Kean University New Device Onboarding SOP


Kean University New Device Onboarding Procedure

Table of Contents

About This SOP

This Standard Operating Procedure (SOP) establishes consistent requirements for receiving, configuring, securing, documenting, and releasing new University‑owned devices before they are placed into service. The goal is to reduce security risk, ensure accurate asset tracking, and align device handling with Kean University’s Asset Management practices.

Back to top

Scope

This SOP applies to all University‑owned or University‑managed computing devices, including laptops, desktops, tablets, servers, and specialized information technology equipment.

Back to top

Key Definitions

  • Baseline Configuration: The minimum required security configuration approved by Information Security.
  • Asset Tag: A unique physical identifier assigned to a device for inventory tracking.
  • Lifecycle Manager: The role responsible for governance and oversight of asset records throughout the device lifecycle.

Back to top

Roles & Responsibilities

  • Procurement: Ensures devices are purchased through approved University channels.
  • Lifecycle Manager: Oversees asset record creation and confirms compliance with onboarding requirements.
  • Help Desk / Technicians: Perform asset tagging, system configuration, validation, and setup.
  • Information Security: Defines and approves baseline security requirements.
  • End User: Accepts the device and acknowledges responsibility for appropriate use.

Back to top

Onboarding Procedures

View step-by-step device onboarding process

1. Device Receipt

  • The device is received by IT or an authorized department.
  • Shipment details are verified against procurement records.
  • The device remains secured and unused prior to onboarding.

2. Asset Registration & Tagging

  • An asset tag is physically affixed to the device.
  • An asset record is created in the Asset Management System.
  • The record includes device type, serial number, department, intended user (if known), and asset classification (Critical, Sensitive, or General).

3. Baseline Security Configuration

  • An approved operating system is installed or validated.
  • Required security controls are applied, including endpoint protection, disk encryption, patch updates, and logging or monitoring agents.
  • Configuration aligns with standards approved by Information Security.

4. Validation & Quality Check

  • The technician validates completion of the configuration checklist.
  • Device functionality is tested.
  • Any deviations are documented and resolved before release.

5. Assignment & Release

  • The device is formally assigned to a user or department.
  • User acknowledgment is recorded.
  • The asset record is updated to an “In Service” status.

Back to top

  • KU IT 01 – Asset Management Policy
  • Change Management Policy
  • Information Security Policy

Back to top

NIST CSF 2.0 Mapping

  • Identify: ID.AM (Asset Management)
  • Protect: PR.AC (Access Control), PR.DS (Data Security), PR.IP (Information Protection Processes)

Back to top

Metrics & KPIs

View device onboarding performance measures
  • Percentage of devices onboarded before first use
  • Configuration compliance rate
  • Time from device receipt to deployment

Back to top

Records & Storage

  • Asset records: Stored in the Asset Management System.
  • Configuration checklists: Stored in [Scrut.io – link to be provided].

Back to top

Document Control

  • Version: 1.0
  • Author: Asset Lifecycle Governance Lead
  • Approver: Chief Information Security Officer (CISO)
  • Effective Date: February 13, 2026
  • Review Cycle: Annual

Back to top

``

Was this answer helpful? Yes No

Sorry we couldn't be helpful. Help us improve this article with your feedback.