This site requires JavaScript to be enabled

Technology Asset Management Policy

202 views

11.0 - Last modified on 09-09-2026 Revised by Joseph Casciano

10.0 - Last modified on 02-10-2026 Revised by Joseph Casciano

9.0 - Last modified on 09-04-2025 Revised by Joseph Casciano

8.0 - Last modified on 05-21-2025 Revised by Joseph Casciano

7.0 - Last modified on 11-26-2024 Revised by Joseph Casciano

6.0 - Last modified on 11-20-2024 Revised by Joseph Casciano

5.0 - Last modified on 11-20-2024 Revised by Joseph Casciano

4.0 - Last modified on 11-20-2024 Revised by Joseph Casciano

3.0 - Last modified on 11-20-2024 Revised by Joseph Casciano

2.0 - Last modified on 11-18-2024 Revised by Joseph Casciano

Policy Rationale and Scope

In order to comply with HMS Security Policies as well as applicable state and federal regulations Harvard Medical School must identify, catalog, and track any and all HMS Technology Assets to manage and mitigate risks associated with them. Effective HMS Technology Asset management requires complete coverage of the entire life cycle, including decommissioning and retirement when systems reach their end of life.

Technology Asset tracking, securing, managing, and reporting are also key requirements for all related federal compliance, associated grant funding agreements, and security/privacy frameworks. Furthermore, the management and securing of all HMS Technology Assets protects HMS data, systems, and the organization from reputational and financial loss.

The intended audience for this policy includes all HMS/HSDM-employed staff, faculty, researchers, contractors, and those conducting business/research on behalf of HMS or HSDM

Policy Statement

To maintain and sustain the required level of HMS Technology Asset compliance and assure security through rigorous asset management, HMS requires the following:

  • HMS Technology Assets must be inventoried, and tracked, including system function, custodian, business criticality, and location.
    • If a separate inventory is used that is not Service Now, it must be shared with HMS IT.

  • For the HMS Technology Assets that are inventoried, HMS IT must also record asset data classification level, and Business Criticality to support risk management analysis that is utilized within Business Continuity, Vulnerability Management, and Security Incident Response processes.

  • HMS IT will provide a service to identify HMS Technology Assets in the inventory that are reaching end of life to support proactive processes that reduce risk through decommissioning and replacement processes.

  • The management and securing of all HMS Technology Assets must be conducted via HMS Approved Standard Technologies. Any Exceptions must be approved by HMS CISO or designee(s).
  • HMS ISPR monitoring, and security systems must have at least view access into all HMS IT Approved Standard Technologies used for the management or securing of HMS Technology Assets.

  • All HMS Technology Assets that are no longer supported (including extended support) by their manufacturer will need to be decommissioned or prevented from accessing the HMS network until replaced with a supported version.

  • All HMS Technology Assets are the property of HMS and must be returned to the appropriate HMS IT or responsible unit individual upon an approved replacement of the asset, for required legal or security reasons, or upon an employee’s separation. Any exceptions must be approved by HMS CIO or designee(s).

  • Any HMS Technology Asset that has not been active or connected to the HMS network or any of the required HMS Technology Asset management and security systems, for over six months, will be considered out of compliance and therefore quarantined.
    • Before quarantining the device, the documented user(s) of that HMS Technology Asset will be contacted on a minimum of two separate occasions requesting specific actions to bring the HMS Technology Asset back into compliance.
    • The quarantined HMS Technology Asset may be released from quarantine once it is considered compliant with this policy.

  • Personal devices should not be used to store or transmit HMS data.
    • If personal devices are used to store or transmit HMS data, such devices must adhere to HMS security and privacy policies, including tracking, securing, and complying with data wipe procedures.
    • If personal devices are used to store or transmit HMS data, Harvard or HMS may request access to the device, and the device owner must provide the requested access.

  • Any HMS Technology Asset that is reported to be stolen, lost, or is not returned to the appropriate HMS individual or department upon request may be quarantined, locked, or wiped by HMS IT depending on the HMS Technology Asset’s level of criticality and specific identified risk to HMS. All data on a wiped device will be deleted and unrecoverable.

Roles and Responsibilities

System Administrators:

System Administrator refers to a role fulfilling the function of ensuring devices (aka systems) are patched, properly configured, and assigned to the intended user. A System Administrator is also responsible for ensuring the device/system is recovered and either destroyed or wiped once its lifecycle comes to an end.

Important note: If a device/system does not have such a responsible individual, HMS IT will be required to assume management of the device and become its System Administrator.

  • System administrators throughout HMS IT, HSDM, and HMS Distributed IT are responsible for documenting, tracking, and updating asset inventory for systems under their area of responsibility.
    • All such documenting and tracking systems must be from the HMS Approved Standard Technologies list.
  • are also responsible for ensuring HMS ISPR has access to view such inventories.
  • are also responsible for ensuring the relevant HMS IT Approved Standard Technologies are used to manage and secure assets.
  • are responsible for the technology asset’s lifecycle including but not limited to, decommissioning, and replacing technology assets when they become end of life (EOL).

HMS Information Security, Privacy, Risk Management, and IAM(ISPR):

  • Responsible for monitoring, collecting, aggregating, and maintaining all HMS Technology Asset information required for security and privacy purposes.
  • Is also responsible for ensuring the list of HMS Approved Standard Technologies is up-to date and available to all HMS.
  • Is also responsible for securing all HMS Technology Assets, regardless of what individual, unit, project, team, or division is managing the HMS Technology Asset.

HMS IT Service Management (ITSM):

  • Responsible for maintaining the system that tracks and stores general asset information.

Definitions

Custodian: The Custodian of a device is the individual assigned to the device by HMS IT or unit IT. The Custodian of a device is responsible for the safekeeping and proper use of the device.

HMS Technology Asset: Any hardware or software that is:

  • on-premises/on HMS network or not (i.e. in the cloud)
    and
  • is purchased by HMS, HMS leased, or gifted to HMS.
  • or neither but stores or transmits HMS data (including HMS research data).

*Whether used for research or non-research purposes.
*Including any laptop, desktop, server connected or instrumentation (such as microscopes, freezers, or other network-attached hardware).
*An HMS Technology Asset is the same as an HMS Technology Device.

HMS IT Approved Standard Technologies: A set of Standard technologies reviewed by a designated working group of relevant SMEs, approved by the proper HMS Committee, approved by the HMS CISO or CIO, and published on the HMS IT Technology Standards site.

IAM: Identity and Access Management.

ISPR: Information Security, Privacy, Risk management.

Harvard Data Security levels: May be found at the Harvard Information Security Policy Site

Decommissioning: standard process to decommission technology assets (due to damage/ loss/ theft/ End-of-Life/End-of-Service) as per institutional policy, legal, or environmental requirements.

Cloud: Systems managed by a hosting provider. These systems fall into the following categories

  • Infrastructure as a Service (IAAS): Cloud Service Providers (CSP) such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) provide access to Operating System level services making it possible to create individual systems to perform any number of functions.
  • Software as a Service (SAAS): Applications that are hosted and managed by the vendor, such as Google G-Suite, Microsoft 365, etc. These are multi-tenant applications that provide specific applications and store data within their infrastructure.
  • Platform as a Service (PAAS): Vendors in this category provide an extensible platform that can be customized by the customer to fit their needs. Examples include Salesforce and ServiceNow.

Business Criticality Levels: Refers to the importance of an asset to the business. Criticality levels are defined by the business. Assets and services with the highest level of criticality will have redundant, or backup, methods for ensuring that the asset or service is available close to 100% of the time. For example, electrical power may be considered to be at a critical level to support operations of certain systems. Mitigations and backups can include battery power, and generator power to keep certain critical operations functioning during a power event.

End of Life (EoL): technology assets for which a vendor no longer supports, or that have reached the end of the product lifecycle which prevents receiving security or system updates, indicates that the product is at the end of its useful life. A device may reach its EoL but remain functional with a valid and approved exception, in rare occasions.

On-premises: On-premises or On-prem refers to IT infrastructure hardware and software applications that are hosted at a location that is owned or rented by Harvard or HMS.

Review Period

This policy will be reviewed annually and updated as needs change.

Related Resources

Revision History

  • August 11, 2023 – Initial Draft
  • May 8, 2023 - Final Draft, pre SPC review
  • September 19, 2024 – Final SPC review
  • October 31, 2024 – V2 Follow up edits made to address comments from the information security governance committee
  • November 12, 2024 – SPC approved

Additional information

  • HMS Primary Responsible Office: HMS ISPR
  • Approval Body: HMS CISO, HMS CIO
  • Version Number: V2
  • Original Approval Date: November 12, 2024
  • Effective Date: January 1, 2025
  • Revision Date: October 31, 2024
  • Subject Area: Device and Asset Management
  • Key Contact: Michael Sardaryzadeh
  • Security Permissions: HMS IT