Device management standards
Expectations and key considerations for managing devices across a school’s digital environment.
- Part of
Technology and devices are deeply embedded in schools and play a central role in learning, teaching and administration. Schools operate complex digital environments that require robust device management standards to ensure security, safeguarding and reliability.
All devices must be effectively managed throughout their lifecycle so that compliance measures, security controls and safeguarding policies are consistently applied. Strong management practices are essential for maintaining a secure and resilient digital environment and planning for device lifecycle is critical.
All devices have a limited lifecycle and may incur ongoing costs for licencing and maintenance. Schools should plan for timely refresh cycles and embed secure, sustainable asset retirement into their digital strategy. Devices that reach end-of-life, must be retired responsibly, including appropriate data sanitisation and environmentally compliant disposal. Considering total cost of ownership within financial planning enables schools to replace, upgrade and retire devices in a way that maintains compliance and reduces risk.
When deploying devices that require wireless connectivity, schools must ensure that the supporting infrastructure can meet performance demands. Wireless capacity and coverage should be assessed and aligned with the wireless networking standard to prevent disruption and maintain a consistent, reliable experience for learners and staff.
-
Devices purchased for school use must meet a standard that supports consistent application of security, safeguarding and performance standards across the school’s digital environment. Ensuring appropriate device quality helps maintain reliability and compliance throughout the device lifecycle.
Schools should consult with their education technology support partner before making any decisions to purchase devices. Schools are encouraged to consider using their local authority’s recommended procurement route.
Working with your local authority will ensure that devices meet appropriate educational specifications and include suitable warranties and support. Procuring through approved routes will help achieve cost efficiency and consistency and will reduce disruption if devices need repair or replacement. These approved procurement routes will also ensure compatibility with management platforms and safeguarding policies.
Procurement decisions should take account of key device specifications. These include supported operating systems, encryption capabilities and hardware components such as wireless network adapters with sufficient capacity to support optimal performance. Encryption of physical storage media is essential, particularly for mobile and teacher devices that may leave school premises. Devices must also be capable of efficient and secure update management. Purchasing devices through non recommended routes introduces significant risks, including the possibility that they cannot be securely or effectively managed.
Through collaboration with all local authorities in Wales, a national route to market for education technology (EdTech) has been established via the EdTech Commercial Service, led by Caerphilly County Borough Council (CCBC). This service provides a compliant and cost effective route to market for devices that meet the education digital standards, reducing procurement barriers and administrative overheads for schools and local authorities.
The EdTech Commercial Service delivers national economies of scale. It secures improved pricing through bulk purchasing and ensuring consistency in device specifications across schools. This consistency simplifies device management, licensing and support. This centralised model streamlines procurement and ensures devices are ready for secure, managed deployment from delivery.
-
Schools should implement robust processes to track all devices used within their digital environment, ensuring visibility and accountability throughout the device lifecycle. Comprehensive tracking supports compliance with security and safeguarding standards. It also helps maintain performance expectations. This approach enables effective planning for maintenance, refresh cycles and secure device retirement.
Device tracking should include accurate records of essential details. This includes the device type, unique identifiers, the assigned user or location, the operating system version and its management status. Schools should also monitor lifecycle indicators such as warranty status and end‑of‑life dates. This helps ensure devices are replaced on time and disposed of securely, following data sanitisation and environmental requirements. Inventory data should be reviewed regularly to confirm accuracy and compliance. Schools should have assurance processes that verify all devices remain under management and continue to meet security and safeguarding requirements.
To support effective tracking, schools should use tools that simplify inventory management and integrate with existing processes. Mobile device management platforms and asset registers can provide centralised visibility and automate key updates. These solutions help schools maintain accurate records, monitor compliance and plan strategically for future investment without introducing unnecessary complexity.
-
All devices should be managed from the point they are introduced into the school environment through to secure retirement at end-of-life. Effective lifecycle management ensures that devices remain secure, compliant and ready to support learning and teaching without disruption. While all devices cannot be centrally managed, all technology assets must still be recorded and tracked as part of the school’s asset management processes. This includes devices or equipment with limited management capabilities, specialist hardware or standalone systems. Maintaining accurate asset records supports accountability, enables risk assessment, and ensures appropriate handling, support and secure disposal at end-of-life.
Where applicable, devices should be managed via a mobile device management (MDM) solution which allows your education technology support partner to configure, update and monitor all enrolled devices. This approach ensures consistent application of safeguarding and security controls. This includes mobile devices such as laptops, tablets, and Chromebooks, which should be managed through an appropriate solution that enables schools to apply policies, enforce encryption and schedule updates outside of teaching hours. Compliance checks should include verification of encryption, anti-virus status, firewall configuration and credential policies.
Before introducing new devices or software, schools should validate compatibility and interoperability with existing infrastructure and services. They must confirm compliance with security and licensing requirements and ensure readiness for integration. Proper configuration from the outset helps prevent disruption, safeguard data integrity and reduce support needs. Planning should also include lifecycle management so that devices remain supported and can be retired securely when they reach end-of-life.
Printers and multifunction devices should be managed through an appropriate print management service. Print and scan capabilities should be treated as managed services rather than standalone peripherals. Print solutions should integrate with existing directory and authentication services, support centralised management and updates, and align with established access control and security policies. Solutions that cannot integrate effectively with the existing digital environment or that require separate unmanaged processes should be avoided due to the increased operational and security risks they introduce.
Consideration should be given to the approach for document scanning and workflows, with a preference for solutions that integrate directly with existing file storage and collaboration services, such as OneDrive. This supports secure handling of data and aligns print and scan services with cloud based working practices.
Management must extend to end-of-life. Devices should remain under management control until secure disposal is confirmed. All data-bearing devices must be wiped or destroyed in accordance with recognised standards (such as NIST 800-88), and certificates of destruction should be retained for audit purposes. Asset registers should be updated to reflect disposal status and confirmation of data sanitisation. Schools should also conduct periodic compliance checks to verify that devices remain under management, up-to-date and meet security baselines throughout their lifecycle.
-
Schools are responsible for ensuring that all devices within their digital environment remain compliant with security, safeguarding and performance requirements. Compliance means that devices are configured and maintained in line with agreed standards. This helps to support a safe, secure and reliable environment for learning and teaching.
To achieve compliance, devices must run an operating system that is still supported by the vendor and must use encryption. Where applicable, devices should also be enrolled in a management system that applies safeguarding controls, configuration policies and updates. Devices should have antivirus or endpoint protection with real‑time scanning and regular signature updates. They must also be continuously monitored for malware, suspicious behaviour, and other potential threats. Firewalls should be enabled and properly configured to prevent unauthorised access, and device‑level credentials must meet complexity requirements and be rotated regularly. Local administration rights should be restricted and granted only when necessary, following the principle of least privilege.
Different types of devices, such as desktops, laptops, tablets and mobile devices, may require different approaches to achieve compliance, but the underlying expectations remain the same. They must be secure, managed and capable of receiving updates. Schools should ensure that any installed software is appropriately licensed and approved for use within the school environment.
Update processes should be configured to minimise disruption to learning and teaching and to optimise network performance. Schools should make use of technologies such as delivery optimisation or caching to reduce bandwidth consumption and avoid simultaneous downloads across large numbers of devices. Schools should also work with their education technology support partner to confirm that update strategies are in place for all device types, including Windows, iOS, ChromeOS and Android, and that these strategies align with safeguarding and performance requirements.
Compliance is not a one time activity. It must be maintained throughout the entire device lifecycle. Schools should establish periodic review and assurance processes to confirm that devices remain secure, up to date and aligned with safeguarding policies. Regular checks help identify risks early, reduce disruption and maintain confidence in the integrity of the school’s digital environment.
-
As part of school’s digital environment, all devices must run a version of an operating system that is currently supported by the vendor. Maintaining supported and up-to-date operating systems is a fundamental principle of device compliance and security. Devices that fall behind on updates or run unsupported versions introduce vulnerabilities that can be exploited, compromising data integrity and disrupting learning and teaching. Operating system compliance must be treated as a non negotiable element of a secure digital environment.
Compliance begins with proactive monitoring and enforcement. Schools should maintain an accurate IT Asset Management System inventory that records operating system versions and support status. Regular compliance checks should be carried out to identify devices nearing end‑of‑support or failing to meet security baselines. Any device found to be non‑compliant should have its network access restricted until remediation is complete. Devices that cannot be updated or have been compromised, such as those jailbroken or containing rootkits, must be removed from service immediately and securely disposed of in line with recognised standards (e.g. NIST 800-88). Certificates of destruction should be retained for audit purposes.
Schools should monitor vendor support timelines and budget for upgrades or replacements well in advance of end-of-life dates. This planning must include secure disposal processes that comply with data protection and environmental standards. By embedding lifecycle considerations into financial and operational planning, schools maintain a consistent, secure digital environment and reduce disruption.
Asset management improvements underpin compliance. Recording OS status, update history, and disposal actions in the asset register ensures auditability and transparency. Where possible, automated compliance reporting should be implemented, enabling leadership teams to monitor risk and enforce policies effectively.
-
Operating system and application updates are essential for maintaining security, safeguarding and the stability of the school’s digital environment. Poorly managed updates can lead to vulnerabilities and performance issues, that can cause disruption to learning and teaching. Schools should therefore treat update management as a core compliance requirement, ensuring that all devices remain secure and aligned with safeguarding policies.
Update processes must be configured to minimise bandwidth consumption and reduce disruption to classroom activities. Schools should use appropriate optimisation technologies, such as delivery optimisation or caching, to reduce the impact of simultaneous downloads and maintain a stable, high performing network. Efficient update management should be supported by automated processes wherever possible, combined with regular monitoring to verify that updates are applied successfully.
Schools should work closely with their education technology support partner to ensure that update strategies are in place for all device types, including Windows, iOS, ChromeOS and Android. These strategies must align with safeguarding, security, and performance requirements. They should also be integrated into routine operational planning to prevent disruption and maintain a secure, resilient digital environment.
By embedding robust update practices within their digital management processes, schools can ensure that devices remain protected, operational and ready to support learning and teaching without unnecessary interruption.
-
Schools must maintain a formal, documented policy and procedure for the retirement and disposal of digital assets, including all Waste Electrical and Electronic Equipment (WEEE). This policy must ensure that devices are handled in a way that maintains security, safeguarding and environmental compliance throughout the end of life process.
To maintain accountability and transparency, schools must keep accurate and up to date asset registers within their asset management system. Disposal records must document asset identifiers, disposal methods, sanitisation outcomes and the identity of the disposal partner. Regular audits and spot checks should be undertaken to verify accuracy, prevent unauthorised disposal and reduce the risk of loss or fraud.
Schools should categorise and segregate assets for disposal based on asset type, data sensitivity and reuse potential. This supports effective risk management by ensuring sensitive devices receive appropriate handling and data protection measures, while also enabling sustainable practices such as recycling, reuse or donation where appropriate. Categorisation also helps streamline workflows and maintain compliance with safeguarding and environmental requirements.
All data bearing devices must be wiped or destroyed in accordance with recognised standards (such as NIST 800 88), and certificates of destruction should be retained for audit purposes. Asset registers should be updated to reflect disposal status and confirmation of data sanitisation. Schools should also conduct periodic compliance checks to verify that devices remain under management, up to date and meet security baselines throughout their lifecycle.
Any third party disposal partners engaged by schools must hold appropriate certifications, such as ISO 14001 or ADISA, and comply with data protection and environmental standards. Contracts or service agreements must clearly define responsibilities, reporting expectations and audit rights, with regular performance reviews to confirm ongoing compliance. By embedding these controls into local policy, schools ensure that strong data protection and security practices extend beyond active device use and remain robust at the point of retirement and disposal.
-
Schools should seek to obtain the greatest possible benefit from devices that is no longer required for its original purpose, while ensuring compliance with security, safeguarding, financial and environmental requirements. Maximising residual value helps schools recoup investment, supports sustainability objectives and reduces waste by extending the useful life of equipment wherever appropriate.
Before disposal, schools should assess whether assets remain functional and suitable for reuse. Where appropriate, options may include resale through approved channels or donation to community organisations. Any donation process must be fully documented, including a signed liability waiver and all actions recorded in the asset register to ensure transparency and accountability. Under no circumstances may staff or learners receive personal gain from the disposal of school assets.
All data‑bearing devices must undergo secure data sanitisation or destruction before reuse, resale or donation. Devices should be wiped or destroyed in accordance with recognised standards, such as NIST 800‑88, with certificates of destruction retained for audit and compliance purposes. This requirement applies regardless of the disposal route to ensure the protection of personal and sensitive data.
Schools should ensure that disposal processes align with environmental standards and local authority guidance. By embedding secure, compliant and sustainable disposal practices into operational planning, schools can maximise the residual value of their assets while upholding data protection, community benefit and environmental responsibility.