Skip to main content
Kean University Identity & Authentication Standard Operating Procedure (SOP01)
Table of Contents
About
This Standard Operating Procedure (SOP01) defines how Kean University issues identities, enforces authentication, secures credentials, and manages session controls in alignment with the Identity & Authentication Policy (KU ID 01).
| Field |
Value |
| Version |
1.0 |
| Author |
Identity & Access Management Lead |
| Approver |
Chief Information Security Officer |
| Effective Date |
February 13, 2026 |
| Review Date |
February 13, 2027 |
Back to top
Scope
- All staff, faculty, students, contractors, and vendors requiring authenticated access
- All platforms (on-premises, cloud, and hybrid)
- All identity types: user, service, shared (restricted), and privileged accounts
Back to top
Definitions
-
Identity: A unique digital representation of a user or system
-
Authentication: Verification of identity using credentials
-
Multifactor Authentication (MFA): A login method requiring two or more verification factors
-
Credential: A password, token, certificate, or authenticator used for access
Back to top
Roles & Responsibilities
| Role |
Responsibility |
| IAM Lead |
Manage identities and enforce authentication controls |
| System Owners |
Validate user eligibility for identity issuance |
| Security Operations |
Monitor authentication events and anomalies |
| Users |
Safeguard credentials and comply with MFA requirements |
| Internal Audit |
Perform identity and authentication audits |
Back to top
Procedure Steps
1. Identity Issuance
- Receive identity request from HR, Registrar, or system owner
- Verify user type
- Create identity in the Identity Management System (e.g., Okta)
- Apply naming conventions
- Assign baseline role-based access control (RBAC)
- Log identity issuance

2. Authentication Enrollment
- Require MFA enrollment at first login
- Enforce password standards
- Perform identity verification for elevated access
- Document enrollment completion

3. Credential Protection
- Ensure passwords are hashed and salted
- Prohibit plaintext credential storage
- Block shared credential usage unless approved
- Rotate service account credentials every 90 days unless automated
4. Session Management
- Enforce 15-minute idle session timeout
- Require reauthentication for sensitive actions
- Monitor sessions using security tools (SIEM)
5. Identity Deactivation
- Disable identities upon HR or Registrar notification
- Remove all access and group memberships
- Revoke tokens and active sessions
- Retain logs per retention policy

Back to top
- [Insert link: KU ID 01 – Identity & Authentication Policy]
- KU ID 02ST – Password & Authentication Standard
- KU SEC 10 – Governance & Precedence
Back to top
Metrics & KPIs
- MFA enrollment rate (target: 100%)
- Identity issuance SLA compliance
- Credential rotation compliance rate
- Identity deactivation time (target: ≤ 24 hours)
Back to top
Required Records & Storage
- Identity creation logs
- Authentication enrollment logs
- Deactivation logs
Stored in: IAM systems, Security Operations SIEM, and Scrut.io
Back to top
Revision History
| Version |
Date |
Change |
Author |
| 1.0 |
February 13, 2026 |
Initial SOP |
IAM Lead |
Back to top