Kean University – Data Access Request & Authorization (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines the standardized process for requesting, reviewing, approving, provisioning, modifying, and revoking access to Kean University systems and data.
This SOP operationalizes the requirements of KU DG 02 – Data Access & Privacy Policy and supports governed access controls defined in KU DG 01 – Data Governance & Protection Policy.
Scope
This SOP applies to:
- All University employees, contractors, and vendors requesting system or data access
- Managers, Data Owners, Identity & Access Management (IAM), and IT Security teams
- All systems containing Internal, Confidential, or Restricted data
This SOP covers access requests across on‑premises, cloud, and hybrid environments.
Definitions
- Access Request – A formal request to obtain access to a system, application, or dataset.
- Authorization – The approval process required before access is granted.
- Role‑Based Access Control (RBAC) – Access model that assigns permissions based on job role.
- Least Privilege – Principle of granting only the minimum access necessary.
- Privileged Access – Elevated access requiring enhanced security controls.
Roles & Responsibilities
Requestor
- Submit access requests through the official request system (Freshservice)
- Provide business justification aligned to job duties
Manager (Supervisor)
- Validate business need and least‑privilege alignment
- Approve or deny access requests
- Notify IAM of role changes or separations immediately
Data Owner
- Approve access to data assets they govern
- Ensure access aligns with assigned data classification
Identity & Access Management (IAM)
- Verify required approvals
- Provision and revoke access using RBAC
IT Security
- Review requests involving sensitive or regulated data
- Ensure multi‑factor authentication (MFA) and logging are enforced
Procedure
Step 1 — Submit Access Request
The requestor submits an access request through Freshservice including system name, requested role, business justification, and duration (if temporary).
Step 2 — Manager Review
The manager validates business need, confirms least‑privilege alignment, and approves or denies the request.
Step 3 — Data Owner Authorization
For systems containing Confidential or Restricted data, the Data Owner reviews and authorizes the request based on data classification requirements.
Step 4 — Security Review
IT Security reviews requests involving regulated data, privileged access, or MFA‑protected systems to ensure policy compliance.
Step 5 — IAM Provisioning
IAM provisions access using approved roles and records provisioning details in audit logs and the Freshservice ticket.
Step 6 — Notification
The requestor and manager are notified when access is granted or denied.
Step 7 — Access Modification
Access is reviewed and adjusted when role changes occur to maintain least privilege.
Step 8 — Access Removal
Access must be revoked immediately upon termination or separation notification.
Step 9 — Access Reviews
Quarterly and semiannual access reviews are conducted in accordance with data classification and policy requirements.
Related Policies & Standards
- KU DG 02 – Data Access & Privacy Policy
- KU DG 01 – Data Governance & Protection Policy
- KU ID 01 – Identity & Authentication
- KU ID 02 – Access Control
- KU ID 03 – Account Management
- KU IT 03 – Cybersecurity Training & Awareness
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Protect | PR.AC – Access Control | PR.AC01, PR.AC02, PR.AC04 |
| Protect | PR.AA – Authentication | PR.AA02 |
| Detect | DE.CM – Monitoring | DE.CM01 |
Metrics & KPIs
- Percentage of access requests completed within SLA
- Quarterly access review completion rate
- Percentage of access removals completed same business day
- Number of unauthorized access attempts detected
Required Records & Storage
- Access request tickets (Freshservice)
- IAM provisioning and deprovisioning logs
- System audit logs
- Access review evidence (GRC repository)
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Identity & Access Management Lead | Chief Information Security Officer |