Kean University New Device Onboarding Procedure
Table of Contents- About This SOP
- Scope
- Key Definitions
- Roles & Responsibilities
- Onboarding Procedures
- Related Policies & Standards
- NIST CSF 2.0 Mapping
- Metrics & KPIs
- Records & Storage
- Document Control
About This SOP
This Standard Operating Procedure (SOP) establishes consistent requirements for receiving, configuring, securing, documenting, and releasing new University‑owned devices before they are placed into service. The goal is to reduce security risk, ensure accurate asset tracking, and align device handling with Kean University’s Asset Management practices.
Scope
This SOP applies to all University‑owned or University‑managed computing devices, including laptops, desktops, tablets, servers, and specialized information technology equipment.
Key Definitions
- Baseline Configuration: The minimum required security configuration approved by Information Security.
- Asset Tag: A unique physical identifier assigned to a device for inventory tracking.
- Lifecycle Manager: The role responsible for governance and oversight of asset records throughout the device lifecycle.
Roles & Responsibilities
- Procurement: Ensures devices are purchased through approved University channels.
- Lifecycle Manager: Oversees asset record creation and confirms compliance with onboarding requirements.
- Help Desk / Technicians: Perform asset tagging, system configuration, validation, and setup.
- Information Security: Defines and approves baseline security requirements.
- End User: Accepts the device and acknowledges responsibility for appropriate use.
Onboarding Procedures
View step-by-step device onboarding process
1. Device Receipt
- The device is received by IT or an authorized department.
- Shipment details are verified against procurement records.
- The device remains secured and unused prior to onboarding.
2. Asset Registration & Tagging
- An asset tag is physically affixed to the device.
- An asset record is created in the Asset Management System.
- The record includes device type, serial number, department, intended user (if known), and asset classification (Critical, Sensitive, or General).
3. Baseline Security Configuration
- An approved operating system is installed or validated.
- Required security controls are applied, including endpoint protection, disk encryption, patch updates, and logging or monitoring agents.
- Configuration aligns with standards approved by Information Security.
4. Validation & Quality Check
- The technician validates completion of the configuration checklist.
- Device functionality is tested.
- Any deviations are documented and resolved before release.
5. Assignment & Release
- The device is formally assigned to a user or department.
- User acknowledgment is recorded.
- The asset record is updated to an “In Service” status.
Related Policies & Standards
- KU IT 01 – Asset Management Policy
- Change Management Policy
- Information Security Policy
NIST CSF 2.0 Mapping
- Identify: ID.AM (Asset Management)
- Protect: PR.AC (Access Control), PR.DS (Data Security), PR.IP (Information Protection Processes)
Metrics & KPIs
View device onboarding performance measures
- Percentage of devices onboarded before first use
- Configuration compliance rate
- Time from device receipt to deployment
Records & Storage
- Asset records: Stored in the Asset Management System.
- Configuration checklists: Stored in [Scrut.io – link to be provided].
Document Control
- Version: 1.0
- Author: Asset Lifecycle Governance Lead
- Approver: Chief Information Security Officer (CISO)
- Effective Date: February 13, 2026
- Review Cycle: Annual
``