Kean University – Role‑Based Access Control (RBAC) Implementation (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines the structured, repeatable process for implementing, maintaining, and auditing Role‑Based Access Control (RBAC) across Kean University systems.
RBAC ensures that users receive only the access required for their job functions and that access aligns with data classification, regulatory requirements, and institutional security controls.
Scope
This SOP applies to:
- All University systems containing Internal, Confidential, or Restricted data
- All user accounts, including employees, contractors, and vendors
- Identity & Access Management (IAM), IT Security, Data Owners, and Data Stewards
- Access provisioning, modification, review, and deprovisioning workflows
RBAC applies to both on‑premises and cloud systems, including enterprise applications and infrastructure platforms.
Definitions
- Role‑Based Access Control (RBAC) – A permissions model that assigns access based on job function.
- Role – A defined set of permissions representing a job function.
- Privilege – A specific action a user may perform (for example, read, write, administer).
- Privileged Role – A role with elevated permissions requiring additional security controls.
- Data Owner – Role accountable for approving access to data within their domain.
Roles & Responsibilities
Identity & Access Management (IAM)
- Create, modify, and retire RBAC roles
- Ensure roles enforce least privilege
- Maintain the RBAC Role Catalog
Data Owners
- Approve roles that provide access to governed data
- Validate alignment with data classification requirements
Data Stewards
- Ensure RBAC‑granted access aligns with handling requirements
IT Security
- Validate MFA, logging, and monitoring for RBAC roles
- Monitor for role misuse or privilege escalation
Managers
- Identify appropriate roles for staff
- Report duty changes requiring role updates
Users
- Use only access granted through assigned roles
- Report incorrect or excessive access
Procedure
Step 1 — Identify Job Functions
IAM works with departments to identify job functions and required permissions, validating data classification requirements with Data Owners.
Step 2 — Create RBAC Roles
When a new role is required, IAM defines permissions, Data Owners approve classification impacts, and IT Security validates least privilege, MFA, and logging requirements.
Step 3 — Assign Users to Roles
Managers submit access requests through Freshservice. IAM provisions access using approved RBAC roles and records assignments in audit logs.
Step 4 — Modify Roles
Role changes require impact analysis, Data Owner approval for sensitive data access, and IT Security validation for privileged roles.
Step 5 — Revoke Role Assignments
Role removal occurs upon separation, role change, or access review findings and is documented immediately.
Step 6 — Periodic RBAC Reviews
RBAC roles and assignments are reviewed quarterly for sensitive systems and semiannually for all other systems. Findings are documented in the GRC repository.
Step 7 — Privileged Role Management
Privileged roles require MFA, continuous monitoring, and formal exception approval when deviations are necessary.
Related Policies & Standards
- KU DG 02 – Data Access & Privacy Policy
- KU DG 01 – Data Governance & Protection Policy
- KU ID 02 – Access Control
- KU ID 04 – Privileged Access
- KU SEC 05 – Exception Management
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Protect | PR.AC – Access Control | PR.AC01, PR.AC02, PR.AC04 |
| Protect | PR.AA – Authentication | PR.AA02 |
| Detect | DE.CM – Monitoring | DE.CM01 |
Metrics & KPIs
- Percentage of users assigned to valid RBAC roles
- Number of privileged roles versus standard roles
- Access review completion rates
- Time to deprovision users after separation
Required Records & Storage
- RBAC Role Catalog (IAM repository)
- Access request and approval logs (Freshservice)
- Provisioning and deprovisioning logs
- Access review evidence (GRC repository)
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Identity & Access Management Lead | Chief Information Security Officer |
``