KUID SOP 01 - Identity & Authentication SOP


Skip to main content

Kean University Identity & Authentication Standard Operating Procedure (SOP01)

Table of Contents

About

This Standard Operating Procedure (SOP01) defines how Kean University issues identities, enforces authentication, secures credentials, and manages session controls in alignment with the Identity & Authentication Policy (KU ID 01).

Field Value
Version 1.0
Author Identity & Access Management Lead
Approver Chief Information Security Officer
Effective Date February 13, 2026
Review Date February 13, 2027

Back to top

Scope

  • All staff, faculty, students, contractors, and vendors requiring authenticated access
  • All platforms (on-premises, cloud, and hybrid)
  • All identity types: user, service, shared (restricted), and privileged accounts

Back to top

Definitions

  • Identity: A unique digital representation of a user or system
  • Authentication: Verification of identity using credentials
  • Multifactor Authentication (MFA): A login method requiring two or more verification factors
  • Credential: A password, token, certificate, or authenticator used for access

Back to top

Roles & Responsibilities

Role Responsibility
IAM Lead Manage identities and enforce authentication controls
System Owners Validate user eligibility for identity issuance
Security Operations Monitor authentication events and anomalies
Users Safeguard credentials and comply with MFA requirements
Internal Audit Perform identity and authentication audits

Back to top

Procedure Steps

1. Identity Issuance
  • Receive identity request from HR, Registrar, or system owner
  • Verify user type
  • Create identity in the Identity Management System (e.g., Okta)
  • Apply naming conventions
  • Assign baseline role-based access control (RBAC)
  • Log identity issuance

 Flow from:  Request → Identity Creation → MFA Enrollment → Active Use → Deactivation


2. Authentication Enrollment
  • Require MFA enrollment at first login
  • Enforce password standards
  • Perform identity verification for elevated access
  • Document enrollment completion

What to show:  Username + password MFA prompt (push, token, etc.) Access granted/denied

3. Credential Protection
  • Ensure passwords are hashed and salted
  • Prohibit plaintext credential storage
  • Block shared credential usage unless approved
  • Rotate service account credentials every 90 days unless automated
4. Session Management
  • Enforce 15-minute idle session timeout
  • Require reauthentication for sensitive actions
  • Monitor sessions using security tools (SIEM)
5. Identity Deactivation
  • Disable identities upon HR or Registrar notification
  • Remove all access and group memberships
  • Revoke tokens and active sessions
  • Retain logs per retention policy

What to show:  HR/Registrar trigger → Disable account → Revoke sessions → Remove access

Back to top

  • [Insert link: KU ID 01 – Identity & Authentication Policy]
  • KU ID 02ST – Password & Authentication Standard
  • KU SEC 10 – Governance & Precedence

Back to top

Metrics & KPIs

  • MFA enrollment rate (target: 100%)
  • Identity issuance SLA compliance
  • Credential rotation compliance rate
  • Identity deactivation time (target: ≤ 24 hours)

Back to top

Required Records & Storage

  • Identity creation logs
  • Authentication enrollment logs
  • Deactivation logs

Stored in: IAM systems, Security Operations SIEM, and Scrut.io

Back to top

Revision History

Version Date Change Author
1.0 February 13, 2026 Initial SOP IAM Lead

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.