Kean University DG – Least Privilege Enforcement (SOP) 5


Kean University – Least Privilege Enforcement (SOP)

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines how Kean University enforces the principle of Least Privilege, ensuring users are granted only the minimum level of access required to perform their assigned job duties.

This SOP operationalizes least‑privilege requirements established in KU DG 02 – Data Access & Privacy Policy and supports access governance controls defined in KU DG 01 – Data Governance & Protection Policy.

Scope

This SOP applies to:

  • All University accounts, including employees, contractors, student workers, and vendors
  • All systems containing Internal, Confidential, or Restricted data
  • Access provisioning, modification, review, and deprovisioning activities
  • Standard, privileged, service, and application programming interface (API) accounts

Least privilege applies to applications, systems, datasets, and administrative permissions.

Definitions

  • Least Privilege – Granting users only the minimum access required to perform job duties.
  • Access Scope – The set of resources and permissions available to a user.
  • Privileged Access – Elevated permissions requiring enhanced controls and monitoring.
  • Segregation of Duties (SoD) – Controls preventing a single user from holding excessive or conflicting permissions.

Roles & Responsibilities

Managers

  • Validate that requested access aligns with job duties
  • Notify Identity & Access Management (IAM) promptly of role or responsibility changes

Data Owners

  • Approve access to Confidential or Restricted data
  • Ensure access aligns with data classification requirements

Identity & Access Management (IAM)

  • Enforce least‑privilege access during provisioning
  • Map access to approved role‑based access control (RBAC) roles
  • Validate required approvals before granting access

IT Security

  • Monitor for excessive permissions or privilege escalation
  • Investigate suspicious access activity

Users

  • Use access only for authorized job responsibilities
  • Report access that appears excessive or unnecessary

Procedure

  1. Access Request Intake
  2. Role & Permission Validation
  3. Access Provisioning
  4. Privileged Access Restrictions
  5. Access Modification
  6. Access Removal
  7. Periodic Least Privilege Reviews

  • KU DG 02 – Data Access & Privacy Policy
  • KU DG 01 – Data Governance & Protection Policy
  • KU DG SOP 04 – Role‑Based Access Control (RBAC) Implementation
  • KU ID 02 – Access Control
  • KU ID 04 – Privileged Access
  • KU SEC 05 – Exception Management

Compliance Mapping

NIST CSF Function Category Subcategory
Protect PR.AC – Access Control PR.AC‑02, PR.AC‑04, PR.AC‑05
Protect PR.AA – Authentication PR.AA‑02
Detect DE.CM – Monitoring DE.CM‑01

Metrics & KPIs

  • Percentage of users with access aligned to current job roles
  • Number of privileged accounts versus standard accounts
  • Access review completion rates
  • Time to revoke access after role change or separation
  • Number of approved access exceptions

Required Records & Storage

  • Access request records (Freshservice)
  • IAM provisioning and deprovisioning logs
  • RBAC role catalog
  • Access review evidence (Governance, Risk, and Compliance repository)
  • Exception approvals (Governance, Risk, and Compliance repository)

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release Identity & Access Management Lead Chief Information Security Officer

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.