Kean University Account Management Policy (Staff‑Facing Summary)
Table of Contents
- 1. What This Policy Is About
- 2. Why This Matters for Staff
- 3. Who This Applies To
- 4. Key Policy Requirements
- 5. Staff Responsibilities
- 6. Roles Important to Staff
- 7. Compliance & Regulations
- 8. Exceptions
- 9. What Happens if the Policy Is Violated
- 10. Related Documents
1. What This Policy Is About
This policy describes how Kean University creates, updates, reviews, and disables user accounts—including staff, faculty, students, vendors, privileged users, and service accounts. It ensures accounts are properly managed to prevent unauthorized access.
[Link to authoritative KU ID 03 Word document]
2. Why This Matters for Staff
This policy helps staff understand:
- How Kean accounts are created and disabled
- Naming conventions and rules for access
- Approval requirements for special access
- Your responsibilities for secure account use
- How IT protects accounts in alignment with FERPA, HIPAA, GLBA, and NIST CSF 2.0
[Link to authoritative KU ID 03 Word document]
3. Who This Applies To
This policy applies to the following account types:
- Faculty & staff accounts
- Student accounts
- Vendor/contractor accounts
- Privileged accounts
- Service accounts (automation)
It covers systems including Active Directory, Azure AD/OKTA, Microsoft 365, Workday, Colleague, and any system requiring login.
[Link to authoritative KU ID 03 Word document]
4. Key Policy Requirements
4.1 Account Creation
- Staff accounts are created automatically once HR provides onboarding data.
- Managers request vendor/privileged accounts with justification.
4.2 Account Naming
Format: first initial + up to seven characters of last name Example: John Smith → jsmith
4.3 Authentication Requirements
- Passwords and MFA follow KU ID 02‑ST (Password & Authentication Standard).
- This policy does not define additional rules.
4.4 Account Deactivation
- Staff accounts disable upon HR‑processed termination.
- Vendor/contractor accounts expire yearly unless renewed.
- Privileged & service accounts require annual review.
4.5 Auditing & Access Reviews
- IT conducts quarterly or biannual access audits.
- Dormant or orphaned accounts are removed.
[Link to authoritative KU ID 03 Word document]
5. Staff Responsibilities
Staff must:
- Use accounts only for authorized University work
- Protect passwords and MFA devices
- Report suspicious activity immediately
- Request only necessary access
- Notify IT when vendors no longer require access
[Link to authoritative KU ID 03 Word document]
6. Roles Important to Staff
CISO & IAM Lead
- Own the policy and manage account lifecycle operations.
Human Resources
- Provides onboarding and termination data that control account state.
Managers & Supervisors
- Approve vendor/privileged account requests
- Ensure access aligns with job duties
- Report role changes affecting access
[Link to authoritative KU ID 03 Word document]
7. Compliance & Regulations
This policy supports compliance with:
- NIST Cybersecurity Framework (CSF) 2.0 PR.AC
- FERPA
- HIPAA
- GLBA
- State of New Jersey access governance requirements
[Link to authoritative KU ID 03 Word document]
8. Exceptions
Exceptions must:
- Follow KU SEC 05 – Exception Management Policy
- Include risk analysis and compensating controls
- Be approved by the CISO and Governance, Risk & Compliance
- Not exceed 12 months
[Link to authoritative KU ID 03 Word document]
9. What Happens if the Policy Is Violated
- Suspension or removal of access
- Disciplinary action (up to termination)
- Vendor contract termination
- Legal or regulatory implications
[Link to authoritative KU ID 03 Word document]
10. Related Documents
- RC 01 – Policy Standard
- KU SEC 10 – Governance & Precedence
- KU ID 01 – Identity & Authentication
- KU ID 02 – Access Control
- KU ID 04 – Privileged Access Management
- KU ID 02‑ST – Password & Authentication Standard
- Kean University Cybersecurity Glossary