Software asset management and security

Opinion
Jan 5, 20113 mins

As I mentioned in my previous column, the most recent Business Software Alliance (BSA) report on the scope of international software piracy dates from October 2009 and is freely available for download as a PDF.  

What kinds of risks result from illegal downloading of software?

The BSA points out that consumers who buy cheap, illegal copies of software or download free pirated programs run serious risks including

• Putting personally identifiable information at risk for identity theft (what would one expect when dealing with thieves?);

• Receiving the wrong software (and what are the victims going to do – complain to the police?);

• Finding that the pirated copies are nonfunctional;

• Never receiving any product at all;

• Failing to receive “upgrades, technical support, manuals or appropriate documentation;”

• “Receiving an incomplete, altered, or trial version of the software;”

• “Infecting the consumer’s computer with viruses or tools for remote-controlled cyber crime.”

Organizations must guard against installation of stolen software on their systems. For example, in 1998, the Los Angeles Unified School District (LAUSD) was found to have made illegal copies of software and was threatened with $5 million in penalties when auditors located over a 1,000 illegal copies of commercial programs such as Microsoft Word and Adobe Photoshop that would have cost about $500,000 in license fees; the lawsuit from the BSA was settled for $300,000 in penalties and a promise to “replace illegal copies citywide with licensed versions at a cost of nearly $5 million.”

Software asset management (SAM) is the practice of keeping an up-to-date inventory of all the software installed on an organization’s systems, including in-house servers and workstations and mobile devices such as laptop computers and smartphones. SAM provides a basis for detecting overused, underused and illegally-installed software and thus plays a valuable role in information assurance.

To avoid the kind of disaster experienced by the LAUSD, organizations should use SAM software to audit their entire installed base and build an accurate picture of exactly which software is running on which computers. Such information not only permits network and security managers to avoid legal snares from unauthorized software, it also lets them identify potential breaches of corporate policy governing the configuration of corporate systems – and the people involved in such breaches. 

Finally, with appropriate metering, the SAM solution should be able to track how the legally installed software is actually being used – and discover where corporate assets are underused or never used. Those licenses can be shifted to other users who can make better use of them or simply not renewed at the next renewal cycle.

For a good guide to SAM, see ScriptLogic’s white paper, “IT Administrators Guide to Software Asset Management,” which is what got me started on this article in the first place. ScriptLogic makes the AssetManager v7.0 product which seems interesting and useful.

[Disclaimer: I have no association with ScriptLogic and have not used their products.]