Endpoint Security Policy
Table of Contents
- 1. Overview
- 2. What Devices Are Covered?
- 3. Who Must Follow This Policy?
- 4. Key Requirements for All Endpoints
- 5. Responsibilities
- 6. Enforcement
- 7. Exceptions
- 8. Related Policies
1. Overview
Kean University requires all devices (endpoints) that access Kean systems or data to meet minimum security standards. These safeguards protect the university from cyber threats and support compliance with FERPA, GLBA, HIPAA, New Jersey breach laws, NIST CSF 2.0, and ISO 27001 controls.
2. What Devices Are Covered?
This policy applies to any device used to access Kean systems or university data, including:
- Laptops and desktops
- Tablets and mobile phones
- Servers (physical or virtual)
- Lab devices, kiosks, and specialty systems (where feasible)
- Personal devices (BYOD) used for Kean work
3. Who Must Follow This Policy?
This Policy applies to anyone accessing Kean systems or Institutional Data, including:
- Students, faculty, staff, and student employees
- Contractors, consultants, and volunteers
- Vendors and third‑party service providers
- All identity types: regular, privileged, shared, service, automation, and API identities
4. Key Requirements for All Endpoints
Expand Key Requirements
4.1 Device Security & Configuration
- Devices must use Kean‑approved security settings.
- Local administrator rights are restricted to Kean IT.
- Default passwords and unnecessary services must be disabled.
4.2 Authentication & Password Protection
- MFA is required where supported.
- Passwords must be at least 12 characters and follow complexity rules.
- Devices must auto‑lock after 15 minutes of inactivity.
- Accounts must lock after five failed login attempts.
4.3 Patching & Vulnerability Management
- Critical patches must be installed within 14 days.
- Kean IT reviews patch compliance monthly.
- Security vulnerabilities must be remediated according to Kean timelines.
4.4 Antimalware & EDR Protections
- All endpoints must run Kean‑approved antivirus and EDR tools.
- Real‑time protection must be enabled.
- Security tools must update continuously or daily.
- Alerts are monitored by the Kean IT Security Team.
4.5 Encryption & Data Protection
- Full‑disk encryption is required on Kean‑owned devices.
- Restricted or regulated data must not be stored locally unless approved.
- Data in transit and at rest must be encrypted.
4.6 Logging & Monitoring
- Device security logs must be sent to Kean’s SIEM or EDR tools.
- Logs must be retained for at least 12 months.
- Kean IT conducts monthly reviews.
4.7 Incident Reporting
- All incidents must follow the Incident Response Policy.
- Suspected device compromise must be reported within 1 hour.
- Incidents involving regulated data must follow breach notification rules.
4.8 BYOD & Vendor Devices
- Personal devices must meet Kean’s minimum security standards.
- Some devices may require mobile device management enrollment.
- Vendors must comply with contract‑defined security controls.
- Non‑compliant devices may be blocked from Kean systems.
5. Responsibilities
Expand Responsibilities
Everyone at Kean
- Keep devices updated and secure.
- Protect login credentials.
- Report suspicious activity immediately.
Kean IT
- Maintain device inventory and security configurations.
- Enforce endpoint security requirements.
- Perform patching, encryption, and compliance checks.
Kean IT Security Team
- Manage EDR tools and alerts.
- Perform threat monitoring and investigation.
- Support incident response efforts.
Departments
- Identify devices essential to their operations.
Vendors
- Meet contract‑defined security controls and requirements.
6. Enforcement
Non‑compliant devices may have access to Kean systems limited or removed. HR, Student Conduct, or vendor‑related corrective actions may apply. Regulated data incidents follow university breach notification rules.
7. Exceptions
Exceptions must follow the Exception Management Policy, include risk analysis and compensating controls, be approved by Kean IT Security and leadership, be limited to 12 months, and must be logged in the exception register.
8. Related Policies
- RC01 – Regulatory Compliance Policy
- KU SEC 10 – Policy Precedence & Governance
- Incident Response Policy (IRP)
- Breach Notification Policy
- Change Management Policy
- Asset Management Policy
- Exception Management Policy
- Supplier Risk Management Policy