Decommissioning
The controlled retirement of an asset from service: revoking its access and identities, retaining or disposing of its data, sanitising its media, and updating the inventory.
Decommissioning is the end-of-service stage of an asset’s lifecycle and the counterpart of provisioning. A controlled process typically confirms the asset is no longer needed, archives any data that must be retained, removes the asset’s accounts, certificates, keys, DNS entries and firewall rules, sanitises or destroys its storage, and updates the asset inventory and the configuration management database. Where media goes to a third party for destruction, a certificate of destruction records what was done.
It is easily confused with deprovisioning, which removes an account and the access that went with it. The two overlap when an asset is retired, because its own service accounts and credentials need removing, but deprovisioning also happens whenever people leave or change roles. Skipped steps leave familiar risks: forgotten, unpatched servers still on the network, dangling DNS records open to takeover, and drives that leave the building with recoverable data because media sanitisation was assumed rather than verified. End of life and end of support dates are common triggers.
Exam relevance: a scenario is likely to describe a retired server, a cloud workload that was switched off, or hardware sold on, and ask what was missed. Candidates are expected to treat decommissioning as a documented process that covers access, data, media and inventory together.