Kean University SOP 14 – Lifecycle Sustainment Planning
Table of Contents
- About
- Scope
- Definitions
- Roles & Responsibilities
- Procedure
- Review & Monitoring
- Records & Retention
- Metrics & KPIs
- Related Policies
About
This Standard Operating Procedure (SOP) establishes the required process for evaluating, documenting, and maintaining lifecycle sustainment plans for University acquisitions.
Lifecycle sustainment planning ensures that systems, software, services, and equipment remain supported, secure, and financially viable throughout their operational lifespan.
Scope
This SOP applies to acquisitions that:
- Introduce IT systems, software, or cloud services
- Rely on third‑party support or vendor roadmaps
- Require licensing, maintenance, or subscription renewals
- Impact data security, compliance, or institutional continuity
- Are funded by University or grant resources
Sustainment planning applies during onboarding, renewal, ongoing operation, and offboarding.
Definitions
- Lifecycle Sustainment: Planning for long‑term support, maintenance, and viability.
- End of Life (EOL): When a vendor no longer supports a product.
- End of Support (EOS): When security patches or updates cease.
- Sustainment Plan: Document outlining costs, upgrades, responsibilities, and risks.
- Sustainment Risk: Risk of obsolescence, insecurity, or lack of funding.
Roles & Responsibilities
View roles
- Procurement Lead: Ensures sustainment planning is completed and documented.
- Business Owner: Defines operational sustainment needs and continuity plans.
- Risk Manager: Evaluates sustainment risks and updates the Risk Register.
- Information Technology (IT) Security: Reviews security implications of EOL/EOS.
- Finance: Confirms long‑term funding and budget viability.
- Chief Information Security Officer (CISO): Approves sustainment plans for High or Critical systems.
Procedure
1. Determine Sustainment Requirements
Procurement identifies whether a Sustainment Plan is required (default: required for all IT, software, cloud, and operational‑critical acquisitions).
2. Gather Vendor Lifecycle Information
Vendor documentation is collected, including support models, patch cycles, upgrade schedules, and EOL/EOS timelines.
3. Develop the Sustainment Plan
The Business Owner documents costs, renewal cycles, staffing needs, upgrade requirements, and contingency planning using the approved sustainment template.
4. Risk & Financial Review
Risk Management evaluates sustainment risks, while Finance confirms funding beyond the initial acquisition period.
Review & Monitoring
Sustainment Plans must be reviewed annually or when vendor conditions, regulatory requirements, or system usage materially change.
IT Security monitors vendor notices for EOL/EOS events and critical vulnerabilities.
Records & Retention
Sustainment Plans, vendor roadmaps, approvals, and review records must be stored in approved repositories.
Records are retained for a minimum of seven (7) years.
Metrics & KPIs
- Percentage of acquisitions with completed Sustainment Plans
- Number of systems operating past vendor EOL/EOS
- Frequency of missed upgrades due to sustainment gaps
- Percentage of High‑risk systems with CISO‑approved sustainment
Related Policies
- KU SRM 01 – Supplier Risk Management Policy
- KU SRM 02 – Procurement Policy
- KU SEC 10 – Governance Precedence Policy
- KU SEC 05 – Exception Management Policy
- KU IT 01 – Asset Management Policy
``