IT Asset Management: Computers, Tablets & Software
This policy defines the standardized lifecycle management of all information technology assets—computers, tablets, and software—to ensure operational efficiency, data security, regulatory compliance, and cost control across the organization.
All company-owned computers, tablets, and software licenses must be tracked from procurement through disposal. This policy establishes uniform standards for hardware specifications, software licensing compliance, physical and digital security, inventory audits, and end-of-life procedures. It applies to all full-time, part-time, and contract personnel who are issued or handle IT assets.
This policy covers all IT assets owned or leased by the company, including desktops, laptops, tablets, smartphones issued as work devices, and all commercial and bespoke software. It applies to every department and all employees, contractors, and third-party vendors accessing company systems. Hardware assets under $500 or software subscriptions with an annual cost below $1,000 are scoped under simplified tracking procedures defined in Appendix B.
- All hardware and software acquisitions must be pre-approved through the IT Asset Request form. Standardized device models are defined in the Approved Hardware Matrix. Any deviation requires VP-level sign-off.
- Every asset must be registered in the central IT Asset Management (ITAM) database within 24 hours of receipt. Required fields: asset tag, serial number, user assignment, purchase date, warranty expiration.
- Encryption (BitLocker/FileVault) and antivirus must be enabled on all endpoints. Software installations are restricted to the company managed deployment tool; self-installation is prohibited without an exemption.
- Physical and digital audits are conducted quarterly. Any unregistered asset or discrepancy must be reported within 5 business days. Non-compliance may result in disciplinary action.
- At end-of-life, all data must be securely wiped using DoD 5220.22-M standards. Hardware must be returned to IT for decommissioning and disposal via certified e-waste recyclers.
- IT Department: Maintain the ITAM database, enforce encryption and security baselines, conduct quarterly audits, manage procurement, and oversee decommissioning.
- Department Managers: Approve asset requests for their teams, ensure employees return equipment upon departure, and report lost or damaged equipment within 48 hours.
- Employees & Contractors: Use issued devices solely for company business, protect assets from theft or damage, and immediately report any security incidents or malfunctions.
- Procurement: Ensure all purchases include warranty, maintenance, and software license terms; coordinate with IT on standardized hardware orders.