Policy Rationale
To comply with HMS Security Policies and applicable state and federal regulations, Harvard Medical School must identify, catalog, and track all HMS Technology Assets. This ensures risks associated with these assets are managed and mitigated. Effective management encompasses the entire lifecycle, including decommissioning and retirement at the end of life.
Technology Asset tracking, securing, managing, and reporting are essential for federal compliance, associated grant funding agreements, and security/privacy frameworks. Securing all HMS Technology Assets protects HMS data, systems, and the organization from reputational and financial loss.
Policy Statement
To sustain HMS Technology Asset compliance and security, the following is required:
-
Inventory and Tracking:
-
HMS Technology Assets must be inventoried and tracked, including system function, custodian, business criticality, and location.
-
If a separate inventory system is used (not ServiceNow), it must be shared with HMS IT.
-
-
Data Classification and Risk Management:
-
HMS IT must record asset data classification levels and business criticality to support risk management processes within business continuity, vulnerability management, and security incident response.
-
-
End-of-Life Identification:
-
HMS IT will identify Technology Assets nearing end-of-life and facilitate risk-reduction through decommissioning and replacement.
-
-
Approved Standard Technologies:
-
All management and security activities must use HMS Approved Standard Technologies. Exceptions require approval by the HMS CISO or designee(s).
-
-
Monitoring and Security Access:
-
HMS ISPR monitoring and security systems must have view access into all HMS IT Approved Standard Technologies.
-
-
End-of-Life Assets:
-
Unsupported assets must be decommissioned or removed from the HMS network until replaced with a supported version.
-
-
Asset Return:
-
HMS Technology Assets are HMS property and must be returned to HMS IT or the responsible unit upon replacement, for legal or security reasons, or when an employee separates. Exceptions require HMS CIO or designee(s) approval.
-
-
Inactive Assets:
-
Any Technology Asset inactive or unconnected to the HMS network for over six months is out of compliance and may be quarantined.
-
Before quarantining, the user will be contacted at least twice to resolve compliance.
-
Quarantined assets may be released upon achieving compliance.
-
-
-
Lost or Stolen Assets:
-
HMS IT may quarantine, lock, or wipe devices reported stolen or lost, based on criticality and risk. Wiped data is unrecoverable.
-
Roles and Responsibilities
System Administrators:
-
Ensure devices are patched, configured, assigned, recovered, and securely decommissioned at the end of life.
-
Maintain asset inventory using HMS Approved Standard Technologies.
-
Provide HMS ISPR with view access to inventories.
-
Use HMS IT Approved Standard Technologies for management and security.
HMS ISPR:
-
Monitor, collect, and maintain HMS Technology Asset data for security and privacy purposes.
-
Maintain the list of HMS Approved Standard Technologies.
-
Secure all HMS Technology Assets regardless of ownership or management.
HMS IT Service Management (ITSM):
-
Maintain systems for tracking and storing general asset information.
Definitions
-
Custodian: Individual assigned responsibility for safekeeping and proper use of a device.
-
HMS Technology Asset: Any hardware or software purchased, leased, or gifted to HMS, or storing/transmitting HMS data, including research equipment.
-
HMS IT Approved Standard Technologies: Technologies approved for asset management and security, listed on the HMS IT Technology Standards site.
-
Decommissioning: Process of removing technology assets from active use in compliance with institutional, legal, or environmental standards.
Review Period
This policy will be reviewed annually and updated as needed.
Related Resources
Revision History
- August 18, 2021: Initial Draft
- December 7, 2021: Draft V2 ready for committee approval
- December 8, 2021: Draft V3 with committee input
- December 13, 2021: V1.0 finalized after committee review
- August 25, 2022: Added link to HMS IT policy – Roles and Responsibilities
- August 11, 2023: Reviewed and edited
- May 8, 2023: Final draft pre-SPC review
- September 19, 2024: Final SPC review
- October 31, 2024: V2 updated per governance committee comments
Additional information
- HMS Primary Responsible Office: HMS ISPR
- Approval Body: HMS CISO, HMS CIO
- Version Number: V2
- Effective Date: January 1, 2025
- Revision Date: October 31, 2024
- Applicable To: HMS IT staff and contractors
- Subject Area: Device and Asset Management
- Key Contact: Michael Sardaryzadeh
- Security Permissions: HMS IT