Steve Klos of Agnitio Advisors provides a quick overview of the International Standard for Software Asset Management. This is an edited version of a discussion in the Software Asset Management forum on LinkedIn. Steve is the convener of the ISO/IEC 19770-2 standard development process.
19770-1 – this is the standard focused on SAM processes. This standard defines 70 different items that a company needs to manage via people, processes and/or tools to ensure they address all SAM requirements. If a company has mature processes that address every one of the 70 items defined in the standard, it DOES NOT mean that they are compliant with all software licenses. What it means is that they will know their compliance position for every software title and will know if they are out of compliance.
19770-2 – the software identification tag – this standard is focused on authoritative software identification. The goal here is to provide definitive information on exactly what is installed on a computing device and provide more than just the basics. The information is provided in a standardized data structure (XML file) and the standard defines 7 mandatory elements and 27 option elements. If optional elements are provided by the software publisher, end-user organizations and SAM tools will be able to identify additional information such as what suite the product is associated with and the distribution channels the specific software installation was targeted for. In general, software tags will be “discovered” as part of an inventory process on corporate computing devices (desktops, notebooks, servers, PDA’s, etc).
19770-3 – the software entitlement tag – this standard is focused on software entitlement definitions. The goal in this standard is to create a standardized data structure (XML file) that can be used to specify what an organization has purchased as well as how and where the purchased item should be measured/tracked. These entitlements should not be using legalese terms for licenses, but rather defining exactly what it is an organization needs to validate in order to know if an entitlement is used. This standard is related to 19770-2 by the fact that unique reference information in 19770-2 and 19770-3 can be reconciled to identify software titles that are related to software entitlements. Other elements in 19770-3 provide details on what information needs to be validated and where that information needs to be captured in order to identify if an entitlement is used or not. In general, this software entitlement tag will be delivered through the purchasing process.
When I ask ITAM professionals about their transition to the cloud, the responses are often similar. “It wasn’t my decision.” It’s striking how many people feel this way—decisions about moving from on-premises solutions to the cloud ...
Marks & Spencer (M&S), the iconic UK retailer, recently became the latest high-profile victim of a devastating cyberattack. Fellow retailers The Co-Op and Harrods were also attacked. Recent reports suggest the rapid action at the Co-Op ...
During our Wisdom Unplugged USA event in New York in March 2025, we engaged ITAM professionals with three targeted polling questions to uncover their current thinking on Artificial Intelligence—what concerns them, where they see opportunity, and ...
Podcast
No time to read? Want to stay up to date on the move? Subscribe to the ITAM Review podcast.
Marks & Spencer (M&S), the iconic UK retailer, recently became the latest high-profile victim of a devastating cyberattack. Fellow retailers The Co-Op and Harrods were also attacked. Recent reports suggest the rapid action at the Co-Op ...
During our Wisdom Unplugged USA event in New York in March 2025, we engaged ITAM professionals with three targeted polling questions to uncover their current thinking on Artificial Intelligence—what concerns them, where they see opportunity, and ...
In the world of ITAM, the regulatory spotlight continues to intensify, especially for financial institutions facing increasing scrutiny from regulatory bodies due to the growing importance of IT in operational resilience, service delivery, and risk management. ...
Executive Summary For ITAM teams, sustainability is a core responsibility and opportunity. Managing hardware, software, and cloud resources now comes with the ability to track, reduce, and report carbon emissions. Understanding emission scopes—from direct operational emissions ...