Kean University Access Control Policy


Kean University Access Control Policy

Table of Contents


About This Policy

Kean University uses access controls to ensure that only the right people — and only those people — can access University systems, applications, and data. This protects confidentiality, integrity, and availability across all environments, including on‑campus, cloud, and hybrid platforms.

Example: Your role may require access to Banner but not HR financial records. Access controls ensure each user only sees what their role requires.

Back to top

Scope

This policy applies to all individuals who use Kean systems, including:

  • Faculty and staff
  • Student workers
  • Contractors and consultants
  • Vendors supporting Kean systems

This includes all systems owned or managed by Kean University.

Back to top

Key Principles

Access to Kean University resources must always be:

  • Authorized — granted only after appropriate approvals.
  • Authenticated — using secure authentication (such as multi-factor authentication).
  • Auditable — logged and subject to review.
  • Revocable — removed immediately when no longer needed.

Example: If a student worker graduates, their shared folder access must be removed immediately.

Back to top

Roles & Responsibilities

IT Security Team

Implements access controls, monitors activity, and investigates anomalies or suspicious behavior.

Managers & Supervisors

Approve access requests and ensure that team members follow this policy.

Compliance Team

Ensures access control practices comply with regulations such as the Family Educational Rights and Privacy Act (FERPA) and the Health Insurance Portability and Accountability Act (HIPAA).

All Users

Follow access rules, protect credentials, and report suspicious activity immediately.

Back to top

Access Control Requirements

5.1 Authorization — Getting Access the Right Way

  • All requests must be submitted through the official access request system.
  • Requests must be approved by the user’s manager and IT Security.

Example: To access a SharePoint site, your manager must approve the request before IT can grant access.

Back to top

5.2 Authentication — Proving Who You Are

  • Multi-factor authentication (MFA) is required for all accounts.
  • Passwords must be at least 12 characters and include uppercase, lowercase, numbers, and symbols.
  • Sessions must automatically time out after 15 minutes of inactivity.

Example: Logging into Microsoft 365 requires both your password and an authenticator app code.

Back to top

5.3 Role-Based Access Control (RBAC)

  • Access is tied to job responsibilities.
  • Privileged accounts (admin, root, etc.) are tightly controlled and monitored.

Example: An advisor may view academic records but cannot access HR salary data.

Back to top

5.4 Least Privilege — Only What You Need

  • Users follow the principle of least privilege and receive only the minimum access needed.
  • Access must be removed or adjusted immediately when duties change.

Example: When moving from Finance to Advising, Finance permissions must be removed right away.

Back to top

5.5 Access Reviews — Keeping Things Current

  • All accounts and permissions must be reviewed quarterly.
  • Access must be removed immediately for terminated or transferred users.

Back to top

5.6 Emergency Access — Break Glass Accounts

  • Emergency access requires approval from IT Security.
  • Emergency access logs must be reviewed within 24 hours.

Example: A database admin may receive temporary emergency access to resolve a critical outage — but all actions must be logged and reviewed.

Back to top

Monitoring & Logging

All access events must be logged in the Security Information and Event Management (SIEM) system. Alerts must be generated for unauthorized access attempts.

Example: If someone repeatedly tries to access a restricted folder, security analysts receive an automatic alert.

Back to top

Enforcement

Failure to comply with this policy may result in:

  • Loss of system access
  • HR disciplinary action
  • Contract penalties for vendors
  • Legal consequences for severe violations

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.