Enterprise Legacy System Decommissioning & Server Retirement Form

1. Legacy Application & Host Server Metadata

This section captures essential identification and classification metadata for the legacy application and its infrastructure. Complete all mandatory fields to establish the decommissioning baseline.


Legacy Application Name

Application Unique Identifier

Current Application Version

Primary Host Server Name

Host Server IP Address/FQDN

Operating System & Version

Data Center or Cloud Region

Decommissioning Scope Classification

Business Rationale for Decommissioning

Proposed Decommissioning Execution Date

Business Owner Name & Department

Technical Owner Name & Team

Business Criticality Rating (1 = Low, 5 = Mission Critical)

Does this system process, store, or transmit sensitive data?


Upload Current Architecture Diagram

Choose a file or drop it here
 

Upload Network Connectivity Diagram

Choose a file or drop it here
 

Assess the potential business impact across dimensions if decommissioning fails or is delayed

No Impact

Minimal

Moderate

Significant

Severe

Revenue Impact

Customer Service Disruption

Regulatory Compliance Risk

Employee Productivity Loss

Reputational Damage

2. Data Migration, Archival Retention & Purge Protocol

This section defines the complete data lifecycle management strategy. Specify migration paths, archival requirements, retention periods, and secure deletion verification methods.


Data Inventory & Classification Matrix

Data Store Name

Data Type (e.g., Database, File Share, Object Storage)

Estimated Volume (GB)

Sensitivity Level

Migration Target System

Retention Period (Years)

Requires Cryptographic Erasure?

user_profiles_db
PostgreSQL Database
450
Confidential
CRM-Platform-Cloud
7
Yes
transaction_logs
Log Files
1200
Internal Use
Archive-Storage-Tier
3
 
temp_file_share
Network File Share
85
Public
Purge-No-Migration
0
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Will data be migrated to a new system or platform?


Archival Storage Location Identifier

Is archival data encrypted at rest and in transit?

Describe the data purge verification process and certificate generation:

Are there legal or compliance requirements mandating specific retention periods?


Upload Data Migration Runbook

Choose a file or drop it here
 

Upload Data Purge Verification Certificate Template

Choose a file or drop it here
 

Rate the confidence level (1-5) for each data management phase

Data Extraction Completeness

Migration Accuracy

Archival Integrity

Purge Irreversibility

Rollback Feasibility

3. Downstream API Dependency & System Disconnection Audit

Comprehensive audit of all integration points, API dependencies, and interconnected systems. This ensures orderly disconnection without disrupting dependent services.


API Dependency & Integration Inventory

API Endpoint or Integration Name

Integration Direction

Consumer System Name

Consumer System Owner

Criticality to Consumer (1-5)

Has consumer system been notified?

Planned Disconnection Date

/api/v2/payment
Outbound
PaymentGateway-PROD
Finance Team
 
Yes
11/15/2024
/legacy/auth/verify
Inbound
EmployeePortal-APP
HR Systems
 
Yes
11/20/2024
/batch/reporting
Outbound
DataWarehouse-ETL
BI Team
 
 
11/25/2024
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Are there any hard-coded IP addresses or dependencies in consumer systems?


Select all disconnection methods that will be employed:

Describe the communication plan and timeline for notifying all dependent system owners:

Will a 'dark launch' or phased disconnection approach be used to monitor for latent dependencies?


Upload API Dependency Mapping Diagram

Choose a file or drop it here
 

Rate your confidence in the completeness of the dependency discovery process

Inbound API Discovery

Outbound Service Discovery

Batch Job Identification

Database Link Detection

Network Flow Analysis

4. User Access Revocation & License Termination Plan

Systematic plan for revoking user access, disabling service accounts, and terminating all associated software licenses. Ensures security and cost optimization post-decommissioning.


User Access Inventory & Revocation Schedule

Service Account Name

Account Type

Associated Department or System

Active Last 90 Days?

Access Revocation Date

Revocation Confirmed?

user.johnson.m
Employee
Sales Operations
Yes
11/18/2024
 
svc_legacy_app
Service Account
Finance Reporting
 
11/18/2024
 
api.key.7845
API Key
Partner Portal
Yes
11/20/2024
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Are there external users (partners, vendors, customers) with access to this system?


Software License & Subscription Termination Tracker

Software Product Name

License Key or Subscription ID

License Model

Annual Cost

Contract End Date

Termination Request Submitted?

Vendor Support Ticket ID

Oracle Database Enterprise
LIC-2023-ORCL-5589
Perpetual
$15,000.00
12/31/2024
Yes
TKT-8847
Red Hat Linux Support
SUB-RHEL-7741
Annual Subscription
$3,200.00
3/15/2025
 
 
Splunk Logging
SaaS-SPLK-221
Monthly SaaS
$850.00
11/30/2024
Yes
TKT-8848
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Will any licenses be repurposed or transferred to other systems?


Describe the process for disabling or deleting system administrator and privileged accounts:

I confirm that all access revocation activities will be logged in the enterprise SIEM system

Upload License Termination Confirmation Letters

Choose a file or drop it here
 

5. Chief Information Security Officer (CISO) & Enterprise Architect Approval

Final risk assessment, security validation, and formal approval from key governance stakeholders. This section confirms that all technical, security, and compliance requirements have been satisfied prior to execution.


Security Control Verification Checklist

Not Reviewed

Non-Compliant

Partially Compliant

Compliant

Exceeds Requirements

Data Sanitization Plan Approved

Access Revocation Process Validated

API Disconnection Risk Assessed

Backup Integrity Verified

Incident Response Plan Updated

Audit Logging Configured

Has a formal security risk assessment been completed for this decommissioning?


Is there a rollback or contingency plan if critical issues arise during decommissioning?


Post-Decommissioning Monitoring Period (Days)

Select all monitoring activities that will be performed after decommissioning:

Will this decommissioning be communicated to external auditors or regulatory bodies?


Overall Technical Risk Level of This Decommissioning

Enterprise Architect's Technical Validation Comments

Enterprise Architect Approval Signature

Enterprise Architect Approval Timestamp

Chief Information Security Officer (CISO) Security Validation Comments

Chief Information Security Officer (CISO) Approval Signature

CISO Approval Timestamp

I acknowledge that this decommissioning form, once fully approved, becomes a formal change record and will be retained for a minimum of 7 years per corporate governance policy

Ready to put your personal touch on this form template? Edit this Legacy System Decommissioning Form Template | IT Architecture
Looking for a way to perform in-depth data analysis directly within your forms? Build your own with Zapof's powerful table and spreadsheet capabilities.
This form is protected by Google reCAPTCHA. Privacy - Terms.
 
Built using Zapof