Kean University DG – Logging, Monitoring & Alerting (SOP)
Table of Contents
- About This SOP
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Related Policies & Standards
- Compliance Mapping
- Metrics & KPIs
- Required Records & Storage
- Revision History
About This SOP
This Standard Operating Procedure (SOP) defines how Kean University performs logging, continuous monitoring, and alerting to detect unauthorized access, suspicious activity, and data misuse.
This SOP operationalizes monitoring and alerting requirements defined in KU DG 02 – Data Access & Privacy Policy and continuous monitoring expectations in KU DG 01 – Data Governance & Protection Policy.
Scope
- All University systems storing Internal, Confidential, or Restricted data
- Cloud, on‑premises, and hybrid environments
- All user, service, privileged, and vendor accounts
- Authentication, access, data movement, and configuration events
This SOP covers log generation, SIEM integration, alerting thresholds, monitoring cadence, escalation, and reporting.
Definitions
- Logging – Recording system and security events for audit and monitoring.
- Monitoring – Continuous review of logs to detect anomalies or violations.
- Alerting – Automated notifications triggered by suspicious activity.
- SIEM – Security Information and Event Management system.
- Unauthorized Access Attempt – Any access attempt without proper authorization.
Roles & Responsibilities
IT Security
- Configure and monitor SIEM
- Define alert thresholds and detection rules
- Investigate high‑severity alerts and escalate incidents
Identity & Access Management (IAM)
- Ensure authentication and access logs feed into SIEM
- Identify privileged accounts requiring enhanced monitoring
IT Custodians
- Enable logging on systems and applications
- Ensure secure log transmission and retention
Data Owners
- Identify systems or datasets requiring enhanced monitoring
Users
- Report unusual access alerts or suspicious activity
Procedure
Step 1 — Configure Logging
Ensure systems log authentication events, access to sensitive data, privileged activity, data exports, and configuration changes.
Step 2 — Centralize Logs
Forward all critical logs securely to the University SIEM with timestamps, user identifiers, event type, and outcome.
Step 3 — Define Alerting Rules
Configure alerts for unauthorized access attempts, failed MFA, abnormal access patterns, and sensitive data movement.
Step 4 — Daily & Weekly Monitoring
Review high‑severity alerts daily and conduct weekly trend and privileged‑access reviews.
Step 5 — Escalation & Incident Handling
Escalate confirmed threats according to Incident Response procedures and notify Data Owners when sensitive data may be impacted.
Step 6 — Log Retention & Protection
Retain security logs according to retention requirements and protect them using encryption and restricted access.
Step 7 — Reporting & Review
Produce monthly security reports, quarterly compliance summaries, and review detection rules at least quarterly.
Related Policies & Standards
- KU DG 02 – Data Access & Privacy Policy
- KU DG 01 – Data Governance & Protection Policy
- KU DG SOP 09 – Data Access Review
- KU SEC 03 – Incident Response
- KU ID 01 – Identity & Authentication
- KU IT 03 – Cybersecurity Training & Awareness
Compliance Mapping
| NIST CSF Function | Category | Subcategory |
|---|---|---|
| Detect | DE.CM – Continuous Monitoring | DE.CM01, DE.CM03 |
| Respond | RS.AN – Analysis | RS.AN01 |
| Recover | RC.IM – Improvements | RC.IM01 |
Metrics & KPIs
- Number of unauthorized access attempts detected
- Mean time to detect (MTTD) security events
- Percentage of systems reporting logs to SIEM
- Percentage of high‑severity alerts investigated within SLA
Required Records & Storage
- SIEM log archives
- Alert investigation records
- Incident response tickets
- Monitoring and compliance reports
Revision History
| Version | Date | Description | Author (Role) | Approver (Role) |
|---|---|---|---|---|
| 1.0 | February 13, 2026 | Initial release | IT Security Operations Lead | Chief Information Security Officer |
``