Kean University DG – Logging, Monitoring & Alerting (SOP) 12


Kean University DG – Logging, Monitoring & Alerting (SOP)

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines how Kean University performs logging, continuous monitoring, and alerting to detect unauthorized access, suspicious activity, and data misuse.

This SOP operationalizes monitoring and alerting requirements defined in KU DG 02 – Data Access & Privacy Policy and continuous monitoring expectations in KU DG 01 – Data Governance & Protection Policy.

Scope

  • All University systems storing Internal, Confidential, or Restricted data
  • Cloud, on‑premises, and hybrid environments
  • All user, service, privileged, and vendor accounts
  • Authentication, access, data movement, and configuration events

This SOP covers log generation, SIEM integration, alerting thresholds, monitoring cadence, escalation, and reporting.

Definitions

  • Logging – Recording system and security events for audit and monitoring.
  • Monitoring – Continuous review of logs to detect anomalies or violations.
  • Alerting – Automated notifications triggered by suspicious activity.
  • SIEM – Security Information and Event Management system.
  • Unauthorized Access Attempt – Any access attempt without proper authorization.

Roles & Responsibilities

IT Security

  • Configure and monitor SIEM
  • Define alert thresholds and detection rules
  • Investigate high‑severity alerts and escalate incidents

Identity & Access Management (IAM)

  • Ensure authentication and access logs feed into SIEM
  • Identify privileged accounts requiring enhanced monitoring

IT Custodians

  • Enable logging on systems and applications
  • Ensure secure log transmission and retention

Data Owners

  • Identify systems or datasets requiring enhanced monitoring

Users

  • Report unusual access alerts or suspicious activity

Procedure

Step 1 — Configure Logging

Ensure systems log authentication events, access to sensitive data, privileged activity, data exports, and configuration changes.

Step 2 — Centralize Logs

Forward all critical logs securely to the University SIEM with timestamps, user identifiers, event type, and outcome.

Step 3 — Define Alerting Rules

Configure alerts for unauthorized access attempts, failed MFA, abnormal access patterns, and sensitive data movement.

Step 4 — Daily & Weekly Monitoring

Review high‑severity alerts daily and conduct weekly trend and privileged‑access reviews.

Step 5 — Escalation & Incident Handling

Escalate confirmed threats according to Incident Response procedures and notify Data Owners when sensitive data may be impacted.

Step 6 — Log Retention & Protection

Retain security logs according to retention requirements and protect them using encryption and restricted access.

Step 7 — Reporting & Review

Produce monthly security reports, quarterly compliance summaries, and review detection rules at least quarterly.

  • KU DG 02 – Data Access & Privacy Policy
  • KU DG 01 – Data Governance & Protection Policy
  • KU DG SOP 09 – Data Access Review
  • KU SEC 03 – Incident Response
  • KU ID 01 – Identity & Authentication
  • KU IT 03 – Cybersecurity Training & Awareness

Compliance Mapping

NIST CSF Function Category Subcategory
Detect DE.CM – Continuous Monitoring DE.CM01, DE.CM03
Respond RS.AN – Analysis RS.AN01
Recover RC.IM – Improvements RC.IM01

Metrics & KPIs

  • Number of unauthorized access attempts detected
  • Mean time to detect (MTTD) security events
  • Percentage of systems reporting logs to SIEM
  • Percentage of high‑severity alerts investigated within SLA

Required Records & Storage

  • SIEM log archives
  • Alert investigation records
  • Incident response tickets
  • Monitoring and compliance reports

Revision History

Version Date Description Author (Role) Approver (Role)
1.0 February 13, 2026 Initial release IT Security Operations Lead Chief Information Security Officer

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.