KUID SOP 11 - IAM Exception & Compensating Controls SOP


Kean University IAM Exception & Compensating Controls Standard Operating Procedure (SOP 11)

Table of Contents

About

This Standard Operating Procedure (SOP) defines how Kean University manages Identity and Access Management (IAM) exceptions and compensating controls. It ensures all exceptions are documented, approved, monitored, and retired in alignment with security policies.

All IAM policies require exceptions to follow the University Exception Management Policy (KU SEC 05), including documented risk analysis, compensating controls, and defined expiration dates.

Back to top

Scope

This SOP applies to all IAM-related exceptions, including:

  • Password or multi-factor authentication (MFA) exceptions
  • Single Sign-On (SSO) integration limitations
  • Shared account usage
  • Account lifecycle delays
  • Service account deviations
  • Privileged access exceptions
  • Technical limitations preventing enforcement

Applies to all employees, contractors, vendors, and system owners.

Back to top

Definitions

View Definitions
  • Exception: Approved deviation from a required IAM policy.
  • Compensating Control: Safeguard used to mitigate risk caused by an exception.
  • Exception Register: Central log of all approved exceptions.
  • Risk Analysis: Assessment of potential security and operational impact.
Back to top

Roles & Responsibilities

Role Responsibilities
Requester Submits exception with justification
System Owner Validates business need and alternatives
IAM Lead Evaluates technical impact and defines controls
Governance, Risk & Compliance (GRC) Performs risk analysis and policy alignment
Chief Information Security Officer (CISO) Final approval authority
Security Operations Implements and monitors controls
Back to top

Procedure Steps

Flowchart showing IAM exception lifecycle from request submission through approval, monitoring, and closure

1. Exception Request Submission
  • Submit via Freshservice ticket
  • Include justification, duration (max 12 months), and documentation
  • Provide proposed compensating controls
2. Initial Review
  • System Owner confirms need
  • IAM Lead evaluates technical feasibility
3. Risk Analysis
  • Performed by GRC
  • Evaluates likelihood, regulatory risk, and data impact
  • Assigns risk rating (Low/Moderate/High)
4. Approval Workflow
  • CISO approval required
  • GRC approval required
  • IAM Lead and System Owner sign-off
  • CIO required for privileged access exceptions

Hierarchical diagram showing required approvals for IAM exception requests including CISO and GRC

5. Implement Compensating Controls
  • Logging, MFA, monitoring, segmentation
  • Controls must be documented and validated before activation

Grid of common compensating controls such as MFA, logging, and session monitoring

6. Activation
  • Activate only after approvals and control validation
  • Add to Exception Register
7. Monitoring
  • Weekly monitoring by Security Operations
  • High-risk exceptions require continuous monitoring
8. Review & Renewal
  • Monthly review for high-risk exceptions
  • Annual maximum duration (12 months)
  • No automatic renewals

Timeline diagram showing IAM exception lifecycle with 12-month expiration and review checkpoints

9. Closure
  • Revert configurations
  • Remove compensating controls
  • Update register and close ticket
Back to top
  • KU SEC 05 – Exception Management Policy
  • KU ID 01 – Identity & Authentication Policy
  • KU ID 02 – Access Control Policy
  • KU ID 03 – Account Management Policy
  • KU ID 04 – Privileged Access Management Policy
  • KU ID 02ST – Password & Authentication Standard
Back to top

Metrics & KPIs

  • Number of active exceptions
  • Percentage with compensating controls
  • Expired exceptions (target: 0)
  • Approval time
  • Risk distribution
  • Monitoring alerts triggered
Back to top

Records & Storage

Record Location
Exception Tickets Freshservice
Risk Analysis GRC Repository
Exception Register GRC Managed System
Monitoring Logs Security Information and Event Management (SIEM)
Back to top

Revision History

Version Date Change
1.0 February 13, 2026 Initial SOP
Back to top

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.