Logging & Monitoring Policy (Simplified)
Table of Contents
- 1. Overview
- 2. Who Must Follow This Policy?
- 3. Systems & Data Covered
- 4. Key Logging Requirements
- 5. Roles & Responsibilities
- 6. Enforcement
- 7. Exceptions
- 8. Related Policies
1. Overview
The Logging & Monitoring Policy ensures Kean University systems generate logs that support threat detection, investigations, and regulatory compliance. Logging helps Kean:
- Identify and respond to cybersecurity incidents
- Maintain audit trails
- Detect unusual or unauthorized activity
- Meet FERPA, GLBA, HIPAA, and NIST CSF 2.0 standards
2. Who Must Follow This Policy?
This policy applies to individuals involved in system use, administration, or monitoring, including:
- Faculty, staff, and students
- Kean IT – Information Security
- IT Operations, system administrators, network and cloud administrators
- Third‑party vendors handling Kean data or systems
3. Systems & Data Covered
Systems
All Kean systems must follow this policy, including:
- Servers, endpoints, and network devices
- Cloud platforms and SaaS services
- Academic, research, and administrative systems
Data Types
Logging applies to all university data classifications:
- Public
- Internal
- Confidential
- Restricted
When Logging Applies
Logging is required throughout the system lifecycle:
- Development
- Deployment
- Maintenance
- Decommissioning
4. Key Logging Requirements
Expand Key Logging Requirements
4.1 Log Generation
Systems must generate logs for key activities, including:
- Logins and authentication attempts
- Access to sensitive or restricted data
- Configuration or permission changes
- System and application errors
Logs must include: timestamp, source IP, user ID, event type, and outcome.
4.2 Centralized Log Collection
- Logs must be sent securely to Kean’s centralized SIEM platform.
- Cloud and vendor systems must integrate with centralized logging.
- Log collection must support redundancy and failover.
4.3 Continuous Monitoring
Monitoring must identify:
- Unauthorized access
- Anomalous or unusual activity
- Threats or suspicious behavior
Monitoring includes:
- Network traffic
- Endpoint events
- User behavior
- Cloud activity
Alerts must be routed to designated security personnel.
4.4 Retention & Protection
- Audit logs must be stored for required retention periods.
- Logs must be protected from unauthorized access or tampering.
- Archived logs must remain accessible for investigations.
4.5 Support for Incident Response
Logs must support every phase of incident response:
- Detection
- Containment
- Eradication
- Recovery
4.6 Governance & Review
- Logging processes must be reviewed annually or after major changes.
- Personnel must complete annual training on logging and monitoring.
- Logging practices must meet applicable accessibility standards.
4.7 Risk‑Based Logging Levels
Tier 1 (High Risk) – Restricted or Confidential Data
- Full logging
- Real‑time monitoring
- Minimum 1‑year log retention
Tier 2 (Moderate Risk) – Academic/Admin Systems
- Standard logging
- Daily review
- 6‑month log retention
Tier 3 (Low Risk) – Public‑Facing Systems
- Basic logging
- Weekly review
- 3‑month log retention
5. Roles & Responsibilities
Expand Roles & Responsibilities
Information Security (CISO Office)
- Maintain the university logging and monitoring strategy.
- Coordinate audits and oversee monitoring capabilities.
IT Operations & Infrastructure
- Maintain logging tools and collectors.
- Ensure systems generate and forward logs correctly.
- Patch and maintain logging infrastructure.
System & Application Administrators
- Configure and maintain application logging.
- Respond to log‑related alerts.
Network & Cloud Administrators
- Forward logs securely to centralized logging.
- Monitor network and cloud activity.
Internal Audit & Compliance
- Audit logging processes and retention practices.
Executive Leadership
- Review logging and monitoring reports.
- Support remediation and improvement initiatives.
End Users
- Follow acceptable use guidelines.
- Report suspicious activity or unusual system behavior.
6. Enforcement
Failure to follow this policy may result in HR disciplinary action, restricted system access, or escalation for unauthorized log tampering, which is a serious violation.
7. Exceptions
Exceptions must follow the Exception Management Policy and require:
- Written justification
- Risk analysis
- Compensating controls
- Time‑bound approval (maximum 12 months)
- CIO approval for high‑risk exceptions
- Quarterly review in the Exception Register
8. Related Policies
- RC01 – Policy Governance Standard
- KU SEC 10 – Cybersecurity & IT Governance
- Information Security Policy
- Data Classification & Handling Policy
- SIEM & Detection Engineering Policy
- Incident Response Policy
- Cloud Computing & Third‑Party Risk Policy