9:200-AP2 Software Asset Management Procedure
9:200-AP2 Software Asset Management Procedure
Purpose
This administrative procedure implements Board Policies 7:345, 9:200, and 9:210 by establishing requirements for the lawful, secure, accessible, and fiscally responsible management of District software, cloud applications, licenses, and subscriptions.
Scope
This procedure applies to paid and free software used for District instruction or operations, including:
- Software-as-a-Service subscriptions
- Mobile applications
- Browser extensions and connected applications
- Artificial intelligence-enabled tools
- Trials and click-through services
- Software and services that access District accounts, systems, networks, or data
Responsibilities
- Requesting Supervisor or Program Owner – Establishes the operational or instructional need, intended use, users, funding, accessibility needs, and whether the software should be renewed, replaced, or discontinued.
- Curriculum and Instruction – Reviews curricular alignment and instructional suitability when the software will be used for instruction.
- Data Privacy Committee and Privacy Officer – Perform the applicable privacy review and approval functions established by Board Policy 7:345 and 7:345-AP1, including SOPPA compliance and transparency requirements.
- Business Office and Authorized Contract Signer – Apply applicable purchasing, budget, bidding, contract, signature, renewal, and records requirements.
- Technology Department – Conducts technical review; maintains the software inventory; administers licenses and integrations; evaluates security, compatibility, identity and access, capacity, and supportability; and coordinates implementation, restriction, and removal.
- District Users – Request software through the established process, use only authorized accounts and licenses, and comply with approved purposes and terms.
Procedure
I. Request and Review
Software shall complete all applicable reviews before purchase, installation, activation, testing with District data, or use with students. Free tools, trials, click-through services, browser extensions, and connected applications are subject to the same requirements when they access District accounts, systems, networks, or data.
The requesting supervisor or program owner shall provide, as applicable:
- Operational or instructional purpose
- Intended users
- Requested term
- Cost and funding source
- Vendor information
- Data involved
- Accessibility needs
- Required integrations
- Desired implementation date
Requests shall be routed for the applicable operational or instructional, privacy, purchasing, accessibility, and technical reviews.
II. Decision Authority and Technical Findings
The requesting supervisor or program owner determines whether the software meets the identified operational need. Curriculum and Instruction determines instructional suitability when applicable. The Data Privacy Committee and Privacy Officer determine whether the proposed use of student data satisfies District requirements. The Business Office and authorized contract signer determine whether a purchase or contract may proceed.
The Technology Department determines whether the software can be securely and reliably implemented and supported within the District’s technical environment. Technology may approve, condition, delay, or decline technical implementation based on documented concerns involving:
- Cybersecurity
- Compatibility or architecture
- Identity and access
- Data protection
- Integration or capacity
- Licensing
- Technical supportability
Technology may also identify duplication, long-term cost, vendor support concerns, or available District-supported alternatives for consideration during the approval process.
Approval by one reviewing area does not override a required legal, privacy, purchasing, accessibility, security, or technical determination. When responsibilities or findings conflict, the Superintendent or designee shall identify the appropriate decision-maker and resolve the matter.
The Technology Department may immediately restrict or suspend software when reasonably necessary to address an active or imminent security or technical risk. The action shall be documented and communicated to the appropriate program owner.
III. Legal, Privacy, Accessibility, and Contract Requirements
No District user may bind the District through a purchase, click-through agreement, trial, renewal, or other commitment without appropriate authority under District purchasing and contract procedures.
Software involving student covered information shall satisfy Board Policy 7:345, 7:345-AP1, the Student Online Personal Protection Act, and applicable operator contract and transparency requirements before student information is disclosed.
Software shall also satisfy applicable:
- Licensing and copyright requirements
- Records-retention requirements
- Accessibility requirements
- Privacy and security requirements
- Data-retention and deletion requirements
- Purchasing and signature requirements
A required legal or contractual control is not an optional technical preference.
IV. Inventory, Licensing, and Assignment
The Technology Department shall maintain the official software inventory in coordination with program owners, the Privacy Officer, and the Business Office.
Inventory records shall include, as applicable:
- Product, vendor, and purpose
- Program owner or responsible department
- Users, devices, and license information
- Cost and funding source
- Contract term
- Renewal and cancellation deadlines
- Accessibility and privacy status
- SOPPA agreement status
- Authentication and integration method
- Current lifecycle status
Licenses shall be assigned based on documented need and reclaimed or reassigned when no longer required.
Supervisors and program owners shall report purchases, renewals, licensing changes, replacements, and discontinuations so the inventory remains accurate.
V. Review and Renewal
Before an applicable renewal or cancellation deadline, the requesting supervisor or program owner shall determine whether to renew, modify, replace, or discontinue the software. The review shall consider:
- Continued operational or instructional need
- Current and projected use
- Available licenses
- Cost and available funding
- Accessibility
- Vendor performance and support
- Contract, renewal, termination, and cancellation requirements
- Technical and integration status
- Security and data privacy requirements
- SOPPA documentation
- Available District-supported alternatives
The Technology Department shall provide available technical, integration, licensing, and usage information. The Business Office shall apply applicable purchasing and contract requirements and retain the official agreement.
Automatic renewal does not replace the required review, approval, notification, or signature process.
VI. Compliance, Restriction, and Removal
The District shall periodically review software use and licensing to identify:
- Unused or underused licenses
- Unauthorized or unsupported software
- Duplicate applications
- Expired licenses or contracts
- Missing accessibility, privacy, or SOPPA documentation
- Software that no longer meets District requirements
Software may be restricted or removed when it does not meet applicable instructional, operational, licensing, accessibility, privacy, security, contractual, or technical requirements.
Except when immediate protective action is necessary, the Technology Department shall coordinate restriction or removal with the official responsible for the applicable determination.
When software is discontinued or no longer approved, the appropriate program owner, Business Office, Privacy Officer, and Technology Department shall coordinate, as applicable:
- Contract cancellation or termination
- Removal or disabling of the software
- Termination of user, vendor, and administrative access
- Recovery of licenses
- Removal of technical integrations
- Preservation or transfer of required District records
- Return or deletion of District data
- Software inventory updates
- SOPPA transparency updates
VII. Exceptions
Exceptions must be documented and approved by the Superintendent or appropriate designee. The exception shall identify:
- Approving authority
- Business or instructional need
- Duration
- Affected users and data
- Identified risks and restrictions
- Required compensating controls
An exception may not waive SOPPA requirements, purchasing or signature authority, records-retention requirements, accessibility law, or another mandatory legal or contractual requirement.
Review Cycle
The Superintendent’s designees for Technology, Curriculum and Instruction, Finance, Privacy, and Accessibility shall review this procedure annually and following a material change in law, Board policy, District systems, or software-management practices.
Cross-References
- 4:060, Purchases and Contracts; 4:060-AP1, Purchases; 4:060-AP2, Contracts; 6:040, Curriculum Development and Instructional Resources; 6:235, Access to Electronic Networks; 6:235-AP1, Acceptable Use of Electronic Networks; 7:345, Use of Educational Technologies; Student Data Privacy and Security; 7:345-AP1; 8:070, Accommodating Individuals with Disabilities; 9:010, Information Assets; 9:020, Risk to Information Assets; 9:100, Information Security; 9:110-AP1, Data Governance; 9:140-AP1, Access Control and Permissions Review; 9:200, Asset Management; 9:200-AP1, Enterprise Asset Inventory and Management; 9:210, Information Asset Acquisition, Development and Maintenance
Purpose
This administrative procedure implements Board Policies 7:345, 9:200, and 9:210 by establishing requirements for the lawful, secure, accessible, and fiscally responsible management of District software, cloud applications, licenses, and subscriptions.
Scope
This procedure applies to paid and free software used for District instruction or operations, including:
- Software-as-a-Service subscriptions
- Mobile applications
- Browser extensions and connected applications
- Artificial intelligence-enabled tools
- Trials and click-through services
- Software and services that access District accounts, systems, networks, or data
Responsibilities
- Requesting Supervisor or Program Owner – Establishes the operational or instructional need, intended use, users, funding, accessibility needs, and whether the software should be renewed, replaced, or discontinued.
- Curriculum and Instruction – Reviews curricular alignment and instructional suitability when the software will be used for instruction.
- Data Privacy Committee and Privacy Officer – Perform the applicable privacy review and approval functions established by Board Policy 7:345 and 7:345-AP1, including SOPPA compliance and transparency requirements.
- Business Office and Authorized Contract Signer – Apply applicable purchasing, budget, bidding, contract, signature, renewal, and records requirements.
- Technology Department – Conducts technical review; maintains the software inventory; administers licenses and integrations; evaluates security, compatibility, identity and access, capacity, and supportability; and coordinates implementation, restriction, and removal.
- District Users – Request software through the established process, use only authorized accounts and licenses, and comply with approved purposes and terms.
Procedure
I. Request and Review
Software shall complete all applicable reviews before purchase, installation, activation, testing with District data, or use with students. Free tools, trials, click-through services, browser extensions, and connected applications are subject to the same requirements when they access District accounts, systems, networks, or data.
The requesting supervisor or program owner shall provide, as applicable:
- Operational or instructional purpose
- Intended users
- Requested term
- Cost and funding source
- Vendor information
- Data involved
- Accessibility needs
- Required integrations
- Desired implementation date
Requests shall be routed for the applicable operational or instructional, privacy, purchasing, accessibility, and technical reviews.
II. Decision Authority and Technical Findings
The requesting supervisor or program owner determines whether the software meets the identified operational need. Curriculum and Instruction determines instructional suitability when applicable. The Data Privacy Committee and Privacy Officer determine whether the proposed use of student data satisfies District requirements. The Business Office and authorized contract signer determine whether a purchase or contract may proceed.
The Technology Department determines whether the software can be securely and reliably implemented and supported within the District’s technical environment. Technology may approve, condition, delay, or decline technical implementation based on documented concerns involving:
- Cybersecurity
- Compatibility or architecture
- Identity and access
- Data protection
- Integration or capacity
- Licensing
- Technical supportability
Technology may also identify duplication, long-term cost, vendor support concerns, or available District-supported alternatives for consideration during the approval process.
Approval by one reviewing area does not override a required legal, privacy, purchasing, accessibility, security, or technical determination. When responsibilities or findings conflict, the Superintendent or designee shall identify the appropriate decision-maker and resolve the matter.
The Technology Department may immediately restrict or suspend software when reasonably necessary to address an active or imminent security or technical risk. The action shall be documented and communicated to the appropriate program owner.
III. Legal, Privacy, Accessibility, and Contract Requirements
No District user may bind the District through a purchase, click-through agreement, trial, renewal, or other commitment without appropriate authority under District purchasing and contract procedures.
Software involving student covered information shall satisfy Board Policy 7:345, 7:345-AP1, the Student Online Personal Protection Act, and applicable operator contract and transparency requirements before student information is disclosed.
Software shall also satisfy applicable:
- Licensing and copyright requirements
- Records-retention requirements
- Accessibility requirements
- Privacy and security requirements
- Data-retention and deletion requirements
- Purchasing and signature requirements
A required legal or contractual control is not an optional technical preference.
IV. Inventory, Licensing, and Assignment
The Technology Department shall maintain the official software inventory in coordination with program owners, the Privacy Officer, and the Business Office.
Inventory records shall include, as applicable:
- Product, vendor, and purpose
- Program owner or responsible department
- Users, devices, and license information
- Cost and funding source
- Contract term
- Renewal and cancellation deadlines
- Accessibility and privacy status
- SOPPA agreement status
- Authentication and integration method
- Current lifecycle status
Licenses shall be assigned based on documented need and reclaimed or reassigned when no longer required.
Supervisors and program owners shall report purchases, renewals, licensing changes, replacements, and discontinuations so the inventory remains accurate.
V. Review and Renewal
Before an applicable renewal or cancellation deadline, the requesting supervisor or program owner shall determine whether to renew, modify, replace, or discontinue the software. The review shall consider:
- Continued operational or instructional need
- Current and projected use
- Available licenses
- Cost and available funding
- Accessibility
- Vendor performance and support
- Contract, renewal, termination, and cancellation requirements
- Technical and integration status
- Security and data privacy requirements
- SOPPA documentation
- Available District-supported alternatives
The Technology Department shall provide available technical, integration, licensing, and usage information. The Business Office shall apply applicable purchasing and contract requirements and retain the official agreement.
Automatic renewal does not replace the required review, approval, notification, or signature process.
VI. Compliance, Restriction, and Removal
The District shall periodically review software use and licensing to identify:
- Unused or underused licenses
- Unauthorized or unsupported software
- Duplicate applications
- Expired licenses or contracts
- Missing accessibility, privacy, or SOPPA documentation
- Software that no longer meets District requirements
Software may be restricted or removed when it does not meet applicable instructional, operational, licensing, accessibility, privacy, security, contractual, or technical requirements.
Except when immediate protective action is necessary, the Technology Department shall coordinate restriction or removal with the official responsible for the applicable determination.
When software is discontinued or no longer approved, the appropriate program owner, Business Office, Privacy Officer, and Technology Department shall coordinate, as applicable:
- Contract cancellation or termination
- Removal or disabling of the software
- Termination of user, vendor, and administrative access
- Recovery of licenses
- Removal of technical integrations
- Preservation or transfer of required District records
- Return or deletion of District data
- Software inventory updates
- SOPPA transparency updates
VII. Exceptions
Exceptions must be documented and approved by the Superintendent or appropriate designee. The exception shall identify:
- Approving authority
- Business or instructional need
- Duration
- Affected users and data
- Identified risks and restrictions
- Required compensating controls
An exception may not waive SOPPA requirements, purchasing or signature authority, records-retention requirements, accessibility law, or another mandatory legal or contractual requirement.
Review Cycle
The Superintendent’s designees for Technology, Curriculum and Instruction, Finance, Privacy, and Accessibility shall review this procedure annually and following a material change in law, Board policy, District systems, or software-management practices.
Cross-References
- 4:060, Purchases and Contracts; 4:060-AP1, Purchases; 4:060-AP2, Contracts; 6:040, Curriculum Development and Instructional Resources; 6:235, Access to Electronic Networks; 6:235-AP1, Acceptable Use of Electronic Networks; 7:345, Use of Educational Technologies; Student Data Privacy and Security; 7:345-AP1; 8:070, Accommodating Individuals with Disabilities; 9:010, Information Assets; 9:020, Risk to Information Assets; 9:100, Information Security; 9:110-AP1, Data Governance; 9:140-AP1, Access Control and Permissions Review; 9:200, Asset Management; 9:200-AP1, Enterprise Asset Inventory and Management; 9:210, Information Asset Acquisition, Development and Maintenance
