Kean University SRM SOP 14 – Lifecycle Sustainment Planning

Skip to main content


Kean University SOP 14 – Lifecycle Sustainment Planning

Table of Contents

About

This Standard Operating Procedure (SOP) establishes the required process for evaluating, documenting, and maintaining lifecycle sustainment plans for University acquisitions.

Lifecycle sustainment planning ensures that systems, software, services, and equipment remain supported, secure, and financially viable throughout their operational lifespan.

Back to top

Scope

This SOP applies to acquisitions that:

  • Introduce IT systems, software, or cloud services
  • Rely on third‑party support or vendor roadmaps
  • Require licensing, maintenance, or subscription renewals
  • Impact data security, compliance, or institutional continuity
  • Are funded by University or grant resources

Sustainment planning applies during onboarding, renewal, ongoing operation, and offboarding.

Back to top

Definitions

  • Lifecycle Sustainment: Planning for long‑term support, maintenance, and viability.
  • End of Life (EOL): When a vendor no longer supports a product.
  • End of Support (EOS): When security patches or updates cease.
  • Sustainment Plan: Document outlining costs, upgrades, responsibilities, and risks.
  • Sustainment Risk: Risk of obsolescence, insecurity, or lack of funding.

Back to top

Roles & Responsibilities

View roles
  • Procurement Lead: Ensures sustainment planning is completed and documented.
  • Business Owner: Defines operational sustainment needs and continuity plans.
  • Risk Manager: Evaluates sustainment risks and updates the Risk Register.
  • Information Technology (IT) Security: Reviews security implications of EOL/EOS.
  • Finance: Confirms long‑term funding and budget viability.
  • Chief Information Security Officer (CISO): Approves sustainment plans for High or Critical systems.

Back to top

Procedure

1. Determine Sustainment Requirements

Procurement identifies whether a Sustainment Plan is required (default: required for all IT, software, cloud, and operational‑critical acquisitions).

2. Gather Vendor Lifecycle Information

Vendor documentation is collected, including support models, patch cycles, upgrade schedules, and EOL/EOS timelines.

3. Develop the Sustainment Plan

The Business Owner documents costs, renewal cycles, staffing needs, upgrade requirements, and contingency planning using the approved sustainment template.

4. Risk & Financial Review

Risk Management evaluates sustainment risks, while Finance confirms funding beyond the initial acquisition period.


Back to top

Review & Monitoring

Sustainment Plans must be reviewed annually or when vendor conditions, regulatory requirements, or system usage materially change.

IT Security monitors vendor notices for EOL/EOS events and critical vulnerabilities.

Back to top

Records & Retention

Sustainment Plans, vendor roadmaps, approvals, and review records must be stored in approved repositories.

Records are retained for a minimum of seven (7) years.

Back to top

Metrics & KPIs

  • Percentage of acquisitions with completed Sustainment Plans
  • Number of systems operating past vendor EOL/EOS
  • Frequency of missed upgrades due to sustainment gaps
  • Percentage of High‑risk systems with CISO‑approved sustainment

Back to top

  • KU SRM 01 – Supplier Risk Management Policy
  • KU SRM 02 – Procurement Policy
  • KU SEC 10 – Governance Precedence Policy
  • KU SEC 05 – Exception Management Policy
  • KU IT 01 – Asset Management Policy

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.