KU ID 02 - Access Control Policy


Skip to main content

KU ID 02 – Access Control Policy (Staff‑Facing Version)

Table of Contents

1. Purpose

This policy defines how access to Kean University systems is requested, approved, monitored, and removed. It ensures users receive only the access they need and lose access promptly when it’s no longer required.

All authentication rules (passwords, MFA, lockouts, timeouts) are defined in the KU ID 02‑ST – Password & Authentication Standard.

Back to top

2. Who Must Follow This Policy

This policy applies to anyone granted access to University systems, including:

  • Employees
  • Contractors
  • Third‑party vendors

Back to top

3. Systems Covered

  • Kean‑owned or managed applications
  • On‑premise systems
  • Cloud and hybrid services

Back to top

4. Types of Access Covered

  • User access (employees, faculty, students)
  • Administrative / privileged access
  • Emergency access
  • Service/system accounts

Back to top

5. Key Responsibilities for Staff

5.1 Requesting Access

To receive access, you must:

  • Submit an official access request
  • Obtain manager approval
  • Undergo security review when required

5.2 Authentication Requirements

Authentication controls (passwords, MFA, lockouts) are defined in the Password & Authentication Standard.

5.3 Role‑Based Access

Access is based on your job role and limited to duties you must perform.

5.4 Least Privilege

  • Use only minimum access required
  • Notify IT when access is no longer needed

5.5 Access Reviews

Quarterly reviews ensure your access is still appropriate.

5.6 Emergency Access

Emergency access must:

  • Be approved
  • Be fully logged
  • Be reviewed within 24 hours

5.7 Monitoring & Logging

All access events are logged in Kean’s SIEM. Unauthorized attempts generate alerts.

Back to top

6. Roles & Responsibilities

CISO

  • Oversees access governance

IAM Lead

  • Manages provisioning & deprovisioning
  • Oversees quarterly reviews

Managers

  • Approve access requests

Security Operations

  • Monitor access logs and alerts

System Owners

  • Validate permission levels for their applications

Internal Audit

  • Review access control compliance

Users

  • Follow access processes
  • Protect credentials
  • Report suspicious activity

Back to top

7. Compliance Requirements
  • NIST CSF 2.0 PR.AC (Access Control)
  • FERPA
  • HIPAA
  • GLBA Safeguards Rule
  • New Jersey access governance requirements

Back to top

8. Enforcement
  • Access may be revoked
  • Employees may face corrective or disciplinary action
  • Vendors may face legal or contractual penalties

Back to top

9. Exceptions
  • Must follow KU SEC 05 – Exception Management
  • Require documented risk analysis
  • Must include compensating controls
  • Must receive CISO + GRC approval
  • Expire after 12 months
  • Logged in the Exception Register

Back to top

10. Review Cycle

This policy is reviewed annually and after significant regulatory or system changes.

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.