KU IT 01 - Asset Management Policy


Kean University IT 01 – Asset Management Policy (Staff‑Facing)

Table of Contents

1. Purpose

This policy describes how Kean University staff must handle University‑owned equipment and digital resources. It ensures all assets—such as laptops, desktops, mobile devices, software, cloud services, and departmental equipment—are properly issued, tracked, secured, maintained, and disposed of according to required standards.

Back to top

2. Who Must Follow This Policy

This policy applies to:

  • All Kean University employees
  • Contractors and vendors using University‑owned equipment
  • Any individual assigned, storing, transporting, or using University assets

Back to top

3. What Assets Are Covered

Covered assets include all items owned, leased, or managed by the University, including:

  • Computers (laptops, desktops, tablets)
  • Servers, networking, and telecommunications equipment
  • Software licenses, cloud services, and digital platforms
  • Peripherals (monitors, keyboards, printers, accessories)
  • Furniture and specialized departmental equipment
  • Digital assets that require licensing or access permissions

Asset Categories

  • Critical Assets: Essential systems such as servers or research equipment
  • Sensitive Assets: Devices storing confidential or regulated data
  • General Assets: Standard equipment with lower risk

Back to top

4. Staff Responsibilities

4.1 When You Receive an Asset

  • Assets must be issued only through the University’s official onboarding process.
  • All devices will be tagged, recorded, and configured before staff receives them.
  • Requests for non‑standard equipment require approval from the Director of OCAP.

4.2 Using and Caring for University Assets

Staff must:

  • Take reasonable care of assigned equipment.
  • Use University assets only for authorized business purposes.
  • Follow required IT security configurations and controls.
  • Report damaged, lost, stolen, or malfunctioning equipment to IT immediately.

4.3 Transfers or Location Changes

  • Notify IT if an asset is moved or reassigned so inventory records remain accurate.
  • Do not informally swap assets with coworkers.
  • Do not relocate equipment between campuses without prior approval.

Back to top

5. Security Requirements

5.1 Vulnerability Scanning

IT performs routine security scanning:

  • Critical & Sensitive Assets: Monthly authenticated scans
  • General Assets: Quarterly scans

Remediation timelines:

  • Critical severity: 7 days
  • High severity: 14 days
  • Medium severity: 30 days
  • Low severity: During standard maintenance cycles

Repeated issues or missed remediations may be escalated to the University’s Risk Management function.

Back to top

6. Maintenance and Support

  • Report all technical issues to IT using official support channels.
  • Technicians will perform updates, repairs, and configuration changes as needed.
  • Major system changes must follow the University’s Change Management Policy.
  • Departments must plan for technology upgrades when devices reach end‑of‑support.

Back to top

7. Annual Audits

During annual asset audits, staff may be asked to:

  • Confirm possession and exact location of assigned equipment
  • Assist with physical or digital verification
  • Return equipment temporarily for review or configuration checks

Back to top

8. Asset Disposal

  • IT will securely wipe or destroy data following legal and regulatory requirements.
  • Staff may not discard, donate, or repurpose equipment independently.
  • All disposal follows environmental and information security standards.

Back to top

9. Compliance & Enforcement

Failure to follow this policy may result in:

  • Loss of equipment access
  • Departmental purchasing holds
  • Disciplinary action, up to and including termination
  • Regulatory or legal consequences if misuse causes data exposure or loss

Back to top

10. Exceptions

Exceptions must:

  • Follow KU SEC 05 – Exception Management Policy
  • Include a risk analysis and compensating controls
  • Be approved by the CISO and Governance, Risk & Compliance (GRC)
  • Not exceed 12 months

Back to top

  • RC01 – Policy Standard
  • KD SEC 10 – Policy Governance
  • New Device Onboarding SOP
  • Change Management Policy
  • Procurement Policy
  • Risk Management Policy

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.