Kean University Cybersecurity Training & Awareness Policy
Table of Contents
- About This Policy
- Scope
- Training Requirements
- Real-Time Risk-Based Training
- Awareness Campaigns
- Responsibilities
About This Policy
Kean University is committed to protecting the campus community from cyberattacks, which increasingly target higher education institutions. This policy describes the cybersecurity training and awareness activities required to help prevent threats and safeguard University systems, information, and users.
Scope
This policy applies to all individuals who access Kean University systems, including:
- Students
- Faculty
- Staff
- Contractors
- Third-party users with system or data access
Training Requirements
Annual Cybersecurity Training (Required for Everyone)
All users must complete online cybersecurity training once per year. Topics include:
- Phishing and suspicious email recognition
- Password safety and credential protection
- Data protection principles
- Social engineering risks
- How to report cybersecurity incidents
Training is updated annually to address emerging threats.
Assessments and Remediation
- If you pass the assessment: requirements for the year are complete.
- If you fail: you must complete extra training within 30 days.
- If you fail twice in one year: your supervisor and the IT Security team are notified and system access may be temporarily restricted.
Users involved in a cybersecurity incident must complete post‑incident training within 15 days.
High-Risk Users
High-risk users include:
- Information Technology staff with administrative access
- Employees handling regulated data such as the Family Educational Rights and Privacy Act (FERPA), Gramm-Leach-Bliley Act (GLBA), or research data subject to National Institute of Standards and Technology (NIST) controls
- Users with repeated training failures or phishing test failures
- Staff in high-exposure departments (Admissions, Financial Aid, Research, Executive Offices)
Additional Requirements for High-Risk Users
- Training twice per year
- More frequent phishing simulations
- Role‑specific training modules
- Annual review to confirm retention in the high‑risk category
A cross‑departmental team (IT Security, Human Resources, Academic Affairs) maintains the high‑risk user list.
Role‑Based Training
Certain groups receive specialized training:
- Information Technology staff: privileged access, insider threat prevention, incident response
- Human Resources and Finance: privacy, data handling, GLBA compliance
- Faculty and researchers: FERPA and research data protection standards
- Executives: spear phishing and strategic cybersecurity awareness
- General staff: email safety and core cyber hygiene practices
Training for New and Departing Users
- New users: required to complete cybersecurity training within 30 days of account activation.
- Departing users: receive a reminder of data handling expectations and access termination obligations.
Real-Time Risk-Based Training
Kean University uses security monitoring tools to detect risky behavior, such as clicking on phishing links or unusual login activity. When high‑risk actions occur, users may automatically be assigned additional training modules.
Awareness Campaigns
The University conducts quarterly cybersecurity awareness campaigns focusing on new threats, best practices, and updates to security tools or policies.
Responsibilities
IT Security Team
- Creates and maintains cybersecurity training content
- Administers assessments and phishing simulations
- Tracks training completion and performance metrics
Managers
- Ensure team members complete training on time
All Users
- Complete assigned training modules
- Follow University cybersecurity guidelines
- Report suspicious activity or security concerns promptly