Kean University IT 01 – Asset Management Policy (Staff‑Facing)
Table of Contents
- 1. Purpose
- 2. Who Must Follow This Policy
- 3. What Assets Are Covered
- 4. Staff Responsibilities
- 5. Security Requirements
- 6. Maintenance and Support
- 7. Annual Audits
- 8. Asset Disposal
- 9. Compliance & Enforcement
- 10. Exceptions
- 11. Related Documents
1. Purpose
This policy describes how Kean University staff must handle University‑owned equipment and digital resources. It ensures all assets—such as laptops, desktops, mobile devices, software, cloud services, and departmental equipment—are properly issued, tracked, secured, maintained, and disposed of according to required standards.
2. Who Must Follow This Policy
This policy applies to:
- All Kean University employees
- Contractors and vendors using University‑owned equipment
- Any individual assigned, storing, transporting, or using University assets
3. What Assets Are Covered
Covered assets include all items owned, leased, or managed by the University, including:
- Computers (laptops, desktops, tablets)
- Servers, networking, and telecommunications equipment
- Software licenses, cloud services, and digital platforms
- Peripherals (monitors, keyboards, printers, accessories)
- Furniture and specialized departmental equipment
- Digital assets that require licensing or access permissions
Asset Categories
- Critical Assets: Essential systems such as servers or research equipment
- Sensitive Assets: Devices storing confidential or regulated data
- General Assets: Standard equipment with lower risk
4. Staff Responsibilities
4.1 When You Receive an Asset
- Assets must be issued only through the University’s official onboarding process.
- All devices will be tagged, recorded, and configured before staff receives them.
- Requests for non‑standard equipment require approval from the Director of OCAP.
4.2 Using and Caring for University Assets
Staff must:
- Take reasonable care of assigned equipment.
- Use University assets only for authorized business purposes.
- Follow required IT security configurations and controls.
- Report damaged, lost, stolen, or malfunctioning equipment to IT immediately.
4.3 Transfers or Location Changes
- Notify IT if an asset is moved or reassigned so inventory records remain accurate.
- Do not informally swap assets with coworkers.
- Do not relocate equipment between campuses without prior approval.
5. Security Requirements
5.1 Vulnerability Scanning
IT performs routine security scanning:
- Critical & Sensitive Assets: Monthly authenticated scans
- General Assets: Quarterly scans
Remediation timelines:
- Critical severity: 7 days
- High severity: 14 days
- Medium severity: 30 days
- Low severity: During standard maintenance cycles
Repeated issues or missed remediations may be escalated to the University’s Risk Management function.
6. Maintenance and Support
- Report all technical issues to IT using official support channels.
- Technicians will perform updates, repairs, and configuration changes as needed.
- Major system changes must follow the University’s Change Management Policy.
- Departments must plan for technology upgrades when devices reach end‑of‑support.
7. Annual Audits
During annual asset audits, staff may be asked to:
- Confirm possession and exact location of assigned equipment
- Assist with physical or digital verification
- Return equipment temporarily for review or configuration checks
8. Asset Disposal
- IT will securely wipe or destroy data following legal and regulatory requirements.
- Staff may not discard, donate, or repurpose equipment independently.
- All disposal follows environmental and information security standards.
9. Compliance & Enforcement
Failure to follow this policy may result in:
- Loss of equipment access
- Departmental purchasing holds
- Disciplinary action, up to and including termination
- Regulatory or legal consequences if misuse causes data exposure or loss
10. Exceptions
Exceptions must:
- Follow KU SEC 05 – Exception Management Policy
- Include a risk analysis and compensating controls
- Be approved by the CISO and Governance, Risk & Compliance (GRC)
- Not exceed 12 months
11. Related Documents
- RC01 – Policy Standard
- KD SEC 10 – Policy Governance
- New Device Onboarding SOP
- Change Management Policy
- Procurement Policy
- Risk Management Policy
``