Skip to main content
Kean University Access Control Standard Operating Procedure (SOP02)
Table of Contents
About
This Standard Operating Procedure (SOP02) establishes how access to Kean University systems is authorized, granted, reviewed, adjusted, and revoked in alignment with the Access Control Policy (KU ID 02).
| Field |
Value |
| Version |
1.0 |
| Author |
Identity & Access Management Lead |
| Approver |
Chief Information Security Officer |
| Effective Date |
February 13, 2026 |
| Review Date |
February 13, 2027 |
Back to top
Security Control Summary
- Access must be approved by management and validated by security
- Least privilege access must be enforced for all roles
- Multifactor authentication (MFA) required before access is granted
- Quarterly access reviews must be completed
- Emergency access must be approved, logged, and removed immediately after use
- Access must be revoked promptly upon termination or role change
Back to top
Scope
- All employees, contractors, and vendors requesting access
- All systems managed or owned by Kean University
- All access types including user, privileged, service, and emergency access
Back to top
Definitions
-
Access Control: Mechanisms that regulate access to systems and data
-
Authorization: Formal approval by management and security
-
Emergency Access: Temporary elevated access granted for critical situations
Back to top
Roles & Responsibilities
| Role |
Responsibility |
| IAM Lead |
Provision access and perform access reviews |
| Managers |
Approve access based on job requirements |
| Security Operations |
Monitor access logs and alerts |
| System Owners |
Validate appropriate levels of access |
| Internal Audit |
Conduct access assurance reviews |
Back to top
Procedure Steps

1. Access Request Submission
- User or department must submit access request via Freshservice
- Manager must approve request
- Security must validate compliance with least privilege
2. Access Provisioning
- IAM team must provision access using role-based access control (RBAC)
- Privileged access controls must be applied where required
- All provisioning actions must be logged
3. Authentication Requirements
- All users must meet authentication standards
- MFA enrollment must be verified before access is granted
- Access must be denied if authentication requirements are not satisfied
4. Access Adjustments
- Managers must request role-based access changes
- IAM must validate against RBAC matrix
- Least privilege must be maintained
5. Emergency Access Procedures
- Emergency access must include documented justification
- Security must approve all emergency access
- Access must be logged and reviewed within 24 hours
- Access must be removed immediately after use

6. Access Reviews
- Quarterly reviews must be conducted by IAM and system owners
- Unnecessary access must be removed immediately
- Review results must be documented

7. Access Revocation
- Triggered by termination, role change, or request
- All access rights, tokens, and group memberships must be removed
- Revocation must be logged
Back to top
- [Insert link: KU ID 02 – Access Control Policy]
- [Insert link: KU ID 01 – Identity & Authentication SOP]
- KU ID 02ST – Password & Authentication Standard
- KU SEC 10 – Governance & Precedence
Back to top
Metrics & KPIs
- Access provisioning SLA compliance (measured via Freshservice reports)
- Quarterly access review completion rate (tracked by IAM team)
- Emergency access closure rate (reviewed within 24 hours)
- Privileged access justification rate (validated by security)
Back to top
Required Records
- Access request tickets (Freshservice)
- Access review reports
- Emergency access logs
Stored in: IAM systems and Security Information and Event Management (SIEM) tools
Back to top
Exception Handling
- All exceptions must be approved by the Chief Information Security Officer (CISO)
- Each exception must include business justification and risk assessment
- Exceptions must have a defined expiration date
- All exceptions must be tracked in [Insert system, e.g., Scrut.io]
Back to top
Revision History
| Version |
Date |
Change |
Author |
| 1.0 |
February 13, 2026 |
Initial SOP |
IAM Lead |
Back to top