Kean University Cybersecurity Training & Awareness Operations
Table of Contents- About This SOP
- Scope
- Roles & Responsibilities
- Operational Procedures
- NIST CSF 2.0 Mapping
- Metrics & KPIs
- Records & Storage
- Document Control
About This SOP
This Standard Operating Procedure (SOP) defines how Kean University operationalizes mandatory cybersecurity training and awareness requirements under KU IT 03 – Cybersecurity Training & Awareness. It ensures that all users understand their responsibilities for protecting University information systems and data.
Cybersecurity refers to the practice of protecting systems, networks, and data from digital attacks.
Scope
This SOP applies to all users with access to Kean University systems, including employees, faculty, students, contractors, and affiliates.
Roles & Responsibilities
- Information Security Office (ISO): Develops training content, manages reporting, and conducts phishing simulations.
- Human Resources (HR): Integrates cybersecurity training into onboarding and offboarding processes.
- Managers: Enforce training compliance within their teams.
- Users: Complete required training and assessments on time.
Operational Procedures
View cybersecurity training procedures
1. Annual Training
All users must complete mandatory cybersecurity awareness training each year. Training topics include:
- Phishing awareness
- Data handling and protection
- Incident identification and reporting
2. Assessment & Remediation
Users must complete a post-training assessment. Failure to pass requires remediation training, which must be completed within 30 days.
3. High-Risk Users
Users identified as high risk must complete advanced cybersecurity training twice per year and participate in mandatory phishing simulations.
4. Incident-Triggered Training
Users involved in a cybersecurity incident must complete targeted training within 15 days of the incident.
5. Reporting
The Information Security Office generates quarterly reports, and training metrics are integrated into the University’s risk dashboard.
NIST CSF 2.0 Mapping
This SOP aligns with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) version 2.0, supporting the following functions:
- Protect: PR.AT (Awareness and Training)
- Detect: DE.CM (Continuous Monitoring)
- Respond: RS.CO (Communications)
- Govern: GV.RR (Roles, Responsibilities, and Authorities)
Metrics & KPIs
View training metrics and key performance indicators
- Training completion rate
- Phishing simulation failure rate
- Remediation completion time
Records & Storage
- Training records: Stored in the Learning Management System (LMS).
- Reports: Stored in the University risk management platform (e.g., [Scrut.io – link to be provided]).
Document Control
- Version: 1.0
- Author: Information Security Office
- Approver: Chief Information Security Officer (CISO)
- Effective Date: February 13, 2026
- Review Cycle: Annual
``