ORIGINAL RESOURCE · V1.0

Legacy decommissioning checklist

Decommissioning is not simply turning off a server. It closes dependencies, preserves evidence and keeps a restoration path during the approved window.

Reviewed .

1. Before the decision

Nothing advances without equivalence and accountable owners.

  • Approved Equivalence Contract
  • Zero blockers or signed exceptions
  • Dependencies and consumers inventoried
  • Communication and support plan

2. Cutover window

Execution needs command, observation and a stop path.

  • Named go/no-go
  • Verified backup and snapshot
  • Stop control and rollback available
  • Live metrics and accountable responders

3. After cutover

Preserve response capability during the agreed window.

  • Post-cutover reconciliation
  • Regression monitoring
  • Archive retention and access
  • Deadline and condition for secure destruction

4. Closure

Technical and contractual retirement must close the same story.

  • Licenses and contracts terminated
  • Access revoked
  • CMDB/inventory updated
  • Evidence Pack and final decision retained

CHECKLIST · Sequence and obligations vary by criticality, sector, contract and privacy role. Validate with Technology, Security, Legal, DPO and the process owner.