AuditPro and ISO 19770

The ISO 19770 standard is a concept of software asset management standardisation within an organisation within the framework of ISO/IEC standards.

The content of ISO 19770 - Software Asset Management (SAM)
The objective of the standard is to give companies guidelines to assist in the risk and cost minimisation in software asset management and, in so doing, acquire a competitive advantage through:

  • Management of the risk of interrupted IT service delivery, possible breach of regulations or legal sanctions
  • Reducing the direct software costs by centralising purchases
  • Improved information availability and more efficient processes to reduce costs within the framework of organisation support and improve decision-making quality within the company
  • Software asset management (SAM) principles applied to all memory media, licenses, license agreements and intellectual property associated with all of the company's software

Stock-taking processes

For all instances on all platforms, the records of software inventory within the company should include as a minimum the records of:

  • Software Master Versions and distribution copies
  • Installed software
  • Software versions, patches and improvements
  • Licenses
  • License agreements
  • Contracts
  • Physical as well as electronic software storage sites
  • License models
  • Inventory records should contain at least an identification, name, location and owner of the relevant assets, the status and corresponding version.

The organisations are recommended to implement such policies and procedures to protect such inventory records as to include protection against unauthorised alteration possibilities and, also, compile and document a recovery plan in case of an accident. It is also necessary to keep an audit record of inventory modifications.

Legal use of software licenses
The aforementioned internal procedures are important to ensure the use of software in compliance with the license agreement and license terms and conditions. In this case it means regular checking of the installed software status and comparing it with the quantity of legally owned licenses. A good-quality process set up and their automation allows more frequent running and, consequently, shorter response time and addressing potential non-conformities in good time.

Another significant benefit of implementing the aforementioned procedures is not only the monitoring of the number of licenses used but also an improvement in the methods the organisation employs to obtain the information, increased relevance of the results and verified data of how the users' real needs correspond with the installed software base.

Attention must be paid also to physical records of license documents.

ISO 19770 divides SAM processes in six basic parts. Special attention is paid to the record process and legality issues (see above). Other issues are as follows:
Control mechanisms
In each organisation, the management, possibly together with other persons in charge, bears responsibility for potential problems resulting from breach of intellectual property rights. The ISO standard recommends adopting internal measures to define not only the manipulation procedures with regards resources protected by copyright but also the scope of the corporate and personal responsibility for individual SAM process stages. The standard also recommends defining disciplinary sanctions for breach of such rules and procedures.

SAM Planning and Implementation based on ISO 19770
To achieve optimum results, initially it is necessary to determine the scope of the project, its objectives, resources, funding, time schedule and individual processes to achieve the objective.

Savings in everyday operations
An important aspect of software asset management - one of those that could bring direct financial savings - is relationships with suppliers, internal and external software users. This concerns the tenders for software supply, verification of use of existing licenses and optimisation of further investment in software licenses.

Statistics and overviews
An inseparable part of the SAM processes, the standard recommends observing the following frequency and scope of output:

  • quarterly overview of expenses (compared with the budget)
  • quarterly comparison of authorised installations against all installations (discovering the scope of unauthorised installations)
  • semi-annual overview of performance against the tasks assigned, summary of changes and solving potential problems
  • semi-annual overview of performing contractual deliveries along with a proposal for extension of contracts or licenses with time limits
  • semi-annual verification of up-to-date status of the hardware and software records (including software builds)
  • annual overview of validity of training and certification of persons in charge
  • annual overview of performance against the plan status and status of management defined tasks for the SAM field
  • annual overview of current user, administrator and management requirements, future prospects, further planning
  • annual overview of supply performance on the part of contractors
  • annual overview of the physical and electronic record status
  • annual overview of up-to-date status of evaluation methods for real software license utilisation by users
  • annual overview to evaluate the compliance with internal regulations and restrictions as stipulated

The last item addressed in the standard is a recommendation for software producers to make license agreements for their products accessible to users over the Internet.