KU ID 03 - Account Management



Kean University Account Management Policy (Staff‑Facing Summary)

Table of Contents

1. What This Policy Is About

This policy describes how Kean University creates, updates, reviews, and disables user accounts—including staff, faculty, students, vendors, privileged users, and service accounts. It ensures accounts are properly managed to prevent unauthorized access.

[Link to authoritative KU ID 03 Word document]

Back to top

2. Why This Matters for Staff

This policy helps staff understand:

  • How Kean accounts are created and disabled
  • Naming conventions and rules for access
  • Approval requirements for special access
  • Your responsibilities for secure account use
  • How IT protects accounts in alignment with FERPA, HIPAA, GLBA, and NIST CSF 2.0

[Link to authoritative KU ID 03 Word document]

Back to top

3. Who This Applies To

This policy applies to the following account types:

  • Faculty & staff accounts
  • Student accounts
  • Vendor/contractor accounts
  • Privileged accounts
  • Service accounts (automation)

It covers systems including Active Directory, Azure AD/OKTA, Microsoft 365, Workday, Colleague, and any system requiring login.

[Link to authoritative KU ID 03 Word document]

Back to top

4. Key Policy Requirements

4.1 Account Creation

  • Staff accounts are created automatically once HR provides onboarding data.
  • Managers request vendor/privileged accounts with justification.

4.2 Account Naming

Format: first initial + up to seven characters of last name Example: John Smith → jsmith

4.3 Authentication Requirements

  • Passwords and MFA follow KU ID 02‑ST (Password & Authentication Standard).
  • This policy does not define additional rules.

4.4 Account Deactivation

  • Staff accounts disable upon HR‑processed termination.
  • Vendor/contractor accounts expire yearly unless renewed.
  • Privileged & service accounts require annual review.

4.5 Auditing & Access Reviews

  • IT conducts quarterly or biannual access audits.
  • Dormant or orphaned accounts are removed.

[Link to authoritative KU ID 03 Word document]

Back to top

5. Staff Responsibilities

Staff must:

  • Use accounts only for authorized University work
  • Protect passwords and MFA devices
  • Report suspicious activity immediately
  • Request only necessary access
  • Notify IT when vendors no longer require access

[Link to authoritative KU ID 03 Word document]

Back to top

6. Roles Important to Staff

CISO & IAM Lead

  • Own the policy and manage account lifecycle operations.

Human Resources

  • Provides onboarding and termination data that control account state.

Managers & Supervisors

  • Approve vendor/privileged account requests
  • Ensure access aligns with job duties
  • Report role changes affecting access

[Link to authoritative KU ID 03 Word document]

Back to top

7. Compliance & Regulations

This policy supports compliance with:

  • NIST Cybersecurity Framework (CSF) 2.0 PR.AC
  • FERPA
  • HIPAA
  • GLBA
  • State of New Jersey access governance requirements

[Link to authoritative KU ID 03 Word document]

Back to top

8. Exceptions

Exceptions must:

  • Follow KU SEC 05 – Exception Management Policy
  • Include risk analysis and compensating controls
  • Be approved by the CISO and Governance, Risk & Compliance
  • Not exceed 12 months

[Link to authoritative KU ID 03 Word document]

Back to top

9. What Happens if the Policy Is Violated

  • Suspension or removal of access
  • Disciplinary action (up to termination)
  • Vendor contract termination
  • Legal or regulatory implications

[Link to authoritative KU ID 03 Word document]

Back to top

  • RC 01 – Policy Standard
  • KU SEC 10 – Governance & Precedence
  • KU ID 01 – Identity & Authentication
  • KU ID 02 – Access Control
  • KU ID 04 – Privileged Access Management
  • KU ID 02‑ST – Password & Authentication Standard
  • Kean University Cybersecurity Glossary


Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.