Kean University – Data Sharing, Transfer & Third‑Party Access (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines the required processes for securely sharing, transferring, and granting third‑party access to Kean University data.
The SOP operationalizes requirements from KU DG 01 – Data Governance & Protection Policy and KU DG 02 – Data Access & Privacy Policy to ensure that all data exchanges are authorized, auditable, and protected.
Scope
- All University data classified as Internal, Confidential, or Restricted
- All employees, contractors, student workers, and vendors
- All internal sharing, external transfers, and third‑party access arrangements
- Digital and physical data transfers
This SOP covers internal sharing, external transfers, third‑party access, secure transmission, logging, and compliance controls.
Definitions
- Data Sharing – Authorized disclosure of data to another individual, department, or system.
- Data Transfer – Movement of data between systems or environments.
- Third‑Party Access – Access granted to external vendors, partners, or service providers.
- Restricted Data – Legally regulated data requiring maximum protection.
- Secure Transfer Methods – University‑approved encrypted tools (e.g., SFTP, secure portals).
Roles & Responsibilities
Data Owners
- Approve all sharing or transfer of Confidential or Restricted data
- Validate legal, regulatory, and classification alignment
Data Stewards
- Ensure appropriate controls are applied during sharing and transfer
- Maintain required documentation and logs
IT Security
- Validate encryption and secure transfer methods
- Monitor third‑party access and investigate anomalies
IT Custodians
- Configure secure transfer channels and integrations
- Validate technical safeguards for vendors
Managers
- Confirm business justification for data sharing or transfer requests
Users
- Share data only through approved channels
- Report unauthorized sharing immediately
Procedure
Step 1 — Identify Data Classification
Determine whether data is Internal, Confidential, or Restricted and apply appropriate labels.
Step 2 — Submit Sharing or Transfer Request
Submit a Freshservice request including purpose, recipients, classification, method, and duration.
Step 3 — Data Owner Approval
Required for all Confidential or Restricted data prior to sharing or transfer.
Step 4 — Validate Secure Transfer Method
IT validates encryption, approved tools, and logging requirements.
Step 5 — Execute Data Sharing or Transfer
Use only approved internal or external secure platforms and ensure logging is enabled.
Step 6 — Enable Third‑Party Access
Provision least‑privilege access, enforce MFA where required, and document approvals.
Step 7 — Monitor and Remove Access
Monitor activity and immediately revoke access when no longer required.
Related Policies & Standards
- KU DG 01 – Data Governance & Protection Policy
- KU DG 02 – Data Access & Privacy Policy
- KU DG SOP 01 – Data Classification & Labeling
- KU DG SOP 05 – Least Privilege Enforcement
- KU SEC 03 – Incident Response
- KU IT 03 – Cybersecurity Training & Awareness
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Protect | PR.DS – Data Security | PR.DS05, PR.DS01, PR.DS02 |
| Protect | PR.AC – Access Control | PR.AC03 |
| Detect | DE.CM – Monitoring | DE.CM01 |
Metrics & KPIs
- Percentage of transfers using approved secure methods
- Percentage of transfers with Data Owner approval
- Number of third‑party access violations
- Time to revoke third‑party access after completion
Required Records & Storage
- Data sharing and transfer requests (Freshservice)
- Data Owner approvals
- Transfer and access logs
- Third‑Party Access Register (GRC repository)
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | Data Governance Lead | Chief Information Security Officer |
``