Kean University IT Asset Management Lifecycle – Operational Procedure
Table of Contents
- About This Procedure
- Scope
- Roles and Responsibilities
- Asset Management Lifecycle
- NIST CSF 2.0 Mapping
- Metrics and Key Performance Indicators
- Required Records and Storage Locations
- Revision History
About This Procedure
This Standard Operating Procedure (SOP) defines the operational controls for acquiring, tracking, maintaining, auditing, transferring, and disposing of information technology (IT) assets at Kean University. It supports compliance with the Kean University IT Asset Management Policy and ensures assets are managed securely throughout their lifecycle.
Scope
This procedure applies to all university-owned or university-managed physical and digital IT assets, including hardware, software, and cloud-based resources.
Roles and Responsibilities
- Lifecycle Manager: Maintains asset records, performs audits, and ensures compliance.
- Help Desk: Tags assets and records asset assignments.
- Technicians: Configure, maintain, and remediate assigned assets.
- Users: Exercise proper care of assigned assets and report issues or loss promptly.
Asset Management Lifecycle
1. Acquisition and Onboarding
- All assets must be approved through the university procurement process.
- Each device is tagged and recorded in the asset management system.
- A security baseline configuration is applied before the asset is released for use.
2. Classification and Assignment
- Assets are classified as Critical, Sensitive, or General.
- Each asset is assigned to a user or department with a documented business purpose.
3. Maintenance and Vulnerability Management
- Critical and Sensitive assets are vulnerability scanned monthly.
- General assets are vulnerability scanned quarterly.
- Identified issues are remediated according to severity-based service level agreements (SLAs).
4. Auditing
- An annual inventory audit is required.
- Any discrepancies are investigated, documented, and resolved.
5. Transfer and Disposal
- All asset transfers are logged in the asset management system.
- Asset disposal requires secure data wiping and proper documentation.
NIST Cybersecurity Framework (CSF) 2.0 Mapping
- Identify: ID.AM (Asset Management)
- Protect: PR.AC (Access Control), PR.DS (Data Security)
- Recover: RC.IM (Improvements)
Metrics and Key Performance Indicators
- Asset inventory accuracy rate
- Vulnerability scan compliance rate
- Disposal documentation completeness
Required Records and Storage Locations
- Asset records: Asset Management System
- Disposal certificates: Scrut.io
Revision History
- Version 1.0: Initial operational release
``