Systems, hardware, software, services, and data are managed throughout their life cycles
Assets that are not properly retired become liabilities. End-of-life software stops receiving security patches, decommissioned servers left running get forgotten, and orphaned SaaS accounts retain access long after the employee leaves. Lifecycle management closes these gaps by ensuring every asset has a defined path from acquisition through secure disposal.
Implementation steps
- 1
Define lifecycle stages and responsibilities
Document the stages each asset type goes through: request and approval, acquisition or provisioning, active use and maintenance, and retirement or disposal. Assign a responsible role for each transition, for example the IT team for hardware disposal and the application owner for software decommission.
servicenowjira - 2
Implement acquisition controls
Require approval before purchasing or provisioning new hardware, software, or cloud services. Check that the item is on the approved list and that security requirements (encryption, patching cadence, supported versions) are met before deployment. Track the acquisition date in the asset inventory.
servicenowsnykdependabot - 3
Enforce retirement and disposal procedures
When an asset reaches end of life: revoke access and credentials, wipe or physically destroy storage media per NIST 800-88 guidance, remove the asset from the inventory, and document the disposal method and date. For cloud resources, terminate or delete rather than simply stop. Archive any data required for legal or compliance holds before deletion.
blanccojamfmicrosoft-intunekandji
Evidence required
Lifecycle management policy or procedure
A written procedure describing each lifecycle stage, who is responsible, and the steps required at acquisition, change, and disposal.
- · IT asset lifecycle policy document
- · Runbook or playbook for hardware decommission
- · SaaS onboarding and offboarding checklist
Disposal or decommission records
Records showing that assets were retired following the defined procedure, including data wiping and inventory removal.
- · Blancco or similar media sanitization certificate
- · Closed tickets showing decommission steps were completed
- · Asset inventory with a retired status column and dates
End-of-life software tracking
Evidence that software components past their vendor support date have been identified and remediated.
- · Dependency scan results showing EOL packages flagged
- · Ticket backlog tracking EOL operating systems for upgrade
- · Snyk or Dependabot report listing unsupported library versions
Related controls
Inventories of hardware assets are maintained
Asset Management
Inventories of software assets are maintained
Asset Management
Authorized network communication and data flow representations are maintained
Asset Management
Inventories of services provided by suppliers are maintained
Asset Management