Documentation and processes

IT governance documents

A policy defines security’s role and desired state (organizational, system-specific, and issue-specific levels). A standard implements a policy. A guideline is a recommendation that allows exceptions.

Common documentation

Asset management

Governance of tangible (buildings, servers) and intangible (IP, reputation) assets across their lifecycle, tracked in a database with unique asset tags and IDs (barcode or RFID).

The procurement lifecycle: change request (business impact), then procurement (budget, vendor), deployment (secure baseline install), maintenance and operations, and finally disposal (sanitize data remnants).

Track warranties, support contracts, license compliance, and user assignments.

IPAM

IP Address Management plans, tracks, and manages address space. Spreadsheets don’t scale. Automated IPAM detects conflicts, integrates with DHCP and DNS, auto-assigns to new VMs during horizontal scaling, and feeds security (spotting unauthorized devices).

Agreements

Product lifecycle

Mainstream support (5+ years for Microsoft), then extended support (3-5 more), then end of life. Legacy operating systems get no patches: Windows XP died in 2015 yet lingers in ICS/SCADA environments where upgrades cost too much, and it’s wide open.

Feature updates land every 6-12 months and can change baseline hardware requirements.

Change and configuration management

Change management is a structured transition to a desired state. The CAB evaluates proposals; the change owner initiates and advocates; stakeholders get consulted; impact analysis runs before anything ships. Same framework as my ITIL change practices note.

Configuration management keeps documentation matching reality: baselines collected under normal conditions (your troubleshooting reference), cable labeling with standard naming, diagrams, wiring schematics, contacts, and procedures in a central knowledge base (share drive, SharePoint).

Operations and maintenance eats around 70% of network time. Optimize it.

Patch management

Why: security (fix CVEs), uptime (prevent crashes), compliance, and features.

Four steps: plan (policies and tracking), test (lab first), implement (SCCM for Windows, MDM for mobile, vendor tools for firmware), audit (verify installs).

Patch rings roll out in stages: a small group first, expanding on success. Firmware on routers, switches, and firewalls needs the same discipline (Cisco UCS Manager, ManageEngine Device Expert).