Incident Response Policy
Table of Contents
- 1. Overview
- 2. What Is Considered a Cybersecurity Incident?
- 3. Who Must Follow This Policy?
- 4. What To Do If You Suspect an Incident
- 5. Incident Response Lifecycle
- 6. Incident Severity Levels
- 7. Communication & Notifications
- 8. Responsibilities
- 9. Records & Documentation
- 10. Enforcement
- 11. Exceptions
- 12. Related Policies
1. Overview
Kean University follows a structured process to detect, contain, eradicate, and recover from cybersecurity incidents. This supports protection of university systems, personal data, and campus operations while ensuring compliance with relevant laws and regulations.
2. What Is Considered a Cybersecurity Incident?
A cybersecurity incident is any event that harms or could harm the confidentiality, integrity, or availability of Kean University data or systems. Examples include:
- Unauthorized access to a Kean account or system
- Malware, ransomware, or suspicious programs
- Phishing emails or suspicious link activity
- Denial‑of‑service attacks
- Loss or theft of a university‑issued device
- Attempts to steal or exfiltrate university data
3. Who Must Follow This Policy?
This policy applies to all members of the Kean University community who use university technology resources, including:
- Students, faculty, and staff
- IT and Security Operations teams
- MDR partners (CrowdStrike Falcon)
- Third‑party IT service providers
- Research support staff and research computing users
4. What To Do If You Suspect an Incident
If something feels suspicious, report it immediately. Contact the Kean IT Service Desk or Security Operations if you notice:
- Strange pop‑ups or unknown programs
- Phishing emails or suspicious links
- Unexpected account behavior
- A lost or stolen device
- Anything that feels unusual or not normal
Early reporting reduces impact and helps prevent further damage.
5. Incident Response Lifecycle
Expand Incident Response Lifecycle
5.1 Identification
Kean uses security monitoring tools and alerts along with user reports to detect potential incidents.
5.2 Containment
To limit impact, IT may isolate affected systems, block malicious traffic, disable compromised accounts, or use endpoint isolation tools.
5.3 Eradication
Security teams remove threats such as malware, backdoors, or unauthorized access and address root causes.
5.4 Recovery
Systems are restored from clean backups, tested, and safely returned to service.
5.5 Post‑Incident Review
Major incidents undergo review within two business days to capture lessons learned and improve processes.
6. Incident Severity Levels
Incidents are classified using a SEV1–SEV4 scale. Higher severity incidents require faster response, broader coordination, and dedicated resources. Detailed definitions appear in Appendix B of the full policy.
7. Communication & Notifications
- Legal and Compliance teams determine whether regulatory notification is required.
- Only authorized staff may communicate publicly about an incident.
- The Communications Office manages all internal and external announcements.
8. Responsibilities
Expand Responsibilities
Everyone at Kean
- Report suspicious activity immediately
- Follow cybersecurity and acceptable‑use policies
- Protect Kean credentials and devices
Kean IT & Security Operations
- Manage all phases of incident response
- Coordinate with MDR partners
- Document incidents in the Incident Management System
- Support departments during system restoration
Legal, Compliance, Research & Communications
- Support regulatory and legal requirements
- Ensure institutionally appropriate communication
- Assist with research‑specific incident handling
9. Records & Documentation
All incidents must be logged in Kean’s Incident Management System and retained for at least three years.
10. Enforcement
Failure to comply with this policy may result in disciplinary action, loss of access, vendor contract actions, or legal penalties.
11. Exceptions
Exceptions must follow the KU SEC 05 Exception Management Policy, include risk analysis, receive approval from the CISO and GRC, and be limited to 12 months.
12. Related Policies
- RC01 – Policy Standard
- KU SEC 10 – Governance & Precedence
- KU SEC 09 – Breach Notification Policy
- Data Classification & Handling Policy (KU DG 01)
- KU IT 03 – Cybersecurity Training & Awareness
- KU BC 01 – Business Continuity