Have you experienced the management dilemma of software compliance auditing?
Most organisations have but won’t admit to it, whilst they continue to waste money and resources!
What is the dilemma?
The dilemma is para-phrased within the following questions- “Are we getting value for money from conducting software compliance audits? What are they achieving for us? How current are they? Do they really make a difference?
Consider the following;
Traditional software compliance audits generate lots of audit data
Are time consuming
Are done covertly
Are restricted to IT specialists either in-house or consultants
Are done as a low priority task
Are often stop-start affairs
Are often never completed
Frequently have to be redone, over and over and over again
Consume enormous amounts of network bandwidth when parameters are set
incorrectly
Some audit tools require specialist SQL skills to work
Some audit tools require database recognition to generate results
Some audittools increase risk due to lack of knowledge by the technologists
performing the audit
Some audit tools are using the wrong technique (and don”t know it)
Some tools increase risk due to exposing sites to port scanning during web
based audits
Some tools result in many false positives and misleading results
Rarely match audit data to proof of purchase records
and finally, consume enormous amounts of money and resources
Software Compliance Audits for many businesses and organisations areso low down the priority chain that the software audit is continually put off, thus increasing the risk to senior
management and stakeholders.
The MOST significant issue is that software compliance is NOT the core business activity of the entityand the money spent (as an overhead cost) on traditional auditing
techniques is TOTALLY WASTED.
This is no way to run your business entity, when the money could be far better s