SAM Standards: A Review of ISO 19770-1 1 and 2



Similar documents
Software Asset Management (SAM) and ITIL Service Management - together driving efficiency

Service Asset & Configuration Management PinkVERIFY

Software Asset Management: Risk and Reward. March 2015

The Power to Take Control of Software Assets

IBM Tivoli Asset Management for IT

The Power to Take Control of Software Assets

Project Management and ITIL Transitions

Software Asset Management High Risk, High Reward

A Provance White Paper

Software Asset Management on System z

How To Use An Inventory And License Management Tool In A Microsoft Inventory Program

The Value of ITAM To IT Service Management. Presented by Daryl Frost. Copyright Burswood Information Solutions Limited 2015

Software and IT Asset Management Standards: Benefits for Organizations and Individuals

Reviewers of proposed revision to ISO/IEC :2006 SAM Processes. Call for feedback on draft of revised Tiered SAM Processes

Marval Software Limited. G Cloud iii Framework Service Definition

Benefits to the Quality Management System in implementing an IT Service Management Standard ISO/IEC

Commercial Software Licensing

ITIL A guide to service asset and configuration management

ITIL Roles Descriptions

The Benefits of IT Asset Discovery and Contract Management. By William Davis

General Platform Criterion Assessment Question

IIA Super Conference

Cracking the Code on Software License Management

SC7-ISO20000 Alignment issues Aligning ITIL to existing ISO JTC1- SC7 Software Engineering Standards

International Software & Systems Engineering. Standards. Jim Moore The MITRE Corporation Chair, US TAG to ISO/IEC JTC1/SC7 James.W.Moore@ieee.

IBM Maximo Asset Management for IT

An InControl Technology White Paper

ITIL: What is it? How does ITIL link to COBIT and ISO 17799?

GENERAL PLATFORM CRITERIA. General Platform Criterion Assessment Question

EDUCORE ISO Expert Training

Modern Data Center needs 10 th of April, Andrew Sedman, RCDD Head of Training and Technical Service R&M

Operationalize Policies. Take Action. Establish Policies. Opportunity to use same tools and practices from desktop management in server environment

Security Controls What Works. Southside Virginia Community College: Security Awareness

IT Service Management

The World of IT Financial Management

Master s Thesis. Productization of Services and Human Resource Management

SUMMIT ASSET MANAGEMENT DATASHEET

White Paper: Establishing a Configuration Management Database Schema: A Working Model

Cloud Services Catalog with Epsilon

5 CMDB GOOD PRACTICES

Service Support Kasse Initiatives, LLC. ITIL Configuration Management - 1. version 2.0

White Paper: AlfaPeople ITSM This whitepaper discusses how ITIL 3.0 can benefit your business.

Maximo ITSM Product Suite. Francois Marais

Getting a head start in Software Asset Management

ITSM Maturity Model. 1- Ad Hoc 2 - Repeatable 3 - Defined 4 - Managed 5 - Optimizing No standardized incident management process exists

SIEM Implementation Approach Discussion. April 2012

ISO/IEC Information & ICT Security and Governance Standards in practice. Charles Provencher, Nurun Inc; Chair CAC-SC27 & CAC-CGIT

HIPAA CRITICAL AREAS TECHNICAL SECURITY FOCUS FOR CLOUD DEPLOYMENT

INFORMATION SYSTEMS SPECIALIST

Software Asset Management Is your company prepared for a software audit?

Session 2: The Business Value of Software License Optimization and ITSM Integration. David Reis, Senior Software Consultant BMC Software

Intelligent Infrastructure Management System (IIMS)

Proven LANDesk Solutions

Proven deployments across different Industry verticals; Being used by leading brands

Information Technology Auditing for Non-IT Specialist

Which ITIL process or function deals with issues and questions about the use of services, raised by end users?

Dynamic Service Desk. Unified IT Management. Solution Overview

Integration Technologies Group (ITG) ITIL V3 Service Asset and Configuration Management Assessment Robert R. Vespe Page 1 of 19

Asset management guidelines

The Software Experts. Software Asset Management Services & Solutions

BSM Transformation through CMDB Deployment. Streamlining the Integration of Change and Release Management

Information and Communication Technology. Patch Management Policy

Information Security ISO Standards. Feb 11, Glen Bruce Director, Enterprise Risk Security & Privacy

CONDIS. IT Service Management and CMDB

ICTEC. IT Services Issues HELSINKI UNIVERSITY OF TECHNOLOGY 2007 Kari Hiekkanen

Telecom Expense Management

Software Asset Management. The challenge

Exam : EX Title : ITIL Foundation Certificate in IT Service Management. Ver :

WebFOCUS Cloud Express. The WebFOCUS Cloud Express service is delivered as a managed G-Cloud service by Amtex Solutions Ltd.

Choosing IT Service Management Software

ITIL Asset and Configuration. Management in the Cloud

Advanced Server Virtualization: Vmware and Microsoft Platforms in the Virtual Data Center

Domain 1 The Process of Auditing Information Systems

Microsoft s Compliance Framework for Online Services

Lot 1 Service Specification MANAGED SECURITY SERVICES

EXIN IT Service Management Foundation based on ISO/IEC 20000

Organizations remain under intense pressure to reduce costs To reduce costs we must increase efficiency in resource allocation

ca IT Leaders Forum Working in the Cloud using the new ISO/IEC/ITU-T Cloud Computing Standards Dr David Ross, Chief Information Security Officer,

Guidelines on Software Asset Management. Version 0.3

Supporting GIS Best practices for Incident Management and Daily Operations

An IACS user viewpoint for Cyber Security Management System

"Service Lifecycle Management strategies for CIOs"

Combine ITIL and COBIT to Meet Business Challenges

ITU Service - Content Management System (CMS)

Injazat s Managed Services Portfolio

Software License management

IAITAM s Certified Software Asset Manager Course Syllabus

ISO/IEC IT Service Management - Benefits and Requirements for Service Providers and Customers

ITAM (IT Asset Management)

Transcription:

SAM Standards: A Review of ISO 19770-1 1 and 2 David Déry

Agenda SAM problems Looking for guidance ISO: the organization ISO: the SAM initiative ISO: The outcome: ISO/IEC 19770-1 and 19770-2 Conclusion References 2

SAM problems Getting an invoice for a software license: Is the software still in use? Several versions of a database on the same server: Which ones are lawful and which ones are not? Two organizations are merging: Which inventory management systems to keep? 3

SAM problems A software is purchased in a country and used in another one: Which licence restrictions apply? An outsourcer manages the hardware and software : Are the licences transferred to the outsourcer? Looking for a software vendor for SAM?: So many vendors & so few standards! 4

The Pressures on IT IT 5 Regulations Technical Legal Configuration management Financial $$$ Security (Lower costs) Business Time to market SOX Basel accord Software licenses Costs $$$ Virus, Firewalls Hardware Software

Looking for guidance Market surveys IDC study: Industry forecasts ECP: SAM Survey Report (November 2005) Gartner: research notes (2001-2003); Opinions, key words; Repository tools, inventory/discovery tools, configuration management tools Meta group (2000-2001): opinions and observations. Numbers provided without context Vocabulary varies in use and meaning 6

Looking for guidance Tool vendors BSA : Asset Management Resources : http://www.bsa.org/usa/antipiracy/asset-management- Resources.cfm Microsoft best practices http://www.microsoft.com/resources/sam/default.mspx Several functionalities: Inventory, Software usage monitoring, Software License Management, Contract (Lease) Management, Automate maintenance tasks, Asset Management Repository, Auto discovery/discovery, Configuration Management, Repair History, Migration, Software compatibility, PC replacement 7

Looking for guidance Few books on this topic SAM (IT Infrastructure Library Services) Some books provide some guidelines but most discuss tools Papers: mostly on source code 8

Looking for guidance ITIL service development: 5 processes: Service level management, Financial management for IT services, Capacity management, IT service Continuity management and Availability management ITIL service support: 5 processes and 1 service: Configuration management, Change management, Incident management, Problem management, Release management and the Service desk 9

Looking for guidance ITIL brings a common vocabulary to service development and service support ITIL certifies individuals but not enterprises In ITIL, Asset Management is a recognised accountancy process The SAM book from ITIL does not bring the same standardization level as service support and service development Can there be a standard on SAM to obtain a common vocabulary and understanding? Can certification be done at the enterprise level? 10

What Is ISO? ISO: International Standardization Organization. Identifies international standards for business, government and society and works in partnership with that sector The sector can include: Agriculture and construction Mechanical engineering Manufacturing and distribution Information and communication technologies 11

ISO and Software and System Engineering For Software and System Engineering, a specific committee: JTC1 /SC7 JTC1/SC7 has the following mandate, or terms of reference, from ISO and IEC: Standardization of processes, supporting tools and supporting technologies for the engineering of software products and systems All strategic decisions are referred to the ISO members, who meet for an annual general assembly Note: IEC : International Electrotechnical Commission was established in 1906 http://www.jtc1-sc7.org/ 12

ISO and Software and System Engineering Member bodies: Australia (SA) - Standards Australia http://www.standards.org.au/ Canada (SCC) - Standards Council of Canada http://www.scc.ca Sweden (SIS) - Swedish Standards Institute http://www.sis.se. USA (ANSI) - American National Standards Institute http://www.ansi.org United kingdom(bsi)-british Standards Institution http://www.bsi-global.com http://www.iso.org/iso/en/aboutiso/isomembers/memberlist.membersummary?membercode=10 13

ISO/SC7 History 1987 - formation of JTC1/ SC7 1991 - publication of ISO/IEC 9126 Software engineering product quality 1995 - publication of ISO/IEC 12207 Information technology software life cycle processes 2000 - name changed to Software and System Engineering In 2004: 79 published standards 14

Guidelines of the ISO SAM group (WG21): Governance: Policies, processes and procedures Upper management buy-in Roles and responsibilities of SAM manager must be formally defined Budget assigned Formalize the process or it will be neglected Just another file in the pile 15

WG21 Approach : SAM Motivation Define SAM Consider international constraints Produce a list of checklists for which compliance can be verified Help define the role of a SAM manager Outline interactions with other functions 16

WG21 Approach : SAM Motivation TAG would help the reconciliation process between licence and software Without process, interpreting data is awkward SAM process ensures we know why we collect data: it comes first 17

WG21 Approach : 19770-1 and 19770-2 ISO/IEC 19770-1 software asset management processes Is well on its way to becoming a published standard ISO/IEC 19770-2 software asset management tag The purpose is to define an industry-wide IT standard for the data needed to identify and manage software assets 18

WG21 Approach : 19770-1 SAM Processes ISO/IEC 19770-1 SAM processes: Control environment for SAM (e.g. Corporate governance, roles and responsibilities) Planning and implementation processes for SAM (e.g. Planning, monitoring and improving SAM) Inventory processes for SAM (e.g. asset identification and control) 19

WG21 Approach : 19770-1 SAM Processes Verification and compliance processes for SAM (e.g. Asset records, Licensing compliance, Conformance verification) Operations management processes and interfaces for SAM (e.g. Relationship and Contract management, SLA, Security Management) Life cycle process interfaces for SAM (e.g. Acquisition, Incident Management, Problem Management, Retirement Process) 20

WG21 Approach : 19770-1 SAM Processes Note: Names of categories are subject to change. 21

WG21 Approach : 19770-2 SAM TAG ISO/IEC 19770-2 SAM TAG purpose: To define an IT-industry-wide standard for the data needed to identify and manage software assets (e.g. Planning, monitoring and improving SAM) Possible data model: Application Manifest Asset Management Tag Application Rights 22

WG21 Approach : 19770-2 SAM TAG ISO/IEC 19770-2 SAM TAG: Better inventory management To provide more accurate inventory of the software applications in all environments Increased security To prevent unauthorized execution of applications Intelligent servicing E.g. trial applications may not be patched, or only select patches that increase the security of the computing platform may be patched 23

WG21 Approach : 19770-2 SAM TAG ISO/IEC 19770-2 SAM TAG: Improved administrative controls certain software assets may not run, or may not run beyond a certain threshold or certain time period 24

WG21 Approach : 19770-2 SAM TAG Scope questions: Should file header information of software assets be standardized? (Asset Management Tag fields) Can non-run-time licensed assets such as fonts and graphics be part of the same scheme but have different characteristics? What about legacy software? Should the standard specify only a logical data structure, or should it specify functionality in the form of an API? 25

What It Means for You? Benefits Risk management: SAM should facilitate the management of business risks (I.E. Legal and regulatory exposure) Cost control: SAM should facilitate cost control (I.E. Such as by negotiating better pricing through improved use of volume contracting arrangements) Competitive advantage: SAM should help the organization gain competitive through the better quality decision 26

SAM in perspective thesis of David Dery Sof tware Installation IT Operations Tech. Support Customers and Users 1 Serv ice Lev el Agreement SAM serv ices (licencing) Serv ice Request Incident/problem Resolution SAM support planning and Control 3 5 Sof tware Manuf acturer (Licence owner) Incidents calls Serv ice Desk 2 OLA SAM Sof tware Asset Management Incident/Serv ice ticket Purchase requests Purchase planning and control 4 2006 David Dery Ph.D. Thesis Purchasing Purchase / Billing 27

Conclusion All organizations need to manage the goods they purchase: From their acquisition through their disposal However, managing intangible goods such as software assets poses some specific inventory problems: It is not only sufficient to determine how many copies of a specific software exist within the enterprise, it also includes knowing how many of them have valid licences and determining what to do about the others 28

Conclusion The cost and the risk of not managing adequately software asset management has grown in importance and it has gained international recognition within ISO: A standard with two subparts will be published in the near future: ISO/IEC 19770-1: SAM processes ISO/IEC 19770-2: SAM tag ISO provides a definition of SAM: effective management, control and protection of software assets within an organization Implementing ISO/IEC 19770-1 could lead to the certification of the enterprise 29

References: To learn more About ISO/IEC 19770 1 and ISO/IEC 19770 2 www.iso.ch and www.iso19770.com About ISO s Software and system engineering activities: www.jtc1-sc7.org About research in Software and System Engineering: www.gelog.etsmtl.ca/publications.html About purchasing standards: through the national body: in the USA : http://webstore.ansi.org/ansidocstore/default.asp 30

Questions? David Dery ETS: david.dery.1@etsmtl.ca 31