Category: Compliance

  • Preparing for a Software Licence Audit

    Preparing for a Software Licence Audit

    Software audits are not just for large companies. Vendors audit small businesses too. Being ready is mostly a matter of keeping decent records.

    What a Software Audit Is

    A software licence audit is when a vendor checks whether the number of licences you have purchased matches the number you are actually using. If you are using more than you have paid for, you may have to buy additional licences. If you have paid for more than you use, you are unlikely to get a refund, but at least you will know.

    Audits are usually initiated by the vendor as part of their contractual right to verify compliance. Some are routine, others are triggered by a discrepancy in purchasing data.

    Which Vendors Commonly Audit

    The vendors most likely to audit are those with the most to lose from under-licensing:

    • Microsoft – audits Microsoft 365, Windows, and server products. Microsoft runs compliance checks regularly.
    • Adobe – audits Creative Cloud and Acrobat deployments, particularly in design and marketing firms.
    • Salesforce – checks user counts against contracted seats.
    • SAP and Oracle – less common in very small businesses, but they do audit mid-sized companies.

    If you use any of these, it is worth assuming you could be audited at some point.

    What They Ask For

    A typical audit request includes:

    • A list of all installations of the vendor’s software across your devices
    • Proof of purchase for each licence
    • The number of users assigned to each product
    • Access to run a scan or review your admin console

    The vendor may send a self-declaration form, or they may ask to run a discovery tool on your network. Either way, they want to compare what you have installed against what you have paid for.

    How to Prepare

    The best preparation is to keep records as you go, rather than scrambling when an audit notice arrives.

    Keep licence records. For every software purchase, store the invoice, the licence agreement, and the number of seats. This applies to both annual and monthly subscriptions.

    Track deployments. Know which devices or users have which software installed. If you use Microsoft Intune or Google Workspace, your admin console already holds this information. For desktop software, keep a manual list.

    Document purchases. If you buy licences through a reseller, keep the reseller invoices. If you buy direct, keep the order confirmations. Store them somewhere you can find them in a hurry.

    Review annually. Once a year, compare what you are paying for against what is actually deployed. This is the same process described in the article on cutting software costs, and it serves double duty here.

    What to Do If You Are Audited

    If you receive an audit notice:

    • Do not ignore it. Responding late makes things harder.
    • Nominate one person to deal with the vendor.
    • Gather your licence records and deployment data before responding.
    • If you find gaps, address them before the audit concludes. Buying the licences you are short on before the audit closes is usually better than waiting for the vendor to find the shortfall.
    • If the audit feels heavy-handed or you are unsure of your position, consider getting advice from an IT consultant or your reseller.

    Practical Takeaways

    • Keep invoices and licence agreements for every software purchase.
    • Track which users and devices have which software installed.
    • Review your licence position at least once a year.
    • If audited, respond promptly and nominate one person to handle it.
    • Being prepared means the audit is a paperwork exercise, not a crisis.

    What this looks like in practice

    Google Workspace: AssetGraph pulls licence data from Gmail invoices – “12 Business Standard seats at £9.60/seat/month” – and cross-references with Google Admin sign-in activity. You can show auditors exactly how many licences you have, how many are in use, and what each one costs.

    Microsoft 365: Outlook invoices like “25 Business Premium seats at £17.55/seat/month” are captured automatically. Intune confirms which devices are licensed. Every licence purchase, renewal and cancellation is in the audit trail with timestamps.

    Auditors want evidence, not spreadsheets. AssetGraph gives you a timestamped record of every licence and device, ready to export.

  • ISO 27001 and Asset Management Requirements

    ISO 27001 and Asset Management Requirements

    ISO/IEC 27001 is the international standard for information security management systems (ISMS). It defines a risk-based framework for protecting information assets, and a significant portion of its Annex A controls concern asset management specifically. For organisations pursuing or maintaining ISO 27001 certification, the ability to demonstrate accurate, up-to-date asset records is not optional – it is a core requirement of the audit.

    This article explains what ISO 27001 requires for asset management, where the common gaps are, and how automated asset tracking helps meet the standard’s expectations.

    The Structure of ISO 27001

    ISO 27001 is structured in two parts:

    • Clauses 4-10 define the management system requirements – how the organisation plans, operates, and improves its ISMS.
    • Annex A contains the reference controls. These are the security measures organisations select based on their risk assessment, using the ISO 27002 standard for implementation guidance.

    Asset management sits within Annex A.8. The 2022 revision of ISO 27001 reorganised the controls, and Annex A.8 now contains five controls covering identification, classification, and handling of information and assets.

    Annex A.8 Controls

    ### A.8.1 – Identification of Assets

    This is the foundational asset management control. It requires the organisation to identify all assets relevant to the ISMS and to maintain an inventory of them. The standard explicitly states that an asset inventory should be maintained throughout the asset lifecycle, from acquisition through to disposal.

    Assets in scope include not only hardware but also software, data, services, and people. The inventory should identify each asset’s owner, location, and classification.

    For most organisations, the asset inventory is the area where automated tracking delivers the most value. A spreadsheet that is updated quarterly cannot meaningfully satisfy “maintained throughout the lifecycle”. An API-driven register that polls MDM, cloud, and identity providers can.

    ### A.8.2 – Classification of Information

    Information assets must be classified according to their sensitivity and criticality. Typical classifications include Public, Internal, Confidential, and Restricted. The classification determines how the information is handled, stored, and transmitted.

    Asset tracking supports this control by providing the context needed for classification: knowing which device holds which data, and who has access to it, is a prerequisite for applying the right classification in the first place.

    ### A.8.3 – Handling of Assets

    This control addresses the physical and logical handling of assets – storage, transmission, processing, and disposal. It requires procedures for secure media handling and for the secure deletion of data when assets are decommissioned.

    An asset register that records lifecycle state – including when a device was retired and how its data was sanitised – directly supports an audit of this control.

    ### A.8.4 – Access to Information

    Annex A.8.4 requires that access to information and associated assets be restricted to authorised users. Asset tracking contributes here by maintaining the mapping between users, devices, and the information they can access. When an employee leaves, the asset register should reflect which devices and licences need to be revoked.

    ### A.8.5 – Secure Development

    While primarily aimed at development practices, this control has asset management implications: development environments and test data are themselves assets that must be inventoried and managed.

    The 2013 vs 2022 Revision

    Organisations certified under the older 2013 revision of ISO 27001 should note that Annex A.8 was restructured in the 2022 update. The 2013 version had a more granular set of controls under A.8, including separate controls for media handling (A.8.2) and access control (A.9). The 2022 revision consolidated and simplified these, but the underlying requirements are substantially the same: identify your assets, classify them, control access, and handle them securely.

    All new certifications and surveillance audits now use the 2022 version. If your asset management practices satisfied the 2013 controls, they will largely satisfy the 2022 ones, but the mapping between controls has changed and your statement of applicability should be updated accordingly.

    Where Organisations Fall Short

    In audit experience, the most common asset management findings are:

    • Incomplete inventories. Cloud instances spun up by developers, SaaS subscriptions bought on a corporate card, and contractor laptops enrolled in the MDM but not added to the asset register all represent untracked assets.
    • No ownership assigned. An inventory that lists assets but does not identify an owner for each one fails to meet A.8.1. Without ownership, accountability for security and lifecycle management is unclear.
    • Stale records. An inventory that lists devices retired months ago, or omits devices acquired since the last update, does not reflect reality. Auditors test this by comparing the inventory to live system data.
    • No lifecycle tracking. The standard requires assets to be managed throughout their lifecycle. An inventory that records acquisition but not retirement, or that has no record of how decommissioned assets were disposed of, is incomplete.

    How Automated Tracking Supports Compliance

    Automated asset tracking addresses each of these gaps directly.

    Completeness. By polling multiple authoritative sources – MDM, identity provider, cloud provider APIs, EDR – automated discovery captures assets that manual tracking misses. A cloud instance appears in the inventory the moment it is created, not the next time someone updates a spreadsheet.

    Ownership. Identity-integrated asset tracking associates each device with the user registered in the identity provider, providing a natural owner for each asset. Where no user is associated, that itself is a signal worth investigating.

    Currency. API-driven polling refreshes the inventory on a defined schedule – hourly, daily, or at whatever interval suits the organisation. The inventory reflects the current state of the estate, not a historical snapshot.

    Lifecycle. By tracking lifecycle state explicitly – active, in maintenance, retired – and recording state transitions with timestamps, the system produces an audit trail that demonstrates compliance with the “throughout the lifecycle” requirement.

    Evidence. Auditors do not take claims at face value. They want evidence: logs, exports, reconciliations. An automated system produces these as a by-product of its normal operation. A spreadsheet does not.

    Preparing for Audit

    If you are approaching an ISO 27001 audit, the asset management evidence you should be able to produce includes:

    1. A current asset inventory covering hardware, software, and information assets 2. Evidence of ownership for each asset 3. Classification assignments for information assets 4. Records of asset lifecycle transitions, including retirement and disposal 5. Reconciliation between the inventory and live system data, demonstrating that the inventory is accurate

    Automated tracking makes all of these straightforward to produce. The inventory is a query against the tracking system. Ownership comes from the identity integration. Lifecycle transitions are recorded as state changes with timestamps. Reconciliation is a comparison between the tracking system’s view and the underlying source APIs.

    ISO 27001 does not prescribe how you maintain your asset inventory – it specifies what the inventory must contain and what it must demonstrate. Automated tracking is not a requirement of the standard, but it is the most reliable way to satisfy the standard’s expectations in a modern, dynamic IT estate where assets are created, changed, and retired continuously.

    What this looks like in practice

    Google Workspace: Google Admin shows every managed device. Gmail picks up procurement emails like “12 Chromebooks purchased, £449 each”. AssetGraph logs who has each device and when it was assigned – exactly what ISO 27001 Annex A.8 requires.

    Microsoft 365: Intune provides the full device inventory. Outlook catches emails like “Surface Laptop 5, serial #ABC987, assigned to J. Smith”. Every device change is logged with a timestamp for your audit trail.

    Both platforms feed the same audit-ready asset register, so ISO 27001 evidence is always current.