Software Compliance
  • Home
  • What We Do
    • Services
    • Tools
    • Experience
    • FAQ
  • Resources
    • Company >
      • About Us
      • Careers
    • Agreements
    • Documentation >
      • Brochure
      • Datasheet
      • Security Measures
      • ComplianceWare >
        • Software
        • Hardware
        • Cloud Configuration
  • Contact Us
  • Latest
  • Search
And the latest is ...

SAM Practices - The NASA Experience

25/1/2023

0 Comments

 

Internal Audit Report highlights flaws in NASA's SAM Practices that many organizations will relate to.

Oh oh ... it's 2023 yet we see it all here again: "Software Asset Management practices at NASA currently expose the Agency to operational, financial, and cybersecurity risks with management of the software life cycle largely decentralized and ad hoc."
Picture
The OIG summary of their SAM audit says it all: 
  • Efforts to implement an enterprise-wide Software Asset Management program have been hindered by both budget and staffing issues and the complexity and volume of the Agency’s software licensing agreements.
  • NASA has not implemented a centralized Software Asset Management tool to discover, inventory, and track license data as required by federal policy.
  • NASA’s Software Asset Management policy is not comprehensive or standardized, leaving roles, responsibilities, and processes unclear.
  • Training for software license use and management is inconsistent across the Agency, with aging web-based training randomly assigned to personnel and a lack of a general software licensing training course available to the entire workforce.
  • NASA’s current efforts to compile a complete and accurate report of annual software spending is a time consuming and mostly manual effort.

... with all of the above quantified in cost terms as:

​We estimate the Agency could have saved approximately $35 million ($20 million in fines and overpayments and $15 million in unused licenses) and moving forward could save $4 million over the next 3 years by implementing an enterprise-wide Software Asset Management program.
All very compelling to implement improvements and progress NASA’s Software Asset Management from “basic” — the lowest of the four rating options in the Software Asset Management Maturity and Optimization Model developed by Microsoft — through the scale as per tiers and representations below:
  • Basic. Software is managed on an ad hoc basis with few, if any, comprehensive policies.
  • Standardized. The agency uses a discovery tool or data repository for tracking assets, although the information may not be complete or accurate enough for decision-making.
  • Rationalized. Assets are actively managed, and the agency has put in place policies, procedures, and tools integrated into the full IT asset life cycle.
  • Dynamic. Assets are optimized, with near real-time alignment with changing business needs.
The report is an insightful read for all SAM practitioners - and responsible management and executives - with clear language and succinct descriptions of the scope and challenges in the field of software asset management, and a pragmatic approach to the creation of an effective SAM Practice that applies to any size organization with a notable software inventory, not just those on the NASA scale.

So, to the findings ...

It was recommended that the Chief Information Officer:
(1) establish enterprise-wide (institutional and mission) Software Asset Management policy and procedures;
(2) implement a single Software Asset Management tool across the Agency;
(3) align the Agency Software Manager position to report to the Agency Chief Information Officer;
(4) establish formal legal representation and guidance for vendor software audits;
(5) establish a software license awareness training ‘short course’ focusing on approvals, compliance, and other issues a general user might encounter;
(6) implement a centralized repository for NASA’s internally developed software applications; and
(7) develop an Agency-wide process for limiting privileged access to computer resources in accordance with the concept of least privilege.

Additionally, to strengthen the financial aspects of NASA’s Software Asset Management it was recommended that  the Chief Financial Officer:
8) implement a “penalty spend” classification in SAP to track license infractions and true-up payouts and
9) centralize software spending insights to include purchase cards.

Nothing fresh there, just the usual (and often unheeded) advice. 

0 Comments



Leave a Reply.

    • ​+
    • +
    • +
    <
    >

    Categories

    All
    Adobe
    Agreements
    Appliances
    Audit
    BCP & DR
    Cloud
    Compliance
    ComplianceWare
    Contracts
    Forums
    HCL
    IBM
    Intel
    ITAM
    Licensing
    Mainframe
    Marketplace
    Microsoft
    Negotiating Deals
    Open Source
    Oracle
    Partnering
    Red Hat
    Roles
    SAM
    Software Metrics
    SQL Server
    Support
    Windows Server

    Archives

    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    June 2020
    May 2020
    April 2020
    March 2020
    February 2020
    January 2020
    December 2019
    November 2019
    October 2019
    September 2019
    August 2019
    July 2019
    June 2019
    May 2019
    April 2019
    March 2019
    February 2019
    January 2019
    December 2018
    November 2018
    October 2018
    September 2018
    August 2018
    July 2018
    June 2018
    May 2018
    April 2018
    March 2018
    February 2018
    January 2018
    December 2017
    November 2017
    October 2017
    September 2017
    August 2017
    July 2017
    June 2017
    May 2017
    April 2017
    March 2017
    February 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016

Unravelling license complexity for Business
ACN 623 529 751

Privacy Policy | Terms of Use
Copyright © 2016-2024 (SWC) ​​

  • Home
  • What We Do
    • Services
    • Tools
    • Experience
    • FAQ
  • Resources
    • Company >
      • About Us
      • Careers
    • Agreements
    • Documentation >
      • Brochure
      • Datasheet
      • Security Measures
      • ComplianceWare >
        • Software
        • Hardware
        • Cloud Configuration
  • Contact Us
  • Latest
  • Search