Kean University Cybersecurity Training & Awareness Operations


Kean University Cybersecurity Training & Awareness Operations

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) defines how Kean University operationalizes mandatory cybersecurity training and awareness requirements under KU IT 03 – Cybersecurity Training & Awareness. It ensures that all users understand their responsibilities for protecting University information systems and data.

Cybersecurity refers to the practice of protecting systems, networks, and data from digital attacks.

Back to top

Scope

This SOP applies to all users with access to Kean University systems, including employees, faculty, students, contractors, and affiliates.

Back to top

Roles & Responsibilities

  • Information Security Office (ISO): Develops training content, manages reporting, and conducts phishing simulations.
  • Human Resources (HR): Integrates cybersecurity training into onboarding and offboarding processes.
  • Managers: Enforce training compliance within their teams.
  • Users: Complete required training and assessments on time.

Back to top

Operational Procedures

View cybersecurity training procedures

1. Annual Training

All users must complete mandatory cybersecurity awareness training each year. Training topics include:

  • Phishing awareness
  • Data handling and protection
  • Incident identification and reporting

2. Assessment & Remediation

Users must complete a post-training assessment. Failure to pass requires remediation training, which must be completed within 30 days.

3. High-Risk Users

Users identified as high risk must complete advanced cybersecurity training twice per year and participate in mandatory phishing simulations.

4. Incident-Triggered Training

Users involved in a cybersecurity incident must complete targeted training within 15 days of the incident.

5. Reporting

The Information Security Office generates quarterly reports, and training metrics are integrated into the University’s risk dashboard.

Back to top

NIST CSF 2.0 Mapping

This SOP aligns with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) version 2.0, supporting the following functions:

  • Protect: PR.AT (Awareness and Training)
  • Detect: DE.CM (Continuous Monitoring)
  • Respond: RS.CO (Communications)
  • Govern: GV.RR (Roles, Responsibilities, and Authorities)

Back to top

Metrics & KPIs

View training metrics and key performance indicators
  • Training completion rate
  • Phishing simulation failure rate
  • Remediation completion time

Back to top

Records & Storage

  • Training records: Stored in the Learning Management System (LMS).
  • Reports: Stored in the University risk management platform (e.g., [Scrut.io – link to be provided]).

Back to top

Document Control

  • Version: 1.0
  • Author: Information Security Office
  • Approver: Chief Information Security Officer (CISO)
  • Effective Date: February 13, 2026
  • Review Cycle: Annual

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.