Kean University Cybersecurity Training & Awareness Policy


Kean University Cybersecurity Training & Awareness Policy

Table of Contents

About This Policy

Kean University is committed to protecting the campus community from cyberattacks, which increasingly target higher education institutions. This policy describes the cybersecurity training and awareness activities required to help prevent threats and safeguard University systems, information, and users.

Back to top

Scope

This policy applies to all individuals who access Kean University systems, including:

  • Students
  • Faculty
  • Staff
  • Contractors
  • Third-party users with system or data access

Back to top

Training Requirements

Annual Cybersecurity Training (Required for Everyone)

All users must complete online cybersecurity training once per year. Topics include:

  • Phishing and suspicious email recognition
  • Password safety and credential protection
  • Data protection principles
  • Social engineering risks
  • How to report cybersecurity incidents

Training is updated annually to address emerging threats.

Assessments and Remediation
  • If you pass the assessment: requirements for the year are complete.
  • If you fail: you must complete extra training within 30 days.
  • If you fail twice in one year: your supervisor and the IT Security team are notified and system access may be temporarily restricted.

Users involved in a cybersecurity incident must complete post‑incident training within 15 days.

High-Risk Users

High-risk users include:

  • Information Technology staff with administrative access
  • Employees handling regulated data such as the Family Educational Rights and Privacy Act (FERPA), Gramm-Leach-Bliley Act (GLBA), or research data subject to National Institute of Standards and Technology (NIST) controls
  • Users with repeated training failures or phishing test failures
  • Staff in high-exposure departments (Admissions, Financial Aid, Research, Executive Offices)

Additional Requirements for High-Risk Users

  • Training twice per year
  • More frequent phishing simulations
  • Role‑specific training modules
  • Annual review to confirm retention in the high‑risk category

A cross‑departmental team (IT Security, Human Resources, Academic Affairs) maintains the high‑risk user list.

Role‑Based Training

Certain groups receive specialized training:

  • Information Technology staff: privileged access, insider threat prevention, incident response
  • Human Resources and Finance: privacy, data handling, GLBA compliance
  • Faculty and researchers: FERPA and research data protection standards
  • Executives: spear phishing and strategic cybersecurity awareness
  • General staff: email safety and core cyber hygiene practices
Training for New and Departing Users
  • New users: required to complete cybersecurity training within 30 days of account activation.
  • Departing users: receive a reminder of data handling expectations and access termination obligations.

Back to top

Real-Time Risk-Based Training

Kean University uses security monitoring tools to detect risky behavior, such as clicking on phishing links or unusual login activity. When high‑risk actions occur, users may automatically be assigned additional training modules.

Back to top

Awareness Campaigns

The University conducts quarterly cybersecurity awareness campaigns focusing on new threats, best practices, and updates to security tools or policies.

Back to top

Responsibilities

IT Security Team

  • Creates and maintains cybersecurity training content
  • Administers assessments and phishing simulations
  • Tracks training completion and performance metrics

Managers

  • Ensure team members complete training on time

All Users

  • Complete assigned training modules
  • Follow University cybersecurity guidelines
  • Report suspicious activity or security concerns promptly

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.