Asset Management Standard (SFA 06-107.2.2)

Summary

Requirements for tracking and protecting SFA's technology assets across their life, from inventory and acceptable use through secure return, disposal, and reuse; supports Policy 06-107.2.

Body

Quick Overview
  • This standard sets the specific requirements for how SFA manages its assets: the hardware, software, media, and systems that hold university data, across their whole lifecycle.
  • It carries out the goals in the SFA 06-107.2 Information Security Technology Policy.
  • It applies to everyone who uses SFA information resources, but the requirements are carried out mostly by asset owners, IT staff, and security leadership.
  • These requirements are the minimum baseline SFA must meet; departments may do more, but never less.
  • Meeting this standard is mandatory unless a formal exception is granted.

An "asset" is anything SFA relies on to do its work with information: laptops, servers, phones, storage media, software licenses, and the systems that store university data. Asset management is the discipline of knowing what we have, protecting each item based on how sensitive it is, using it appropriately, and retiring it safely. This standard spells out what SFA must do at every stage of an asset's life: keep an accurate inventory and maintain it, protect assets according to their classification, govern acceptable use, and handle return, disposal, and reuse without exposing university data.

i
Policy vs. Standard
The matching policy (06-107.2) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.

Who This Applies To

This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users of SFA information resources, including vendors, visitors, and contingent workers who work within SFA IT facilities. In practice, the requirements below are carried out mostly by the people who own, track, and maintain assets: asset owners and custodians, IT teams, Human Resources, Privacy Officers, and the CISO.

i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
  • CISO & Office of Information Security: Develop, implement, and maintain the asset management processes and procedures, covering inventory, maintenance, protection, classification, acceptable use, and disposal.
  • Asset Owners / Custodians: Identify, inventory, classify, and retire the assets in their care; set and enforce access controls based on how critical each asset is; and monitor usage and report security events.
  • Privacy Officers (PO): Make sure asset handling meets privacy, legal, and vendor obligations in user and vendor contracts.
  • IT Management / Teams: Maintain and enforce asset management processes and run the tools that identify, track, monitor, and report on assets.
  • Human Resources (HR): Provide timely, accurate employee information (including separations) so assets can be collected and reassigned properly.
Full role definitions Complete responsibilities for each role are in the attached standard PDF.

What This Standard Requires

The requirements are grouped into four areas that follow an asset's lifecycle. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.2.2.1.1) are shown so you can match them to the attached PDF.

1  Inventory & Maintenance of Assets  Knowing what we have ⌄

SFA must keep an accurate, current record of its assets and keep looking for anything that is missing from that record.

  • Keep an accurate, up-to-date inventory of SFA-owned and leased assets, covering all assets in the necessary systems and IT facilities, at the level of detail needed for tracking and reporting (may capture type, tag or ID number, location, owner, status, serial number, service contracts, end-of-life status, and configuration) (06-107.2.2.1.1).
  • Review and update the inventory at least once every 24 months, or sooner when assets are installed, decommissioned, changed, or reassigned to a new owner (06-107.2.2.1.2).
  • Regularly run asset discovery (manual or automated) to scan networks and IT facilities for assets not yet in the inventory (06-107.2.2.1.3).
  • Define an asset classification and rating scale using a risk-based approach, judging assets by confidentiality, integrity, availability, regulatory and compliance needs, data classification, and end-of-life status (06-107.2.2.1.4).
2  Asset Management & Protection  Guarding assets by how sensitive they are ⌄

SFA must protect assets in proportion to their classification, and keep tight control of them, especially critical assets and anything leaving SFA premises.

  • Apply protections to assets (digital and non-digital media) based on their classification, such as access controls, physical security, backup and recovery methods, and software or firewall protections (06-107.2.2.2.1).
  • Restrict and log physical and logical access attempts for critical assets, using manual or automated mechanisms (06-107.2.2.2.2).
  • Protect and control assets when they travel outside SFA-controlled areas: secure transport, only authorized and scheduled moves, only authorized people, encryption of the data on them, and before-and-after inventories to catch theft or loss (06-107.2.2.2.3).
  • Keep the system component inventory current, complete, and accurate with automated tools, assign each component to a system, and get the responsible owner or custodian to acknowledge that assignment (06-107.2.2.2.5).
  • Identify and document the custodians accountable for digital and non-digital media during transport outside controlled areas, and keep that accountability throughout the trip (06-107.2.2.2.6).
3  Acceptable Use of Assets  Using assets the right way ⌄

SFA must prevent misuse of its assets and software, and keep certain risky or banned technologies off its networks.

  • Prevent misuse of SFA assets: use them only for their intended business purpose, track their use, keep only the number of assets (such as software licenses) actually needed, perform regular maintenance, and work with Privacy Officers on the correct usage terms in user and vendor contracts (06-107.2.2.3.1).
  • Define rules and procedures for software use: limits and guidance on user installs, license access based on user privileges, labeling and inventorying to confirm proper use, proper renewal or termination when licenses expire, and removing software once it is no longer needed (06-107.2.2.3.2).
  • Maintain a list or process of restricted or prohibited assets, at a minimum prohibiting unapproved or ownerless assets, assets with unauthorized hardware or software, and any technology banned by the Texas Department of Information Resources (06-107.2.2.3.3).
4  Return, Disposal, & Reuse of Assets  Retiring assets safely ⌄

When an asset is returned, retired, or reused, SFA must recover it, wipe its data securely, and record what happened.

  • Collect SFA-owned assets from users as part of the HR separation and offboarding process, and decommission and physically remove assets at the end of their life or when no longer needed, within defined timeframes (06-107.2.2.4.1).
  • Securely delete (sanitize) SFA data on assets before disposal, transfer out of SFA control, or reuse, using approved methods with strength matched to the asset's classification and record-retention rules (06-107.2.2.4.2).
  • Return decommissioned assets to the provider, or dispose of them properly following SFA disposal processes and any applicable contracts or grants (06-107.2.2.4.3).
  • Set restrictions and processes for internal reuse and external release: sanitize the asset first, update its details in the inventory before it goes back into service, and perform any maintenance or new controls the new use requires (06-107.2.2.4.4).
  • Review, approve, track, verify, and update asset status in the inventory after sanitization, return, removal, or reuse, and keep a sanitization record (date, item description and serial number, inventory number, method used, and where the equipment went) with the Records Management Officer (06-107.2.2.4.5).
!
Important
Disposing of SFA assets must be done by the appropriate Information Security or IT staff and management. Individual users must not dispose of SFA assets on their own.

Conformance & Exceptions

Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely cannot be met and there is no workable fix, follow the exception process in the SFA 06-107.2 Information Security Technology Policy; requests go to the SFA Chief Information Security Officer (CISO).

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section unless they need control references.

Frameworks & control references ⌄

The requirements in this standard map to one or more of these authoritative sources:

  • NIST 800-53 Rev 5.1.1, for example the CM (Configuration Management), MP (Media Protection), PM, RA, PS, and SR control families.
  • TAC 202, for example 202.71, 202.72, and 202.74.
  • Texas DIR Security Controls Catalog (for example CM-8, MP-2, MP-5, MP-6, PM-5), the DIR Data Classification Guide, and DIR Prohibited Technologies.
  • NIST CSF (for example the ID.AM asset-management category) and NIST 800-171 (for example the 3.4 and 3.8 requirement families).
  • UTS 165, and privacy and regulatory frameworks (GDPR, HIPAA, GLBA) where relevant.

The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

Supporting policy: SFA 06-107.2 Information Security Technology Policy

Related standards:

Other references:

  • SFA 06-107 Controls Crosswalk Reference
  • Texas DIR Data Classification Guide · Texas DIR Prohibited Technologies

Responsible office: Office of Information Security; Records Management Officer  ·  Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173930
Created
Thu 7/16/26 2:25 PM
Modified
Fri 7/17/26 12:16 PM

Related Articles

Related Articles (2)

Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Sets SFA's objectives for the technical safeguards that protect its systems, devices, and data, covering access, asset management, system development, continuity and disaster recovery, security monitoring, and incident response; carried out by Standards 06-107.2.1 through 06-107.2.6.