Iso 19770
Iso 19770
Bawa S Bedi
Sensitivity: general
ISO 19770-1 applies to SAM processes additional requirements dealing with:
a) controls over software modification, duplication, and
It is a framework of ITAM processes to enable an distribution, with particular emphasis on access and
organization to prove that it is performing software asset integrity controls.
management to a standard sufficient to satisfy corporate b) audit trails of authorizations and of changes made to IT
governance requirements and ensure effective support for assets.
IT service management overall. c) controls over licensing, under licensing, over licensing,
and compliance with licensing terms and conditions.
d) controls over situations involving mixed ownership and
ISO/IEC 19770-1 (2012) established 27 processes for the responsibilities, such as in cloud computing and with
conceptual framework of SAM, divided into three main ‘Bring-Your-Own-Device’ (BYOD) practices; and
categories which are: e) reconciliation of IT asset management data with data
Organizational Management Processes in other information systems when justified by
Core SAM Processes business value, with financial information systems
Primary Process Interfaces for SAM recording assets and expenses.
Sensitivity: general
ISO 19770-2 establishes Software Identification Tag
It establishes specifications for tagging software to optimize its identification and management. This part of ISO/IEC
19770 applies to Tag producers and Tag consumers.
a) Tag producers: These organizations and/or tools create software identification (SWID) tags for use by others in the
market. A tag producer may be part of the software creator organization, the software licensor organization, or be a
third-party organization. These organizations and/or tools can broadly be broken down into the following categories.
Platform providers
Software providers
Tag tool providers
b) Tag consumers: These tools and/or organizations utilize information from SWID tags and are typically broken down
into the following two major categories:
Software consumers
IT discovery and processing tool providers
Sensitivity: general
ISO 19770-3 relates to Software Entitlement schema
The primary intentions of this part of ISO/IEC 19770 are:
a) to provide a basis for common terminology to be used when describing entitlement rights, limitations, and
metrics, and
b) to provide a schema which allows effective description of rights, limitations and metrics attaching to a software
license.
It is intended that this standardized schema will be of benefit to all stakeholders involved in the
creation
licensing
distribution
release
installation and ongoing management of software
software entitlements
Sensitivity: general
ISO 19770-4 specifies Resource Utilization Measurement
To understand the benefits of the ISO. Have divided it into three entities: IT asset manufacturers, Tool providers, IT
asset users.
a) IT asset manufacturers: These are the entities that create IT assets for distribution or installation.
b) Tool providers: These are the entities that may provide any number of tools that use the information contained in
a Resource Utilization Measurement (RUM). These tools will include aggregation facilities capable of producing
consolidated reports of the utilization of resources throughout an organization, and threshold reporting facilities
capable of generating an alarm when utilization reaches a predetermined level.
c) IT asset users: These are the entities that purchase, use IT assets, and who are intended as one of the major
beneficiaries of the visibility made possible by the information that is contained within the RUM.
Sensitivity: general
ISO 19770-5 provides Overview and Vocabulary
This part of ISO/IEC 19770 provides:
Also, this part of ISO/IEC 19770 is applicable to all types of organization (e.g., commercial enterprises, government
agencies, and non-profit organizations).
Sensitivity: general