UBC — AI Solutions

Audit — Dynamic Documentation Platform

Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.

Back to library
SOP
Fresh

SOP-SDLC-09 — Decommissioning

Retires services and their data safely, preserving records required by law and contract.

Owner: Platform Eng DirectorApprover: GRC LeadVersion: 1.6Updated: 10/13/1969

1. Purpose

Retire services and data with certainty, evidence, and no residual risk.

2. Scope

Any service, dataset, model, or piece of infrastructure being retired.

3. Definitions

  • Retention hold — A legal or regulatory requirement to keep data past normal retention.

4. Roles & Responsibilities (RACI)

ActivityRACICadence
Author decommissioning planService ownerPlatform Eng DirectorGRC, SecurityUsersPer retirement
Verify data handlingData ownerGRC LeadSecurityLegalPer retirement
Approve retirementProduct OwnerGRC LeadSecurity, SREUsersPer retirement

5. Procedure

  1. Publish a retirement notice to users at least 90 days in advance.
  2. Identify integrations and provide migration paths.
  3. Confirm records requirements and apply any retention holds.
  4. Securely dispose of data per NIST SP 800-88 (crypto-erase or purge).
  5. Remove infrastructure, IAM, DNS, and secrets.
  6. Archive the decommissioning package as evidence.

6. Inputs & Outputs

Inputs

  • Service inventory
  • Data classification
  • Legal hold register

Outputs

  • Decommissioning package
  • Data-disposal certificate

7. Controls & Metrics

MetricTarget
Decommissionings with disposal certificate100%
Orphan IAM after retirement0

8. Exceptions & Escalation

  • Legal hold overrides retention until the hold is lifted.

9. Records & Retention

RecordRetention
Decommissioning packages10 years
Disposal certificates10 years
  • SOP-QMS-07
  • Access Control Policy

11. References

  • ISO 27001 A.8.3
  • NIST SP 800-88 Rev.1

12. Revision History

See the Versions tab for the full change history maintained by the Auto-Doc Engine.


Document code: SOP-SDLC-09 · Aligned to ISO 27001 A.8.3 / NIST SP 800-88. Controlled document — reproduction outside the UBC QMS requires the Quality Manager's approval.

Suggested by AI
No suggestions right now.
Frameworks
ISO 27001
HIPAA
GDPR
ISO 9001