KU SEC 01 - Information Security Policy


Kean University SEC 01 – Information Security Policy

Table of Contents


1. Overview

Kean University maintains an Information Security Program to protect Institutional Data and University technology resources. This policy defines the requirements staff must follow to safeguard information, systems, and digital services.

Back to top

2. Purpose

The purpose of this policy is to establish clear expectations and security requirements for Institutional Data and University systems. It ensures consistency across the University and aligns with industry standards and regulations.

Back to top

3. Scope

This policy applies to:

  • All staff, faculty, administrators, student workers, contractors, consultants, and vendors
  • All systems, devices, networks, applications, and cloud services used for University business
  • All classifications of Institutional Data
  • All access methods including on-campus, remote, mobile, or automated

Back to top

4. Security Principles

4.1 Govern
  • Follow all University security policies and standards.
  • Ensure compliance with legal, regulatory, and contractual obligations.
  • Use only University-approved technologies for official business.
4.2 Identify
  • Understand the sensitivity of the data you handle.
  • Apply University classification rules for Public, Internal, Confidential, and Restricted data.
  • Use only approved systems for storing or transmitting data.
4.3 Protect
  • Use multi-factor authentication (MFA) where required.
  • Protect Institutional Data using encryption, secure storage, and proper access controls.
  • Install only approved software and keep systems updated.
4.4 Detect
  • Remain alert for phishing attempts or unusual system behavior.
  • Report suspicious activity immediately.
4.5 Respond
  • Report cybersecurity incidents promptly.
  • Preserve evidence and follow Information Security Office instructions.
4.6 Recover
  • Assist in system or data restoration as needed.
  • Support post‑incident validation activities.

Back to top

5. Roles and Responsibilities

5.1 Staff Members
  • Protect Institutional Data in all formats.
  • Use only approved systems and applications.
  • Complete required cybersecurity training.
  • Report security concerns immediately.
5.2 Information Security Office (ISO)
  • Manage the Information Security Program.
  • Monitor for threats and suspicious activity.
  • Lead incident response processes.
  • Perform security risk assessments.
5.3 Data Owners
  • Classify data based on sensitivity.
  • Approve access to sensitive data.
  • Ensure appropriate business and security controls.
5.4 System Owners
  • Apply patches and maintain secure configurations.
  • Ensure logging and monitoring remain active.
  • Maintain compliance with security requirements.
5.5 Legal and Privacy
  • Provide guidance on regulatory obligations.
  • Support incident response processes.
5.6 Internal Audit
  • Perform independent control assessments.
  • Verify compliance with University policy.

Back to top

6. Security Requirements for Staff

6.1 Identity and Access Management
  • Use multi‑factor authentication (MFA) where required.
  • Protect authentication devices and credentials.
  • Use only assigned University accounts.
  • Request timely removal of access when no longer needed.
6.2 Data Protection

Classification

  • Public
  • Internal
  • Confidential
  • Restricted

Storage

  • Use only University‑approved storage platforms.
  • No personal devices or cloud accounts for Institutional Data.

Encryption

  • Sensitive and Restricted data encrypted at rest.
  • All sensitive data encrypted in transit.

Data Loss Prevention

Do not bypass monitoring or data‑loss prevention controls.

6.3 Data Integrity

The University uses integrity controls such as checksums, tamper‑evident logs, validated backups, and file integrity monitoring. Staff must report corrupted or suspicious data.

6.4 Device and System Security
  • Keep devices updated.
  • Install only approved software.
  • Report lost or stolen devices immediately.
  • Do not store Restricted data on personal devices.
6.5 Secure Development and Change Management
  • Use secure development practices.
  • Conduct code reviews and use version control.
  • Follow approved change management procedures.
6.6 Monitoring and Logging

Do not alter, disable, or interfere with monitoring or logging tools.

6.7 Incident Response

Report immediately:

  • Suspicious emails
  • Unauthorized access attempts
  • Malware or unusual activity
  • Corrupted, missing, or exposed data
  • Lost or stolen devices

Do not delete or modify evidence.

6.8 Artificial Intelligence (AI) and Digital Tools

Approved: Microsoft 365 Copilot, KeanU AI

Not approved: Public AI tools unless formally reviewed

No sensitive data may be entered into unapproved tools.

Review all AI-generated content before use.

6.9 Training and Awareness
  • Annual cybersecurity training
  • Phishing simulations
  • Role-based security training

Back to top

7. Exceptions

Exception requests must include a justification, risk assessment, compensating controls, and a defined time limit. All exceptions must go through the formal review process.

Back to top

8. Enforcement

Non‑compliance may result in removal of access, HR disciplinary action, vendor consequences, or regulatory reporting obligations. Severe or repeated violations may trigger additional administrative or legal action.

Back to top

9. Document Control

This policy is maintained by the Information Security Office and reviewed annually or as required based on technology, regulatory, or risk changes.

Back to top

``


Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.