization (SOP) 2


Kean University – Data Access Request & Authorization (SOP)

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines the standardized process for requesting, reviewing, approving, provisioning, modifying, and revoking access to Kean University systems and data.

This SOP operationalizes the requirements of KU DG 02 – Data Access & Privacy Policy and supports governed access controls defined in KU DG 01 – Data Governance & Protection Policy.

Scope

This SOP applies to:

  • All University employees, contractors, and vendors requesting system or data access
  • Managers, Data Owners, Identity & Access Management (IAM), and IT Security teams
  • All systems containing Internal, Confidential, or Restricted data

This SOP covers access requests across on‑premises, cloud, and hybrid environments.

Definitions

  • Access Request – A formal request to obtain access to a system, application, or dataset.
  • Authorization – The approval process required before access is granted.
  • Role‑Based Access Control (RBAC) – Access model that assigns permissions based on job role.
  • Least Privilege – Principle of granting only the minimum access necessary.
  • Privileged Access – Elevated access requiring enhanced security controls.

Roles & Responsibilities

Requestor

  • Submit access requests through the official request system (Freshservice)
  • Provide business justification aligned to job duties

Manager (Supervisor)

  • Validate business need and least‑privilege alignment
  • Approve or deny access requests
  • Notify IAM of role changes or separations immediately

Data Owner

  • Approve access to data assets they govern
  • Ensure access aligns with assigned data classification

Identity & Access Management (IAM)

  • Verify required approvals
  • Provision and revoke access using RBAC

IT Security

  • Review requests involving sensitive or regulated data
  • Ensure multi‑factor authentication (MFA) and logging are enforced

Procedure

Step 1 — Submit Access Request

The requestor submits an access request through Freshservice including system name, requested role, business justification, and duration (if temporary).

Step 2 — Manager Review

The manager validates business need, confirms least‑privilege alignment, and approves or denies the request.

Step 3 — Data Owner Authorization

For systems containing Confidential or Restricted data, the Data Owner reviews and authorizes the request based on data classification requirements.

Step 4 — Security Review

IT Security reviews requests involving regulated data, privileged access, or MFA‑protected systems to ensure policy compliance.

Step 5 — IAM Provisioning

IAM provisions access using approved roles and records provisioning details in audit logs and the Freshservice ticket.

Step 6 — Notification

The requestor and manager are notified when access is granted or denied.

Step 7 — Access Modification

Access is reviewed and adjusted when role changes occur to maintain least privilege.

Step 8 — Access Removal

Access must be revoked immediately upon termination or separation notification.

Step 9 — Access Reviews

Quarterly and semiannual access reviews are conducted in accordance with data classification and policy requirements.


  • KU DG 02 – Data Access & Privacy Policy
  • KU DG 01 – Data Governance & Protection Policy
  • KU ID 01 – Identity & Authentication
  • KU ID 02 – Access Control
  • KU ID 03 – Account Management
  • KU IT 03 – Cybersecurity Training & Awareness

Compliance Mapping

NIST CSF Function Category Subcategory
Protect PR.AC – Access Control PR.AC01, PR.AC02, PR.AC04
Protect PR.AA – Authentication PR.AA02
Detect DE.CM – Monitoring DE.CM01

Metrics & KPIs

  • Percentage of access requests completed within SLA
  • Quarterly access review completion rate
  • Percentage of access removals completed same business day
  • Number of unauthorized access attempts detected

Required Records & Storage

  • Access request tickets (Freshservice)
  • IAM provisioning and deprovisioning logs
  • System audit logs
  • Access review evidence (GRC repository)

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release Identity & Access Management Lead Chief Information Security Officer

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.