KU ID 01 – Identity & Authentication Policy (Staff‑Facing Version)
Table of Contents
- 1. Purpose
- 2. Who Must Follow This Policy
- 3. Systems Covered
- 4. Types of Identities Covered
- 5. Staff Responsibilities
- 6. Account Lifecycle Rules
- 7. Governance & Supporting Policies
- 8. Roles & Responsibilities
- 9. Compliance Requirements
- 10. Enforcement
- 11. Exceptions
- 12. Review Cycle
1. Purpose
This policy defines how Kean University issues, verifies, protects, and manages user identities and login credentials to ensure only authorized and properly verified individuals can access University systems and data.
2. Who Must Follow This Policy
This policy applies to all individuals accessing University systems, including:
- Staff and faculty
- Students
- Contractors and temporary workers
- Third‑party vendors requiring authenticated access
3. Systems Covered
Covered platforms include:
- Cloud services (Azure, AWS, SaaS applications)
- On‑premise systems
- Hybrid identity configurations
4. Types of Identities Covered
- Individual user accounts
- Service accounts
- Privileged accounts (see KU ID 04)
- Shared accounts (require exception approval)
5. Staff Responsibilities
5.1 Unique Identity Requirement
Every user must have their own unique account. Sharing accounts or passwords is prohibited.
5.2 Authentication Requirements
- MFA (Multifactor Authentication) is mandatory for all staff and faculty.
- Password requirements:
- Minimum 10 characters
- Must include uppercase, lowercase, numbers, and symbols
- Rotated every 90 days
- No reuse permitted
5.3 Credential Protection
- Do not store passwords in plaintext.
- Do not send passwords via email or chat.
- Credentials must never be shared—not even with IT staff.
5.4 Session Security
- Idle sessions must log out after 15 minutes.
- Privileged or sensitive actions may require re‑authentication.
6. Account Lifecycle Rules
6.1 New Accounts
All identities must be issued, updated, and removed using Kean’s official Identity Management systems (e.g., Active Directory or Azure AD).
6.2 Termination & Role Changes
- Accounts must be disabled immediately upon employee separation.
- Access must be removed when a change in role eliminates need.
- Quarterly account reviews are required.
7. Governance & Supporting Policies
This policy is governed by:
- RC01 – Policy Standard
- KU SEC 10 – Governance & Precedence
This policy relates to:
- KU ID 02 – Access Control Policy
- KU ID 03 – Account Management Policy
- KU ID 04 – Privileged Access Management Policy
- KU ID 02‑ST – Password & Authentication Standard
8. Roles & Responsibilities
CISO
- Oversees identity governance and enforcement.
IAM Lead
- Manages identity lifecycle processes.
System Owners
- Approve access to their systems.
Security Operations
- Monitor authentication and detect suspicious behavior.
Internal Audit
- Conduct credential and identity audits.
Users
- Protect their login credentials.
- Follow Kean authentication standards.
- Report suspicious login activity immediately.
9. Compliance Requirements
This policy supports compliance with:
- NIST CSF 2.0 – Access Control categories
- FERPA
- HIPAA
- GLBA
- New Jersey identity protection requirements
10. Enforcement
- Loss of account access
- Disciplinary action up to termination
- Legal or regulatory consequences for severe violations
11. Exceptions
Exceptions must:
- Follow KU SEC 05 – Exception Management Policy
- Include risk analysis and compensating controls
- Receive approval from the CISO and GRC
- Not exceed 12 months
- Be entered into the Exception Register
12. Review Cycle
This policy is reviewed annually or when significant changes occur to identity systems, authentication mechanisms, or after major security incidents.