Concept and mechanism
Infrastructure lifecycle includes introduction, maintenance, upgrade, and retirement. If middleware support ends before go-live, new servers do not resolve the dependency. Identifying the supported version, application compatibility, test effort, and transition window supports a funded plan. An authorized temporary exception needs an owner, boundaries, and review date; it does not remove technical risk. Patch management includes identification, prioritization, installation, and verification. Copying a package does not demonstrate that the running process uses the fixed library. Evidence should connect the approved change to the version actually running and observed functional behavior.
Guided application
Decommissioning starts by confirming consumers and the business cycle. Thirty days without login can hide a quarterly batch or an archive used at annual close. Plan migration of these dependencies, validate readability, and reconcile inventory with resources and contracts. Data retention and disposal are related but different decisions: still-needed data should not be destroyed to meet a savings target. Once retirement is authorized, apply sanitization appropriate to media and sensitivity with outcome evidence. Deleting files or preventing boot does not prove data is unrecoverable. Also confirm access withdrawal, residual monitoring, and actual cessation of costs.
Example: the old-system archive supports quarterly reporting. Savings need revision until validated destination access or an approved contingency exists.
Common pitfalls
New hardware treated as supported software; copied package treated as active patch; no login treated as no consumers.
Related topics: Services, dependencies, and evidence · Identity, connectivity, and protection · Resilience and data recovery
Close the lifecycle with compatibility, operational evidence, and actual retirement.
Reference: NIST SP800-40 Revision4 · DR banking infrastructure professional assessment2026.10