Kean University Privileged Access Management Policy
Table of Contents
- 1. What This Policy Is About
- 2. Why This Matters for Staff
- 3. Who This Policy Covers
- 4. Types of Privileged Access
- 5. Key Policy Requirements
- 6. Staff Responsibilities
- 7. Key Roles Supporting Privileged Access
- 8. Compliance & Regulatory Alignment
- 9. Exceptions
- 10. Enforcement
- 11. Related Documents
1. What This Policy Is About
The Privileged Access Management (PAM) Policy explains how Kean University manages accounts with elevated permissions. These accounts pose higher security risk, so additional controls, approvals, and monitoring are required.
[Link to authoritative KU ID 04 Word document]
2. Why This Matters for Staff
This policy helps staff understand:
- What privileged access is
- How privileged accounts are approved and reviewed
- Your responsibilities when using elevated access
- Emergency (break‑glass) access rules
- Compliance with FERPA, HIPAA, GLBA, and NIST CSF 2.0
3. Who This Policy Covers
This policy applies to individuals requiring elevated permissions, including:
- Employees
- Contractors
- Third‑party vendors
It covers privileged access across systems such as servers, cloud platforms, enterprise apps, and network infrastructure.
4. Types of Privileged Access
- Administrator / root accounts
- Domain or directory admins
- Database administrators
- Application administrators
- Elevated service accounts
- Emergency (break‑glass) accounts
5. Key Policy Requirements
5.1 Requesting Privileged Access
- Least privilege must be followed
- Requires System Owner AND CISO approval
- Provisioned only through IAM workflows
5.2 Authentication Requirements
- Passwords and MFA follow KU ID 02‑ST
5.3 Session Management
- Privileged sessions must use PAM tools or jump servers
- Session recording must be enabled when possible
5.4 Logging & Monitoring
- All privileged activity must feed into the SIEM
- Alerts required for unusual activity
5.5 Periodic Reviews
- Quarterly privileged access reviews required
- 30‑day inactive privileged accounts must be disabled
5.6 Emergency (Break‑Glass) Access
- Stored in a secure vault
- Requires CISO + CIO approval
- Use must be reviewed within 24 hours
5.7 Removing Privileged Access
- Removed immediately when employment ends
- Removed when duties change
- Vendor access removed when engagement ends
6. Staff Responsibilities
Staff with privileged access must:
- Use elevated access only for authorized work
- Follow authentication and MFA requirements
- Use PAM tools and jump servers
- Report suspicious activity immediately
- Work with IAM and supervisors when access needs change
- Ensure vendor elevated access is reviewed and removed as needed
7. Key Roles Supporting Privileged Access
CISO
- Approves privileged access and oversees governance.
IAM Lead
- Manages provisioning, reviews, and privileged workflows.
System Owners
- Approve privileged access to their systems.
Security Operations
- Monitors logs, alerts, and unusual privileged activity.
Internal Audit
- Verifies compliance with controls.
8. Compliance & Regulatory Alignment
- NIST CSF 2.0 PR.AC
- FERPA
- HIPAA
- GLBA
- NJ State privileged access requirements
9. Exceptions
- Follow KU SEC 05
- Must include risk analysis and compensating controls
- Requires CISO + GRC approval
- Tracked in the Exception Register
- Valid for max 12 months
10. Enforcement
- Privileged access removal
- Disciplinary action (up to termination)
- Vendor contract termination
- Legal or regulatory penalties
11. Related Documents
- RC01 – Policy Standard
- KU SEC 10 – Governance & Precedence
- KU ID 01 – Identity & Authentication Policy
- KU ID 02 – Access Control Policy
- KU ID 03 – Account Management Policy
- KU SEC 03 – Incident Response
- KU ID 02‑ST – Password & Authentication Standard
- Privileged Access SOP