Kean University Privileged Access Management (PAM) Policy
Table of Contents
About This Policy
Kean University uses privileged access controls to protect sensitive systems, critical infrastructure, and high-impact data. Privileged accounts have elevated capabilities — such as installing software, modifying configurations, accessing restricted data, and managing security tools. Because these accounts pose high risk if misused or compromised, they require enhanced protections.
Example: A database administrator (DBA) can view or update thousands of records. If their account is compromised, attackers could steal or corrupt large volumes of data instantly.
Scope
This policy applies to all individuals with privileged or administrative access, including:
- Employees with elevated or administrative permissions
- IT administrators
- System owners
- Contractors and vendors managing Kean systems
This policy covers all platforms, including servers, applications, databases, networks, and cloud services.
Core Principles
Kean University’s approach to privileged access is based on four essential principles:
- Authorized only: Privileged access is granted strictly based on legitimate business needs.
- Secured tightly: Privileged accounts require strong authentication and secure session controls.
- Monitored closely: Admin actions are logged, reviewed, and monitored for suspicious behavior.
- Revoked quickly: Access must be removed immediately when no longer necessary.
Example: When a system engineer transfers into a non-technical position, their elevated access must be removed the same day.
Detailed Policy Requirements
4.1 Access Control — Least Privilege Always
- Privileged access must follow the principle of least privilege — users receive only the minimum permissions required.
- All privileged access must be approved by both:
- The system owner
- The Information Security Office (ISO)
Example: A contractor hired for one project should not receive full domain admin access — only the specific rights required for the defined assignment.
4.2 Authentication — Strong Access Protection
- Multi-factor authentication (MFA) is required for every privileged account — without exception.
- Privileged account passwords must follow Kean’s Password Policy.
Example: Logging in as a server administrator requires both a password and an MFA token or authenticator app approval.
4.3 Session Management — Secure Admin Sessions
All privileged sessions must:
- Be accessed through approved Privileged Access Management (PAM) tools or secure jump servers
- Record all administrative actions
Example: When working on production servers, administrators must use the approved jump server, not connect directly from a personal workstation.
4.4 Logging & Monitoring — Every Action Leaves a Trail
- All privileged activity must be logged into the Security Information and Event Management (SIEM) system.
- Alerts must be generated for:
- Unauthorized privilege escalation
- Abnormal administrator behavior
Example: If an administrator attempts to change hundreds of file permissions at midnight, the SIEM system alerts security analysts automatically.
4.5 Periodic Review — Quarterly Check-ups
- ISO must conduct quarterly reviews of all privileged accounts.
- Privileged accounts unused for 30 days must be disabled.
Example: A developer’s admin account is disabled if unused for 30 days, reducing unneeded attack surface.
4.6 Emergency Access — Break Glass Procedures
Emergency privileged access is allowed only when:
- Credentials are stored in a secure vault
- ISO and the Chief Information Officer (CIO) approve the request
- A post-event review is completed within 24 hours
Example: During a critical outage, a break-glass account may be used — but ISO must review all actions performed.
4.7 Deprovisioning — Remove Rights Immediately
Privileged access must be revoked:
- Immediately upon termination
- Immediately upon role change
- Immediately when a contract ends
Example: When an administrator leaves the University, all privileged access must be disabled before their final day.
``