Showing posts with label license compliance audit. Show all posts
Showing posts with label license compliance audit. Show all posts

Thursday, June 30, 2016

Ask for Software License Compliance Help - Get Audited

This post is in response to a LinkedIn post entitled "A Customer Asked Oracle for EULA Help and Here's What Happened" - Originally posted on ITAM Channel web site (HERE).


Here's my comment with additional supportive data:

"Lesson learned - for the thousandth time: Do NOT engage the copyright holder (or its 'independent auditor' friends) in conducting a review of your software portfolio. The result is invariably a costly punitive audit of your enterprise - often followed up by 'me too' audits as other copyright holders 'discover' that you can't effectively manage your technology environment.


Reality Check: It isn't just Oracle - it's nearly every major software publisher and a large percentage of the less than major publishers.



Reality Check Number 2: Since we began recommending that asset managers monitor settlements and keep them in an "Audit Trends" notebook, the software industry and its enforcement friends have nearly eliminated ANY public reference to a majority of audits. When virtually no one knows the true negative impact of software audits, then no one will be effectively prepared to counter one. (And we STILL don't "get it" that we're being hunted in a seriously crooked game of software safari.)

It's been over twenty years since the software industry players ramped up their predatory enforcement actions, yet the average enterprise remains virtually clueless regarding the risks they take in not proactively, and aggressively, managing the entire life cycle of software goods, services, and contractual relationships. 


Try this on for size: You know those 5% of audits that are actually made partially public? The amount of the fines in the publication represents less than 1/3 to 1/6 of the actual financial impact of the audit on the targeted enterprise. (To put it more clearly, actual audit costs are between 3 and 6 times the published fines - and that's a VERY conservative percentage.)

If you have ANY doubt (even if you have no doubt), get your people trained in effective software and copyright compliance assurance. Be sure that your asset managers understand the wide range of license types and the potential of each license to put your enterprise at risk. Or, if you really want to pay more for less, carefully vet ANY group you hire to help you with license management.


Historically speaking, in the mid-90s, the client-server software industry players discovered that they could take a page from the mid-range and mainframe players and gain a significant revenue stream merely by auditing their customers for license compliance. Through their own attitudes, they created an "us versus them" atmosphere within an entire industry.

This predatory audit attitude was made even more lucrative when many of the software players and their friends began hyper-enforcing license terms and conditions. Highly paid legal teams began re-crafting software license agreements to include multiple onerous terms and conditions (Ts and Cs).  These Ts and Cs were intentionally built to ensure that virtually any enterprise without a crack legal team of its own would be guaranteed to violate at least one--frequently more--license clause (or clauses).

Result? Instant violation.

Couple these new license styles and a downright greedy audit attitude with intense lobbying to create even more consumer unfriendly copyright-related laws and regulations and the entire world is now expected to view ineffective software asset management as intentional software piracy. 

Think I'm wrong? Read any settlement relating to software license violations. In excess of 90% of these will blithely label any licensing mistake - any level of non compliance - as piracy. After all--piracy generates better publicity than inability to manage the asset.

So? The result? Software publishers literally leap at ANY opportunity to audit your enterprise, and if your enterprise is a small- to medium-sized company, you get to be in their 'favored target status group'. Companies in these categories have proven themselves easy audit targets as well as being the most willing to merely write a check when confronted. Keep in mind that any sane corporate lawyer--even the part-timers--will always push to settle out of court--hence the ease of confrontation to settlement audit opportunities.

Want to become a target? Here's the brief list of options:
  1. Call technical support
  2. Displace virtually ANY major software product with one from a competitor
  3. Call and ask for licensing help
  4. Order upgrade licensed products
  5. Acquire ANY "free" software products
  6. Forget about removing demo or eval licensed products
  7. Purchase COTS products at your local office supply store
  8. Buy ANY software title online
  9. Accept named user licensed products
  10. Distribute products across your enterprise without reading the permissions
  11. Speak the wrong sentence to a supplier rep or software publisher rep
I could go on, but you should get the picture by now. Non compliance is not about licensing. It's about revenue streams and licensing sharp practices. As business technology consumers we have to wake up and recognize that we're being constantly placed on the defensive--reacting to supplier predatory audit practices. There are only two realistic methods to minimize these audits.

First:
Get trained to proactively manage the entire software portfolio of goods, services, and contractual relationships. That means REAL training, not training developed or sponsored by the very enterprises that have set you up for audit in the first place.

Next:
Carefully negotiate every license with compliance in mind. Recognize that the absolute root cause of 90% of license non compliance is the reality that business technology consumers simply have no clue how licenses actually work. In a majority of cases, those being audited have never read those licenses, let alone negotiated the onerous terms and conditions out. When we recognize that the supplier fully intends to hyper-enforce all license clauses, why wouldn't we ensure that those licenses are negotiated to be mutually beneficial?

Closure: Yes, you could contact the software publisher when you are concerned about compliance issues, but it's nearly a 100% guarantee that their first response is going to be to audit you.

Time for some serious changes?

Monday, January 9, 2012

Selecting a License Compliance Discovery Tool

This post is an answer to a LinkedIn question regarding selecting a compliance discovery tool. There is a wide range of considerations when you are interested in investing in this tool. These are only a few. For additional information, please look over The Institute's online Knowledge Brief: “Selecting & Using the Systems Discovery Tool.”

It looks to me like you are primarily concerned about compliance but it's important to recognize that the discovery tool, in and of itself, is not going to do much more than let you know what's present. The most effective discovery tools will contain a dynamic database that includes identifiers for a majority of software products. When it runs the systems, it will compare what you have loaded against its database to identify what you actually have present. This information should include, at least, the precise name of the product, version &/or release, copyright data, size of the executable file & date the executable was finalized. Part of the reason for all this is to prevent users from merely re-naming a file so that it's "hidden" from the tool (that strategy won't work with a good discovery tool). An effective discovery tool will also permit you to add legacy applications (or others not currently in the database) so that you can adjust to your specific environment. The quality of this database, as well as your ability to adjust for missing products, represent serious considerations in selecting a product.

A key element of the database also includes whether or not you can adjust the system to run specialized scans for items such as fonts, graphics, or other problem products that show up as "surprises" during audits. You should also be capable of looking for MP3s, games, &/or video files.

What you want to accomplish with the discovery tool is a baseline analysis of configurations - what's loaded. You'll then compare this baseline against your proofs of possession (licenses & etc) to determine what "should" be on the systems. From that baseline you'll eventually begin monitoring the systems to identify two factors:
  1. What products "should" be present but are missing
  2. What products do not belong but are present
In the first case, you have a need to add correctly licensed missing products. In the second, you will have identified products that may or may not be non compliant. If non compliant, they should be removed or licensed (but ensure the install dates match up with your proofs of purchase). When you monitor by exception, you significantly reduce your work load.

What all this implies is that you genuinely have all your proofs of possession under control for eventual entry into the "approved product" database. This side of the discovery tool permits you to establish what you are legally permitted to possess and it will help you reconcile against the configurations. This provides you with a snapshot of compliance status.

As to an uninstall tool: Recognize that the "built-in" uninstall tool for your operating system is not very dependable. It tends to leave elements of applications behind that "could" expose you to hidden audit issues. Depending on your size & systems environment, you can possibly acquire an open source uninstall tool. However, an effective uninstall tool is critical to to compliance assurance.

Another very important issue that Karan mentions is the entire discovery tool acquisition & implementation process. You should be able to have a discovery tool operational in less than 5 hours on a client-server network - more or less depending on the number of client systems the tool has to audit as well as the focus of your install team. Of more importance will be the amount of bandwidth the tool sucks up as it runs the systems reviews - keep it low and minimize the downtime time while it audits a device. Also keep in mind that you may want to run independent reviews of systems that are not accessed via the network - or on remote systems. This option should be considered in tool selection.

Further, is the discovery tool easily managed by a "normal" human being? I.E. a non-techie? Too many of these tools are so over-engineered that it requires an unnecessarily costly team to manage & operate the product. Be sure that any advanced clerical worker can generate & manipulate reports as well as manage the over-all system. This will drastically reduce ongoing costs.

Finally, if you are doing compliance for the sake of compliance, you are wasting money. I know that sounds wrong but, in reality, the majority of cost & risk reductions for your enterprise will be derived from effective life cycle management of both software AND hardware. Yes... You DO have to maintain compliance, but do not stop there. Usually, enterprises that stop with compliance miss out on the true value of SAM & ITAM. The core issue with this comment is that, whenever you select a discovery tool, ensure that it will also help you monitor your hardware configurations.

At the end of the day, it's important that we begin our search for "just the right tool" with a clear concept of what we want that tool to accomplish, in what environment, and with what level of internal talent. There is significantly more to this topic but, since we cover it in our online training, it's best for those who are interested to follow up with the specialized training. 

Please let me know if this helps or if you need additional information!

Saturday, April 17, 2010

Minimizing Costs & Risks of Business Technologies - Online Seminar Series

Free Online Knowledge Briefing - April 22nd, 2010

For over ten years, I have commented that we lose way too many of our technology dollars to essentially empty IT spending.
Industry studies have consistently backed up my perspectives, with some actually placing losses at more than $10 for every $1 spent. There a plenty of purported solutions to this waste. Unfortunately, very few of them are designed to produce positive ROI without serious additional spending.
On April 22nd, 2010 I'll deliver the first of an online Knowledge Briefing Series covering a wide range of methods any company can use to minimize risks while putting the brakes on wasteful IT spending - without negative impact on your budget or operations.
Tired of the unnecessarily high costs & risks of business technologies? This is your chance to identify the life cycle technology asset management issues that create those problems and to walk through the simple, common sense, and cost effective procedures that you can use to begin saving serious IT dollars.

Each registered participant receives a customized Session Workbook to use in documenting delivered content. We'll add to the Workbook with each new online session we deliver.

Let's conduct a quick cost-benefit analysis...

The Costs?
  • It's free...
  • The methods are proven,
  • I'm not selling you anything and,
  • It's only a single hour out of your day...
The Benefits?
Your company could easily begin converting those all-too-frequently negative technology investments to gaining $5 (or more) in value for every $1 you spend.


You have absolutely nothing to lose and everything to gain.

Series intro URL: Minimizing Technology Costs & Risks, April 22.
Session One: Minimizing Exposure to Punitive Software Non Compliance Audits