KUID SOP 02 - Access Control SOP


Skip to main content

Kean University Access Control Standard Operating Procedure (SOP02)

Table of Contents

About

This Standard Operating Procedure (SOP02) establishes how access to Kean University systems is authorized, granted, reviewed, adjusted, and revoked in alignment with the Access Control Policy (KU ID 02).

Field Value
Version 1.0
Author Identity & Access Management Lead
Approver Chief Information Security Officer
Effective Date February 13, 2026
Review Date February 13, 2027

Back to top

Security Control Summary

  • Access must be approved by management and validated by security
  • Least privilege access must be enforced for all roles
  • Multifactor authentication (MFA) required before access is granted
  • Quarterly access reviews must be completed
  • Emergency access must be approved, logged, and removed immediately after use
  • Access must be revoked promptly upon termination or role change

Back to top

Scope

  • All employees, contractors, and vendors requesting access
  • All systems managed or owned by Kean University
  • All access types including user, privileged, service, and emergency access

Back to top

Definitions

  • Access Control: Mechanisms that regulate access to systems and data
  • Authorization: Formal approval by management and security
  • Emergency Access: Temporary elevated access granted for critical situations

Back to top

Roles & Responsibilities

Role Responsibility
IAM Lead Provision access and perform access reviews
Managers Approve access based on job requirements
Security Operations Monitor access logs and alerts
System Owners Validate appropriate levels of access
Internal Audit Conduct access assurance reviews

Back to top

Procedure Steps


Diagram showing access request workflow from submission through approval, validation, and provisioning

1. Access Request Submission
  • User or department must submit access request via Freshservice
  • Manager must approve request
  • Security must validate compliance with least privilege
2. Access Provisioning
  • IAM team must provision access using role-based access control (RBAC)
  • Privileged access controls must be applied where required
  • All provisioning actions must be logged
3. Authentication Requirements
  • All users must meet authentication standards
  • MFA enrollment must be verified before access is granted
  • Access must be denied if authentication requirements are not satisfied
4. Access Adjustments
  • Managers must request role-based access changes
  • IAM must validate against RBAC matrix
  • Least privilege must be maintained
5. Emergency Access Procedures
  • Emergency access must include documented justification
  • Security must approve all emergency access
  • Access must be logged and reviewed within 24 hours
  • Access must be removed immediately after use

6. Access Reviews
  • Quarterly reviews must be conducted by IAM and system owners
  • Unnecessary access must be removed immediately
  • Review results must be documented

Diagram showing quarterly access review cycle including validation and removal of unnecessary access

7. Access Revocation
  • Triggered by termination, role change, or request
  • All access rights, tokens, and group memberships must be removed
  • Revocation must be logged

Back to top

  • [Insert link: KU ID 02 – Access Control Policy]
  • [Insert link: KU ID 01 – Identity & Authentication SOP]
  • KU ID 02ST – Password & Authentication Standard
  • KU SEC 10 – Governance & Precedence

Back to top

Metrics & KPIs

  • Access provisioning SLA compliance (measured via Freshservice reports)
  • Quarterly access review completion rate (tracked by IAM team)
  • Emergency access closure rate (reviewed within 24 hours)
  • Privileged access justification rate (validated by security)

Back to top

Required Records

  • Access request tickets (Freshservice)
  • Access review reports
  • Emergency access logs

Stored in: IAM systems and Security Information and Event Management (SIEM) tools

Back to top

Exception Handling

  • All exceptions must be approved by the Chief Information Security Officer (CISO)
  • Each exception must include business justification and risk assessment
  • Exceptions must have a defined expiration date
  • All exceptions must be tracked in [Insert system, e.g., Scrut.io]

Back to top

Revision History

Version Date Change Author
1.0 February 13, 2026 Initial SOP IAM Lead

Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.