KU SEC 03 - Incident Response Policy


Incident Response Policy

Table of Contents

1. Overview

Kean University follows a structured process to detect, contain, eradicate, and recover from cybersecurity incidents. This supports protection of university systems, personal data, and campus operations while ensuring compliance with relevant laws and regulations.

2. What Is Considered a Cybersecurity Incident?

A cybersecurity incident is any event that harms or could harm the confidentiality, integrity, or availability of Kean University data or systems. Examples include:

  • Unauthorized access to a Kean account or system
  • Malware, ransomware, or suspicious programs
  • Phishing emails or suspicious link activity
  • Denial‑of‑service attacks
  • Loss or theft of a university‑issued device
  • Attempts to steal or exfiltrate university data

3. Who Must Follow This Policy?

This policy applies to all members of the Kean University community who use university technology resources, including:

  • Students, faculty, and staff
  • IT and Security Operations teams
  • MDR partners (CrowdStrike Falcon)
  • Third‑party IT service providers
  • Research support staff and research computing users

4. What To Do If You Suspect an Incident

If something feels suspicious, report it immediately. Contact the Kean IT Service Desk or Security Operations if you notice:

  • Strange pop‑ups or unknown programs
  • Phishing emails or suspicious links
  • Unexpected account behavior
  • A lost or stolen device
  • Anything that feels unusual or not normal

Early reporting reduces impact and helps prevent further damage.

5. Incident Response Lifecycle

Expand Incident Response Lifecycle

5.1 Identification

Kean uses security monitoring tools and alerts along with user reports to detect potential incidents.

5.2 Containment

To limit impact, IT may isolate affected systems, block malicious traffic, disable compromised accounts, or use endpoint isolation tools.

5.3 Eradication

Security teams remove threats such as malware, backdoors, or unauthorized access and address root causes.

5.4 Recovery

Systems are restored from clean backups, tested, and safely returned to service.

5.5 Post‑Incident Review

Major incidents undergo review within two business days to capture lessons learned and improve processes.

6. Incident Severity Levels

Incidents are classified using a SEV1–SEV4 scale. Higher severity incidents require faster response, broader coordination, and dedicated resources. Detailed definitions appear in Appendix B of the full policy.

7. Communication & Notifications

  • Legal and Compliance teams determine whether regulatory notification is required.
  • Only authorized staff may communicate publicly about an incident.
  • The Communications Office manages all internal and external announcements.

8. Responsibilities

Expand Responsibilities

Everyone at Kean

  • Report suspicious activity immediately
  • Follow cybersecurity and acceptable‑use policies
  • Protect Kean credentials and devices

Kean IT & Security Operations

  • Manage all phases of incident response
  • Coordinate with MDR partners
  • Document incidents in the Incident Management System
  • Support departments during system restoration

Legal, Compliance, Research & Communications

  • Support regulatory and legal requirements
  • Ensure institutionally appropriate communication
  • Assist with research‑specific incident handling

9. Records & Documentation

All incidents must be logged in Kean’s Incident Management System and retained for at least three years.

10. Enforcement

Failure to comply with this policy may result in disciplinary action, loss of access, vendor contract actions, or legal penalties.

11. Exceptions

Exceptions must follow the KU SEC 05 Exception Management Policy, include risk analysis, receive approval from the CISO and GRC, and be limited to 12 months.

  • RC01 – Policy Standard
  • KU SEC 10 – Governance & Precedence
  • KU SEC 09 – Breach Notification Policy
  • Data Classification & Handling Policy (KU DG 01)
  • KU IT 03 – Cybersecurity Training & Awareness
  • KU BC 01 – Business Continuity

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.