Software Asset Management SAM v4.1 (SAMAC 2014)
Software Asset Management SAM v4.1 (SAMAC 2014)
Software Asset Management SAM v4.1 (SAMAC 2014)
Standard
Ver. 4.1
June 18, 2014
Usage Restrictions:
“SAM Standard” can be used free of charge except as stated below.
(1) “SAM Standard” and any portion of its copy are distributed, issued, provided, or sent to
outside of the organization.
(2) “SAM Standard” and any portion of its copy are duplicated for distribution, issuance,
provision, or sending to outside of the organization.
(3) “SAM Standard” and all or any portion of its copy are distributed, issued, provided, or sent
for a fee.
(4) “SAM Standard” and all or any portion of its copy are translated into a foreign language.
(5) “SAM Standard” and all or any portion of its copy are adapted or altered.
(6) “SAM Standard” and all or any portion of its copy are published or distributed, issued,
provided, or sent as an attachment or appendix to a publication.
(7) “SAM Standard” and all or any portion of its copy are publicly transmitted or uploaded to
outside of the organization.
(8) “SAM Standard” and all or any portion of its copy are publicly transmitted or uploaded inside
the organization.
Software Asset Management Standard Ver. 4.1 Association of SAM Assessment & Certification
i
Introduction
Operations to evaluate the maturity level to which software asset management has been
adopted in organizations such as corporations and public institutions (evaluation of
maturity level)
Operations such as providing training, certification criteria, and other services for
organizations and consultants that provide support for establishing SAM structures, and
development in areas such as the certification and the certification management
Various operations as needed for the appropriate adoption of software asset
management
SAMAC also establishes and operates software asset management standards and
assessment criteria for use in evaluation of software asset management. This Software Asset
Management (SAM) Standard has been established within the framework of these standards
and criteria. SAMAC succeeded activity of the Software Asset Management Consortium
(SAMCon), which created SAM Standard originally, and these standards are developing
conforming to ISO/IEC19770 and related JIS standard.
Software Asset Management Standard Ver. 4.1 Association of SAM Assessment & Certification
ii
2. Members of the working group responsible for establishment of the Software Asset
Management (SAM) Standard Ver. 4.1
Software Asset Management (SAM) Standard Ver. 4.1 was established by the SAMAC
Standards Working Group. The work of establishing the standard was further divided into two
teams: the Editorial Team and the Review Team. Members of each team are listed below.
Software Asset Management Standard Ver. 4.1 Association of SAM Assessment & Certification
iii
Table of Contents
Software Asset Management Standard Ver. 4.1 Association of SAM Assessment & Certification
iv
I. About Software Asset Management (SAM) Standard
1. Background
The Software Asset Management Consortium (SAMCon) was launched on May 20, 2002 for the purpose of
organizing various issues and confusions in software asset management in Japan and introducing software
asset management to enhance a proper IT environment in an organization. Most of organizations have not
been introduced appropriate software asset management in place, although the environments surrounding
organizations have changed significantly, such as an increase in penetration rates of PCs, increasing use of
networks and Open system. One of the reasons for this is that has not been established SAM framework.
Therefore, SAMCon has put an effort into establishment of SAM Standard to provide a management guideline
for organizations interested in introducing appropriate SAM (“Software Asset Management Standard Ver1.0” on
October 31, 2002). After that, Software Asset Management Assessment Criteria was established to know the
maturity level of SAM and set SAM goals (“Software Asset Management Assessment Criteria Ver1.0” on
November 19, 2013).
In 2006, “ISO/IEC 19770-1,” the international standard for SAM, which was established and published jointly
by the International Organization for Standardization (ISO) and International Electro technical Commission
(IEC) . SAM Standard and Assessment Criteria have been revised by reference to the ISO in 2007 and 2008.
(“SAM Standard Ver2.0” on November 27, 2007 and “SAM Evaluation Standard Ver2.0” on April 17, 2008).
In 2010, SAMAC took over SAMCon’s activities and SAMCon was dissolved. SAMAC will develop a new
software asset management standards and software asset management evaluation criteria with consideration
of the environmental changes and the latest circumstances etc. surrounding the software asset management
based on the SAMCon's criteria. Since SAMAC succeeded SAMCon’s SAM Standard, which had a certain level
of market penetration, SAMAC’s new standard was named Ver3.0 to avoid confusion. Detailed revisions,
Ver3.01 and Ver3.1, were made to Ver3.
Due to the revision and publication of “ISO/IEC19770-1” in June 2012, SAMAC reviewed its standards from
the overall perspective, such as consistency with the revised ISO/IEC 19770-1, operation status with Ver3, and
current situations of the various environments surrounding SAM, and came up with a revision Ver4.1.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
1
2. Necessity and Objectives of SAM
With the progress of IT development, software assets have become indispensable to the operations of
organizations and businesses. Lack of proper management may impact a corporation significantly. In other
words, there are a lot of inherent risk factors in terms of software assets in an organization.
In particular, the following are the conceivable risks.
Given the growing importance of risk management in recent years, it is necessary for an organization to
implement SAM from a variety of perspectives in order to respond to various risks.
Although the levels to be achieved at each organization with regard to the management objectives should be
considered based on its own factors, objectives in this management standard are organized into 3 main
objectives, with an addition of competitive advantage, etc., to the 4 existing objectives, including establishment
of accountability, avoidance of legal risks, response to security issues, and TCO reductions, to be consistent
with the international standard.
Management Objectives
Risk management objectives
Accountability
Asset preservation
Avoidance of legal risks
Response to security issues
Ensuring availability, etc.
Cost management objectives
TCOP Reduction1, etc.
Competitive advantage objectives
Effective applications of software, etc.
1
TCO (Total Cost of Ownership): The total cost of owning the system throughout its life cycle, including
purchasing, introduction, maintenance and management, and disposal.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
2
3. Management Standard System
This management standard is composed of the following 9 management areas. The following areas are
classified based on the management objectives necessary for SAM. Each domain is associated with an
objective.
(1) Pol Policy: Establishment of Policy and Regulation
(2) Sys Systems: Establishment of a Managerial System
(3) Comp Competence: Establishment and Maintenance of Competence in SAM
(4) Own Ownership: Confirmation and Verification of Licenses Owned
(5) Imp Implement: Confirmation of Software and Related Asset Implemented
(6) Cost Cost Optimization
(7) Sec Security: Compliance with Security Requirements
(8) OM Operations Management: SAM Operations Management Processes
(9) LC Life Cycle Processes and Interfaces
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
3
4. Management Standard Structure
The management standard‘s structure consists of management objectives, management requirements, and
management items.
(1) Management objectives
Management objectives are the basic elements of implementing software asset management, indicating the
tasks that must be completed in order to implement software asset management. In other words, these
management objectives must be implemented in order to carry out proper software asset management.
Whether the management items of this Management Standard are suitable to the organization
Whether the management items of this Management Standard are practicable and reasonable
Whether there are other methods that may be substituted, and whether such substitute methods would
satisfy the management requirements
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
5
management focused on processes rather than management focused on results in the form of ascertaining the
actual situation.
The quality of the management system itself as a system for preventing problems and self-purification if they
do arise, is a major factor behind the success of any type of management. Accordingly, in software asset
management it is essential to establish a management structure that effectively allocates the functions of
deterrence, prevention, discover, and correction as the basic functions of management.
While essentially hardware management covers a different management domain than software asset
management, the scope of this Management Standard includes particular items related to hardware
management that can be considered essential to software asset management.
However, this means that such items need to be implemented thoroughly as part of hardware management
for the purpose of appropriate software asset management, rather than as part of software asset management
itself.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
6
The objective of the software asset management monitoring and review processes is to achieve the
management objectives of software asset management.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
7
7. Definition of Terms
Term Definition
Related assets Assets necessary for the use and management of software, including hardware and other
assets
Personnel Any individual expected to perform duties of the organization, including officers,
Management Corporate board or equivalent body, which is person or group of people who assumes
management approach individually at each site or department. Centralized management approach is a method
and centralized where management is carried out collectively by an organization as a whole. In general,
management approach cost reduction is difficult with the decentralized management approach and the risk of
unauthorized license use is higher than with the centralized management approach.
Owned license A license approved by the manufacturer of software for its use as an organization
Down-grading Use of previous versions approved within the scope of an owned license
License agreement An agreement describing the terms and conditions of a software license
version
Distribution copy Duplications of the definitive master version for the purpose of installation onto other
Underlying license License for software use as originally purchased or procured, and which can typically be
Service provider Person responsible for provision or support of an element that supports IT service
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
8
8. Establishment and Revision History
Software Asset Management Consortium
Date Revision
October 30, 2002 Software Asset Management (SAM) Standard Ver. 1.0 established
November 27, 2007 Software Asset Management (SAM) Standard Ver. 2.0 established
SAMAC
Date Revision
August 1, 2011 Software Asset Management (SAM) Standard Ver. 3.0 established
September 2, 2011 Software Asset Management (SAM) Standard Ver. 3.01 established
October 1, 2011 Software Asset Management (SAM) Standard Ver. 3.1 established
October 1, 2013 Software Asset Management (SAM) Standard Ver. 4.0 established
June 18, 2014 Software Asset Management (SAM) Standard Ver. 4.1 established
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
9
II. Software Asset Management (SAM) Standard
[Management Objective] To establish SAM policies, regulations, etc., that are suitable for the
organization
Management Policy 1 SAM policies, regulations, and procedures of the Corresponding Corresponding
ISO/IEC
Management Items 1 2 3 4
19770-1
in a way which reaches all new personnel when they start, and continuing
4.2.4.2 d) ○
personnel at least annually, and are readily accessible at all times to
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
10
Management Policy 1 SAM policies, regulations, and procedures of the Corresponding Corresponding
ISO/IEC
Management Items 1 2 3 4
19770-1
documented in all countries within the scope of SAM and are reviewed at least 4.2.2.2 c) ○
annually.
a. A SAM plan is updated at least annually and specifies matters including the scope
of SAM and assets subjected to SAM. This plan is examined from the perspective 4.3.2.2 b) ○
b. The objectives of SAM are established at least annually, and these require the 4.2.2.2 e)
○
approval of management. 4.3.2.2 a)
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
11
Management Policy 2 Risks related to SAM are assessed. Corresponding
Corresponding Tiers (Tier)
Requirements Clauses in
SAM.
management approaches
(2) Risks associated with assets subjected to SAM are analyzed and
evaluated. 4.2.2.2 d) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
12
Management Policy 3 SAM is subjected to monitoring and Corresponding
Corresponding Tiers (Tier)
Requirements auditing. Clauses in
measures.
annually to confirm whether the SAM management items are All of 4.3.4.2 a) ○
achieved.
approved by the SAM owner for the entire organization, and 4.3.4.2 b) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
13
Management Policy 4 SAM policies, regulations, and procedures Corresponding
Corresponding Tiers (Tier)
Requirements are reviewed. Clauses in
organization.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
14
Management Policy 5 SAM documents and records are controlled. Corresponding
Corresponding Tiers (Tier)
Requirements Clauses in
(1) The SAM owner for the entire organization maintains a Master of
minimum:
Date of updating
Control of changes
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
15
2. Systems: Establishment of a Managerial System
[Management objective] Managerial, educational, and auditing systems are established and maintained
management structure.
4.2.3.2 a)5) ○
Section roles and responsibilities related to corporate
is implemented reliably.
and procedures
assets
internal customers
d. All parts of the organization are covered by the SAM owner or local 4.2.3.2
○
SAM owners, without conflicting overlap. a)5)
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
16
Management Sys 1 The managerial system and responsibilities for Corresponding
Corresponding Tiers (Tier)
Requirements SAM are established. Clauses in
are communicated.
(4) The person responsible for auditing of SAM (SAM auditor) and
related SLAs
All of 4.2.3.2 a) ○
Confirmation of whether SAM policies approved by the
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
17
Management Sys 1 The managerial system and responsibilities for Corresponding
Corresponding Tiers (Tier)
Requirements SAM are established. Clauses in
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
18
3. Competence: Establishment and Maintenance of Competence in SAM
[Management objective] Systems are in place for establishment and maintenance of SAM competence
(1) SAM abilities for SAM managers and personnel subject to SAM
a. Content of training
Licensing in general
training implemented.
4.2.5.2 a)
* The results of this review can be used to confirm the content of ○ ○
1)2)
education provided and the degree of understanding among
participants.
there have been any changes in the licensing terms of software 4.2.5.2 d) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
19
Management Comp 2 Abilities for SAM auditing personnel are Corresponding
Corresponding Tiers (Tier)
Requirements defined and training implemented as necessary. Clauses in
(1) Abilities for SAM auditing personnel are defined, and such
c. SAM systems
d. Licensing in general
training implemented.
4.2.5.2 a)
* The results of this review can be used to confirm the content of
1)2)
education provided and the degree of understanding among
participants.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
20
4. Ownership: Confirmation and Verification of Licenses Owned
[Management objective] It is verified that software used is licensed, and the types and quantities of
owned licenses are ascertained.
b. Items to be managed
licenses
relevant
Licensing models
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
21
Management Own 1 Systems are in place for recording Corresponding
Corresponding Tiers (Tier)
Requirements information on changes to licenses Clauses in
items including the name of the holder of the license are 4.4.2.2 a) ○
ascertained.
are held, with duplication allowed only if duplicate information can 4.4.2.2 b) ○
b)3)
4.5.2.2
○
a)7)
4.5.3.2
a)1)
managed appropriately.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
22
Management Own 1 Systems are in place for recording Corresponding
Corresponding Tiers (Tier)
Requirements information on changes to licenses Clauses in
a)-c)1)
a. Procedures are established for lending and return of media. All of 4.4.3.2 c) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
23
Management Own 2 Materials necessary for licenses are stored Corresponding
Corresponding Tiers (Tier)
Requirements appropriately. Clauses in
(1) License certificates, terms of use, contracts, etc. are stored under All of 4.4.3.2 a),
○
the management of the SAM owner. c)4)
appropriately.
4.5.3.2 a)1)-3)
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
24
Management Own 3 The state of management of owned licenses is Corresponding
Corresponding Tiers (Tier)
Requirements verified. Clauses in
a. All licenses held by the organization are verified at least annually using
inventory lists, and materials certifying terms of use are verified regularly 4.5.2.2 a)6)7) ○
verified.
d. When a site uses decentralized management, the site’s records are 3) 8) 9): Tier 1
4.5.2.2 a)3)-9)
reconciled against overall records. 4)-7): Tier 4
(2) Timeliness
c. For licenses with expiration dates, the expiration dates are recorded 4.4.3.2 d)
○
and the software is not used after the expiration date. 4.5.3.2 a)1)
(3) Adequacy
a. The SAM owner approves license changes and records thereof. All of 4.7.2.2 a) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
25
Management Own 3 The state of management of owned licenses is Corresponding
Corresponding Tiers (Tier)
Requirements verified. Clauses in
following: license changes including retirement and return, checking All of 4.7.2.2 a) ○
approval of copying and disposal of media and preparation and removal All of 4.7.2.2 a) ○
of installation images.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
26
5. Implement’n: Confirmation of Software and Related Asset Implemented
[Management objective] The physical and logical inventory management of hardware and software are
properly implemented.
(1) For the hardware on which software is used and the software installed,
(4) All installed software can be identified as having been installed を削除
under permission.
a. Installed software and owned licenses are linked in accordance with the
terms of use.
4.4.3.2 b)2)3) ○
b. As necessary, the hardware to which a license applies (such as hardware
with preinstalled software or other cases that individual linkage is required) can
be ascertained.
software installation.
software being used. For example, they might include metrics such 4.4.3.2 d) ○
processors.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
27
Imp 1 The procedure for recording information for Corresponding
Management Corresponding
changes of hardware and software is properly Clauses in
Requirements Tiers (Tier)
implemented. ISO/IEC
users.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
28
Management Imp 2 The status of management of placed hardware Corresponding
Corresponding Tiers (Tier)
Requirements and installed software is verified. Clauses in
and effective licenses is performed at least quarterly. Corrective actions 4.5.2.2 a)1)2) ○
locations, is conducted at least semi-annually, and conformance with the 4.5.2.2 a)3) ○
(2) Timeliness
a. Information on changes in all the software and hardware within the
and users.
(3) Adequacy
a. All hardware and software changes and records are approved by the
4.5.2.2 a)1) ○
responsible person.
changes related to the content of hardware and software including the All of 4.7.2.2 a) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
29
6. Cost Optimization
Correspondin
Management Cost 1 Consideration is given to optimization of the Corresponding Tiers
g Clauses in
Requirements costs of assets subjected to SAM. (Tier)
ISO/IEC
Management Items 19770-1 1 2 3 4
(3) Purchasing policies are established that take into consideration Main scope: Tier 3
the costs of purchase and operation, for example by developing 4.6.3.2 f) Basic items that should be
(6) Policies for identical processes are unified (standardized). 4.7.3.2 c)1) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
30
7. Security: Compliance with Security Requirements
[Management objective] The organization’s security requirements relevant to assets subjected to SAM,
including security requirements related to SAM policies, are complied with
(2) Systems are in place for confirming the state of compliance with
4.5.4.2
the organization’s security requirements related to assets ○
a)b)
subjected to SAM.
(4) Physical and logical access controls are designated and 4.6.5.2
○
recorded. b)c)
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
31
8. Operations Management: SAM Operations Management Processes
[Management objective] Various processes and interfaces are adopted for effective and efficient
implementation of SAM management functions.
their responsibilities
4.6.2.2 a)1)-3) ○
Establishment of purchasing specifications for software or related
related issues
related services
Review, at least every six months, of contracts related to assets * Limited scope subject to Tier
subjected to SAM and related services, and review of results 2 to identify opportunities for
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
32
OM 2 Systems are in place to make it possible to Corresponding
Management
obtain financial information related to assets Clauses in Corresponding Tiers (Tier)
Requirements
subjected to SAM as needed. ISO/IEC
as necessary.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
33
Management OM 3 Service levels related to SAM are defined, Corresponding
Corresponding Tiers (Tier)
Requirements recorded, and managed. Clauses in
documented.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
34
9. Life Cycle Processes and Interfaces
[Management objective] Various processes and interfaces are adopted to carry out effective and
efficient life-cycle management of assets subjected to SAM
maintained, and the necessary electronic and physical media are 4.7.3.2 d)2)3) ○
subjected to safe-keeping.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
35
Management LC 3 Procedures are established and implemented for Corresponding
Corresponding Tiers (Tier)
Requirements software development. Clauses in
development. 4.7.4.2 a) ○
prerelease software.
references to change requests or issues on which the release was based, 4.7.5.2 a)1)-5) ○
approval.
reviewed.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
36
Management LC 5 Procedures are established and implemented for Corresponding
Corresponding Tiers (Tier)
Requirements deployment of assets subjected to SAM. Clauses in
are documented.
are recorded and resolved in accordance with their priority, and All of 4.7.7.2 a) ○
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
37
LC 8 Procedures are established and implemented for Corresponding
Management
retirement, return, and sale of assets subjected to Clauses in Corresponding Tiers (Tier)
Requirements
SAM. ISO/IEC
(1) Systems are established and approved for retirement, return, and
implications.
and licenses available for use in order to reflect the licenses of software 4.7.9.2 a)2) ○
implemented.
e. When assets subjected to SAM are sold to other related parties, such
requirements.
f. Records are updated to reflect the changes above, and audit trails of
4.7.9.2 a)5) ○
the changes are maintained.
Software Asset Management Standard Ver4.1 Association of SAM Assessment & Certification
38