Kean University – Data Storage & Encryption Compliance (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines how Kean University ensures that University data—especially Confidential and Restricted data—is stored only on approved platforms and protected using mandatory encryption controls.
This SOP operationalizes storage and encryption requirements established in KU DG 01 – Data Governance & Protection Policy and privacy protections defined in KU DG 02 – Data Access & Privacy Policy.
Scope
- All University systems, applications, and storage platforms
- All University employees, contractors, vendors, and service accounts
- All data classified as Internal, Confidential, or Restricted
- On‑premises, cloud, and hybrid storage environments
This SOP covers approved storage platforms, encryption at rest and in transit, monitoring, and remediation.
Definitions
- Approved Storage Platform – A system validated and maintained by Kean IT for compliant data storage.
- Encryption at Rest – Cryptographic protection applied to stored data.
- Encryption in Transit – Encryption applied while data is transmitted over networks.
- Restricted Data – Legally protected data requiring the highest level of control.
- Data Custodian – IT role responsible for implementing and maintaining storage and encryption controls.
Roles & Responsibilities
Data Owners
- Determine data classification
- Approve storage platform usage based on classification
Data Stewards
- Ensure data is stored and handled according to classification
- Verify labeling and approved storage locations
IT Custodians (Kean IT)
- Maintain the approved storage platform list
- Enforce encryption at rest and in transit
- Block or disable unapproved storage services
IT Security
- Validate encryption configurations
- Monitor for unauthorized storage and data movement
- Investigate encryption failures and violations
Users
- Store data only in approved systems
- Report improper or accidental data storage immediately
Procedure
Step 1 — Identify Data Classification
Determine whether data is Internal, Confidential, or Restricted using approved classification standards.
Step 2 — Select Approved Storage Platform
Verify the storage platform is approved by Kean IT. Personal cloud storage is prohibited for sensitive data.
Step 3 — Verify Encryption at Rest
Ensure industry‑standard encryption (for example, AES‑256) is enabled for stored data.
Step 4 — Verify Encryption in Transit
Confirm all data transfers use secure, encrypted protocols.
Step 5 — Data Upload & Handling Compliance
Store data only in authorized systems and notify IT Security of improper storage.
Step 6 — Monitoring & Detection
Security teams monitor logs and alerts for unauthorized storage or data movement.
Step 7 — Remediation & Incident Handling
Noncompliant data is quarantined or migrated, and corrective actions are documented.
Step 8 — Periodic Storage & Encryption Audits
Storage and encryption controls are reviewed quarterly and semiannually.
Related Policies & Standards
- KU DG 01 – Data Governance & Protection Policy
- KU DG 02 – Data Access & Privacy Policy
- KU DG SOP 01 – Data Classification & Labeling
- KU SEC 03 – Incident Response
- KU SEC 05 – Exception Management
- KU IT 03 – Cybersecurity Training & Awareness
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Protect | PR.DS – Data Security | PR.DS01, PR.DS02, PR.DS05 |
| Detect | DE.CM – Monitoring | DE.CM01 |
| Respond | RS.MI – Mitigation | RS.MI01 |
Metrics & KPIs
- Percentage of systems with encryption enabled at rest
- Percentage of systems enforcing encrypted transport
- Number of unauthorized storage events detected
- Audit compliance rate for approved storage platforms
Required Records & Storage
- Approved Storage Platform List (Governance repository)
- Encryption configuration and validation logs
- Data loss prevention and storage violation alerts
- Audit and review evidence (GRC repository)
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | IT Infrastructure & Security Engineering Lead | Chief Information Security Officer |