KU ID 01 - Identity and Authentication Policy


Skip to main content

KU ID 01 – Identity & Authentication Policy (Staff‑Facing Version)

Table of Contents

1. Purpose

This policy defines how Kean University issues, verifies, protects, and manages user identities and login credentials to ensure only authorized and properly verified individuals can access University systems and data.

Back to top

2. Who Must Follow This Policy

This policy applies to all individuals accessing University systems, including:

  • Staff and faculty
  • Students
  • Contractors and temporary workers
  • Third‑party vendors requiring authenticated access

Back to top

3. Systems Covered

Covered platforms include:

  • Cloud services (Azure, AWS, SaaS applications)
  • On‑premise systems
  • Hybrid identity configurations

Back to top

4. Types of Identities Covered

  • Individual user accounts
  • Service accounts
  • Privileged accounts (see KU ID 04)
  • Shared accounts (require exception approval)

Back to top

5. Staff Responsibilities

5.1 Unique Identity Requirement

Every user must have their own unique account. Sharing accounts or passwords is prohibited.

5.2 Authentication Requirements

  • MFA (Multifactor Authentication) is mandatory for all staff and faculty.
  • Password requirements:
    • Minimum 10 characters
    • Must include uppercase, lowercase, numbers, and symbols
    • Rotated every 90 days
    • No reuse permitted

5.3 Credential Protection

  • Do not store passwords in plaintext.
  • Do not send passwords via email or chat.
  • Credentials must never be shared—not even with IT staff.

5.4 Session Security

  • Idle sessions must log out after 15 minutes.
  • Privileged or sensitive actions may require re‑authentication.

Back to top

6. Account Lifecycle Rules

6.1 New Accounts

All identities must be issued, updated, and removed using Kean’s official Identity Management systems (e.g., Active Directory or Azure AD).

6.2 Termination & Role Changes

  • Accounts must be disabled immediately upon employee separation.
  • Access must be removed when a change in role eliminates need.
  • Quarterly account reviews are required.

Back to top

7. Governance & Supporting Policies

This policy is governed by:

  • RC01 – Policy Standard
  • KU SEC 10 – Governance & Precedence

This policy relates to:

  • KU ID 02 – Access Control Policy
  • KU ID 03 – Account Management Policy
  • KU ID 04 – Privileged Access Management Policy
  • KU ID 02‑ST – Password & Authentication Standard

Back to top

8. Roles & Responsibilities

CISO

  • Oversees identity governance and enforcement.

IAM Lead

  • Manages identity lifecycle processes.

System Owners

  • Approve access to their systems.

Security Operations

  • Monitor authentication and detect suspicious behavior.

Internal Audit

  • Conduct credential and identity audits.

Users

  • Protect their login credentials.
  • Follow Kean authentication standards.
  • Report suspicious login activity immediately.

Back to top

9. Compliance Requirements

This policy supports compliance with:

  • NIST CSF 2.0 – Access Control categories
  • FERPA
  • HIPAA
  • GLBA
  • New Jersey identity protection requirements

Back to top

10. Enforcement

  • Loss of account access
  • Disciplinary action up to termination
  • Legal or regulatory consequences for severe violations

Back to top

11. Exceptions

Exceptions must:

  • Follow KU SEC 05 – Exception Management Policy
  • Include risk analysis and compensating controls
  • Receive approval from the CISO and GRC
  • Not exceed 12 months
  • Be entered into the Exception Register

Back to top

12. Review Cycle

This policy is reviewed annually or when significant changes occur to identity systems, authentication mechanisms, or after major security incidents.

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.