IT hardware does not last forever. A disciplined lifecycle - plan, procure, deploy, operate, refresh, dispose - keeps cost, security, and sustainability under control. This lesson maps each phase and the controls that belong there.
Six-Phase Lifecycle
Phase
Activities
Owner
Key Risk
Plan
Forecast demand, set standards
Architecture
Buying the wrong spec
Procure
Vendor selection, PO, receive
Procurement
Counterfeit or used as new
Deploy
Image, asset tag, place
IT Ops
Drift from gold image
Operate
Patch, monitor, replace parts
IT Ops
Unsupported firmware
Refresh
Decide reuse vs return vs retire
Finance + IT
Keeping kit past warranty
Dispose
Wipe, certify, e-waste
IT Ops + EHS
Data leak via discarded disk
Critical Controls Per Phase
**Plan** - Maintain an approved hardware standards list with model, lifespan, and total cost.
**Procure** - Buy only from authorized resellers; record serial numbers immediately.
**Deploy** - Apply BitLocker / FileVault / LUKS during provisioning, never after.
**Operate** - Patch firmware and BIOS, not just OS - rootkits live below the OS.
**Refresh** - Use a documented threshold (age + repair cost vs replacement).
**Dispose** - Issue a certificate of data destruction; pair with a chain-of-custody form.
Discussion
Loading…