Category Archives: SAM

IT&SAM and GDPR

gdpr-2When you’re involved in IT&SAM in Europe you have probably heard of the new General Data Protection Regulation. In this post, I’d like to shine some light on how this new ruleset affects your job, and how you should adapt to it. When you’re in IT&SAM outside of the EC you will be affected (maybe) less. When you’re in an organization that’s acting global, and in the EC, you must navigate between various regulations that are valid in different parts of the world.

As SAM practitioners may involve internal staff, sometimes hired experts or employees of a SAM service provider, it’s of the highest priority to find out what role you have according the new GDPR. And at times there will be a combination of roles, between data processor and/or data controller.

new-jobFirst you need to know that the regulation started on May 18th of this year (2016) in Europe, and will be effective as of May 25th, 2018. In the meantime, organizations have time to adapt to the new regulation, train people, assign accountable and responsible. Last week I read that it was to be expected that between 26.00 and 74.000 new Data Protection Officers will need to be added in organizations, in the years to come.

As IT&Software Asset manager you’re using lots of data sources. Incorporated in some of these sources is personal information and other data that is subject to the new GDPR. And it doesn’t matter anymore if your part of the data controlling organization or a service provider, or any other function. If you’re handling GDPR affected data, you need to comply! (more…)

Read More

SAM processes

process_iconMany organizations struggle with software licenses and only few succeed in managing software compliance. Often the advice is to get the Software Asset Management processes properly implemented. But then many questions arise. Process models like ISO 19770 or ITIL-SAM identify processes but don’t provide support for specification and implementation. In a series of articles, I will discuss SAM processes and an approach to implement them.

Why SAM processes?

Many, even most organizations, are periodically audited by software vendors. The huge amounts that must be paid for licenses and fines – which are, by the way, in many cases compensated by investments in new, unwanted software – are triggers to reflect. Some organizations choose ‘all you can eat contracts’ (expensive, but no risk for claims afterwards) or doing nothing (accept the cost for the short term and resolve the problem later; don’t cross the bridges before you come to them). The majority select a SAM tool vendor and have them their tool implemented. The implementation approach implies processes but, in fact, limited to the ability of using the software. I know many examples of organizations that after one year are frustrated by the tool and decide to select another tool. In most cases, this decision is not justified. The differences between tools are small and the results will likely be the same the next time. Probable conclusions are that input data is not reliable or SAM operators are not capable to process the data. In both cases implementing SAM processes may be the solution.

(more…)

Read More