Kean University DG– Role‑Based Access Control (RBAC) Implementation (SOP) 4


Kean University – Role‑Based Access Control (RBAC) Implementation (SOP)

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines the structured, repeatable process for implementing, maintaining, and auditing Role‑Based Access Control (RBAC) across Kean University systems.

RBAC ensures that users receive only the access required for their job functions and that access aligns with data classification, regulatory requirements, and institutional security controls.

Scope

This SOP applies to:

  • All University systems containing Internal, Confidential, or Restricted data
  • All user accounts, including employees, contractors, and vendors
  • Identity & Access Management (IAM), IT Security, Data Owners, and Data Stewards
  • Access provisioning, modification, review, and deprovisioning workflows

RBAC applies to both on‑premises and cloud systems, including enterprise applications and infrastructure platforms.

Definitions

  • Role‑Based Access Control (RBAC) – A permissions model that assigns access based on job function.
  • Role – A defined set of permissions representing a job function.
  • Privilege – A specific action a user may perform (for example, read, write, administer).
  • Privileged Role – A role with elevated permissions requiring additional security controls.
  • Data Owner – Role accountable for approving access to data within their domain.

Roles & Responsibilities

Identity & Access Management (IAM)

  • Create, modify, and retire RBAC roles
  • Ensure roles enforce least privilege
  • Maintain the RBAC Role Catalog

Data Owners

  • Approve roles that provide access to governed data
  • Validate alignment with data classification requirements

Data Stewards

  • Ensure RBAC‑granted access aligns with handling requirements

IT Security

  • Validate MFA, logging, and monitoring for RBAC roles
  • Monitor for role misuse or privilege escalation

Managers

  • Identify appropriate roles for staff
  • Report duty changes requiring role updates

Users

  • Use only access granted through assigned roles
  • Report incorrect or excessive access

Procedure

Step 1 — Identify Job Functions

IAM works with departments to identify job functions and required permissions, validating data classification requirements with Data Owners.

Step 2 — Create RBAC Roles

When a new role is required, IAM defines permissions, Data Owners approve classification impacts, and IT Security validates least privilege, MFA, and logging requirements.

Step 3 — Assign Users to Roles

Managers submit access requests through Freshservice. IAM provisions access using approved RBAC roles and records assignments in audit logs.

Step 4 — Modify Roles

Role changes require impact analysis, Data Owner approval for sensitive data access, and IT Security validation for privileged roles.

Step 5 — Revoke Role Assignments

Role removal occurs upon separation, role change, or access review findings and is documented immediately.

Step 6 — Periodic RBAC Reviews

RBAC roles and assignments are reviewed quarterly for sensitive systems and semiannually for all other systems. Findings are documented in the GRC repository.

Step 7 — Privileged Role Management

Privileged roles require MFA, continuous monitoring, and formal exception approval when deviations are necessary.


  • KU DG 02 – Data Access & Privacy Policy
  • KU DG 01 – Data Governance & Protection Policy
  • KU ID 02 – Access Control
  • KU ID 04 – Privileged Access
  • KU SEC 05 – Exception Management

Compliance Mapping

NIST CSF Function Category Subcategory
Protect PR.AC – Access Control PR.AC01, PR.AC02, PR.AC04
Protect PR.AA – Authentication PR.AA02
Detect DE.CM – Monitoring DE.CM01

Metrics & KPIs

  • Percentage of users assigned to valid RBAC roles
  • Number of privileged roles versus standard roles
  • Access review completion rates
  • Time to deprovision users after separation

Required Records & Storage

  • RBAC Role Catalog (IAM repository)
  • Access request and approval logs (Freshservice)
  • Provisioning and deprovisioning logs
  • Access review evidence (GRC repository)

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release Identity & Access Management Lead Chief Information Security Officer

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.