This section captures essential identification and classification metadata for the legacy application and its infrastructure. Complete all mandatory fields to establish the decommissioning baseline.
Legacy Application Name
Application Unique Identifier
Current Application Version
Primary Host Server Name
Host Server IP Address/FQDN
Operating System & Version
Data Center or Cloud Region
Decommissioning Scope Classification
Full Application Retirement
Partial Module Decommissioning
Server Hardware Refresh Only
Application Consolidation
Technology Stack Migration
Business Rationale for Decommissioning
Proposed Decommissioning Execution Date
Business Owner Name & Department
Technical Owner Name & Team
Business Criticality Rating (1 = Low, 5 = Mission Critical)
Does this system process, store, or transmit sensitive data?
Upload Current Architecture Diagram
Upload Network Connectivity Diagram
Assess the potential business impact across dimensions if decommissioning fails or is delayed
No Impact | Minimal | Moderate | Significant | Severe | |
|---|---|---|---|---|---|
Revenue Impact | |||||
Customer Service Disruption | |||||
Regulatory Compliance Risk | |||||
Employee Productivity Loss | |||||
Reputational Damage |
This section defines the complete data lifecycle management strategy. Specify migration paths, archival requirements, retention periods, and secure deletion verification methods.
Data Inventory & Classification Matrix
Data Store Name | Data Type (e.g., Database, File Share, Object Storage) | Estimated Volume (GB) | Sensitivity Level | Migration Target System | Retention Period (Years) | Requires Cryptographic Erasure? | |
|---|---|---|---|---|---|---|---|
user_profiles_db | PostgreSQL Database | 450 | Confidential | CRM-Platform-Cloud | 7 | Yes | |
transaction_logs | Log Files | 1200 | Internal Use | Archive-Storage-Tier | 3 | ||
temp_file_share | Network File Share | 85 | Public | Purge-No-Migration | 0 | ||
Will data be migrated to a new system or platform?
Archival Storage Location Identifier
Is archival data encrypted at rest and in transit?
Describe the data purge verification process and certificate generation:
Are there legal or compliance requirements mandating specific retention periods?
Upload Data Migration Runbook
Upload Data Purge Verification Certificate Template
Rate the confidence level (1-5) for each data management phase
Data Extraction Completeness | |
Migration Accuracy | |
Archival Integrity | |
Purge Irreversibility | |
Rollback Feasibility |
Comprehensive audit of all integration points, API dependencies, and interconnected systems. This ensures orderly disconnection without disrupting dependent services.
API Dependency & Integration Inventory
API Endpoint or Integration Name | Integration Direction | Consumer System Name | Consumer System Owner | Criticality to Consumer (1-5) | Has consumer system been notified? | Planned Disconnection Date | |
|---|---|---|---|---|---|---|---|
/api/v2/payment | Outbound | PaymentGateway-PROD | Finance Team | Yes | 11/15/2024 | ||
/legacy/auth/verify | Inbound | EmployeePortal-APP | HR Systems | Yes | 11/20/2024 | ||
/batch/reporting | Outbound | DataWarehouse-ETL | BI Team | 11/25/2024 | |||
Are there any hard-coded IP addresses or dependencies in consumer systems?
Select all disconnection methods that will be employed:
API Gateway Route Removal
Firewall Rule Deactivation
DNS Record Deletion
Load Balancer Pool Removal
Service Account Disablement
Certificate Revocation
Describe the communication plan and timeline for notifying all dependent system owners:
Will a 'dark launch' or phased disconnection approach be used to monitor for latent dependencies?
Upload API Dependency Mapping Diagram
Rate your confidence in the completeness of the dependency discovery process
Inbound API Discovery | |
Outbound Service Discovery | |
Batch Job Identification | |
Database Link Detection | |
Network Flow Analysis |
Systematic plan for revoking user access, disabling service accounts, and terminating all associated software licenses. Ensures security and cost optimization post-decommissioning.
User Access Inventory & Revocation Schedule
Service Account Name | Account Type | Associated Department or System | Active Last 90 Days? | Access Revocation Date | Revocation Confirmed? | |
|---|---|---|---|---|---|---|
user.johnson.m | Employee | Sales Operations | Yes | 11/18/2024 | ||
svc_legacy_app | Service Account | Finance Reporting | 11/18/2024 | |||
api.key.7845 | API Key | Partner Portal | Yes | 11/20/2024 | ||
Are there external users (partners, vendors, customers) with access to this system?
Software License & Subscription Termination Tracker
Software Product Name | License Key or Subscription ID | License Model | Annual Cost | Contract End Date | Termination Request Submitted? | Vendor Support Ticket ID | |
|---|---|---|---|---|---|---|---|
Oracle Database Enterprise | LIC-2023-ORCL-5589 | Perpetual | $15,000.00 | 12/31/2024 | Yes | TKT-8847 | |
Red Hat Linux Support | SUB-RHEL-7741 | Annual Subscription | $3,200.00 | 3/15/2025 | |||
Splunk Logging | SaaS-SPLK-221 | Monthly SaaS | $850.00 | 11/30/2024 | Yes | TKT-8848 | |
Will any licenses be repurposed or transferred to other systems?
Describe the process for disabling or deleting system administrator and privileged accounts:
I confirm that all access revocation activities will be logged in the enterprise SIEM system
Upload License Termination Confirmation Letters
Final risk assessment, security validation, and formal approval from key governance stakeholders. This section confirms that all technical, security, and compliance requirements have been satisfied prior to execution.
Security Control Verification Checklist
Not Reviewed | Non-Compliant | Partially Compliant | Compliant | Exceeds Requirements | |
|---|---|---|---|---|---|
Data Sanitization Plan Approved | |||||
Access Revocation Process Validated | |||||
API Disconnection Risk Assessed | |||||
Backup Integrity Verified | |||||
Incident Response Plan Updated | |||||
Audit Logging Configured |
Has a formal security risk assessment been completed for this decommissioning?
Is there a rollback or contingency plan if critical issues arise during decommissioning?
Post-Decommissioning Monitoring Period (Days)
Select all monitoring activities that will be performed after decommissioning:
SIEM Log Analysis for Access Attempts
Network Traffic Monitoring for Residual Connections
API Gateway Hit Analysis
Service Desk Ticket Trend Analysis
Vendor License Renewal Notification Check
Compliance Audit Trail Review
Will this decommissioning be communicated to external auditors or regulatory bodies?
Overall Technical Risk Level of This Decommissioning
Very Low Risk
Low Risk
Moderate Risk
High Risk
Critical Risk
Enterprise Architect's Technical Validation Comments
Enterprise Architect Approval Signature
Enterprise Architect Approval Timestamp
Chief Information Security Officer (CISO) Security Validation Comments
Chief Information Security Officer (CISO) Approval Signature
CISO Approval Timestamp
I acknowledge that this decommissioning form, once fully approved, becomes a formal change record and will be retained for a minimum of 7 years per corporate governance policy