Kean University IAM Exception & Compensating Controls Standard Operating Procedure (SOP 11)
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure Steps
- Related Policies & Standards
- Metrics & KPIs
- Records & Storage
- Revision History
About
This Standard Operating Procedure (SOP) defines how Kean University manages Identity and Access Management (IAM) exceptions and compensating controls. It ensures all exceptions are documented, approved, monitored, and retired in alignment with security policies.
All IAM policies require exceptions to follow the University Exception Management Policy (KU SEC 05), including documented risk analysis, compensating controls, and defined expiration dates.
Back to topScope
This SOP applies to all IAM-related exceptions, including:
- Password or multi-factor authentication (MFA) exceptions
- Single Sign-On (SSO) integration limitations
- Shared account usage
- Account lifecycle delays
- Service account deviations
- Privileged access exceptions
- Technical limitations preventing enforcement
Applies to all employees, contractors, vendors, and system owners.
Back to topDefinitions
View Definitions
- Exception: Approved deviation from a required IAM policy.
- Compensating Control: Safeguard used to mitigate risk caused by an exception.
- Exception Register: Central log of all approved exceptions.
- Risk Analysis: Assessment of potential security and operational impact.
Roles & Responsibilities
| Role | Responsibilities |
|---|---|
| Requester | Submits exception with justification |
| System Owner | Validates business need and alternatives |
| IAM Lead | Evaluates technical impact and defines controls |
| Governance, Risk & Compliance (GRC) | Performs risk analysis and policy alignment |
| Chief Information Security Officer (CISO) | Final approval authority |
| Security Operations | Implements and monitors controls |
Procedure Steps
1. Exception Request Submission
- Submit via Freshservice ticket
- Include justification, duration (max 12 months), and documentation
- Provide proposed compensating controls
2. Initial Review
- System Owner confirms need
- IAM Lead evaluates technical feasibility
3. Risk Analysis
- Performed by GRC
- Evaluates likelihood, regulatory risk, and data impact
- Assigns risk rating (Low/Moderate/High)
4. Approval Workflow
- CISO approval required
- GRC approval required
- IAM Lead and System Owner sign-off
- CIO required for privileged access exceptions
5. Implement Compensating Controls
- Logging, MFA, monitoring, segmentation
- Controls must be documented and validated before activation
6. Activation
- Activate only after approvals and control validation
- Add to Exception Register
7. Monitoring
- Weekly monitoring by Security Operations
- High-risk exceptions require continuous monitoring
8. Review & Renewal
- Monthly review for high-risk exceptions
- Annual maximum duration (12 months)
- No automatic renewals
9. Closure
- Revert configurations
- Remove compensating controls
- Update register and close ticket
Related Policies & Standards
- KU SEC 05 – Exception Management Policy
- KU ID 01 – Identity & Authentication Policy
- KU ID 02 – Access Control Policy
- KU ID 03 – Account Management Policy
- KU ID 04 – Privileged Access Management Policy
- KU ID 02ST – Password & Authentication Standard
Metrics & KPIs
- Number of active exceptions
- Percentage with compensating controls
- Expired exceptions (target: 0)
- Approval time
- Risk distribution
- Monitoring alerts triggered
Records & Storage
| Record | Location |
|---|---|
| Exception Tickets | Freshservice |
| Risk Analysis | GRC Repository |
| Exception Register | GRC Managed System |
| Monitoring Logs | Security Information and Event Management (SIEM) |
Revision History
| Version | Date | Change |
|---|---|---|
| 1.0 | February 13, 2026 | Initial SOP |