SlideShare a Scribd company logo
1 of 18
Download to read offline
The ITAM Review US Conference 2017
Audit Defense: Plugging The Leaks
Chris Moffett, Global Software Asset Manager
Lisa Hellberg, Sr. Director, Global Supplier
Asset Management
The ITAM Review US Conference 2017
Introduction
TOPIC	
  OF	
  DISCUSSION:	
  
Many	
  companies	
  struggle	
  with	
  tools,	
  "helpful"	
  employees	
  and	
  even	
  internal	
  audit	
  teams	
  
leaking	
  what	
  appears	
  to	
  be	
  irrelevant	
  informaFon	
  to	
  outside	
  auditors.	
  Unfortunately	
  the	
  
auditors	
  and	
  sales	
  teams	
  are	
  very	
  adept	
  at	
  asking	
  probing	
  quesFons	
  that	
  are	
  out	
  of	
  scope	
  
and	
  oIen	
  lead	
  to	
  unintended	
  audit	
  complicaFons.	
  
	
  
WHAT	
  YOU	
  WILL	
  LEARN:	
  
In	
  this	
  session	
  you	
  will	
  discover	
  how	
  to	
  organize	
  your	
  company's	
  audit	
  response	
  acFviFes.	
  
Who	
  can	
  discuss	
  what	
  informaFon,	
  what	
  tools	
  can	
  be	
  used	
  and	
  how	
  the	
  auditors	
  and	
  
sales	
  teams	
  can	
  interact	
  with	
  your	
  company	
  while	
  under	
  audit.	
  
	
  
The ITAM Review US Conference 2017
Agenda
•  Software Audit Pre-conditions
•  What are we trying to avoid
•  Prevent leaks
•  Before the audit
•  At audit commencement
•  Upon audit completion
The ITAM Review US Conference 2017
Audit Preconditions: Non-Negotiable
•  All	
  communicaFon	
  regarding	
  the	
  ongoing	
  audit	
  must	
  be	
  directed	
  to	
  “Your	
  Company’s”	
  
audit	
  response	
  team	
  	
  
•  Publisher/auditor	
  representaFves	
  must	
  not	
  aWempt	
  to	
  discuss	
  environment,	
  
installaFon	
  count,	
  forecast,	
  growth	
  expectaFons,	
  strategic	
  direcFon	
  or	
  any	
  other	
  audit	
  
related	
  data	
  with	
  other	
  “Your	
  Company”	
  employees.	
  
The ITAM Review US Conference 2017
What Are We Trying To Avoid
•  Unauthorized	
  release	
  of	
  confidenFal	
  informaFon	
  
•  Prohibit	
  gathering	
  and	
  communicaFon	
  that	
  is	
  out	
  of	
  scope	
  
•  InteracFons	
  between	
  auditors	
  and	
  non	
  audit	
  team	
  members	
  
•  Auditor/Company	
  representaFves	
  probing	
  for	
  addiFonal	
  informaFon	
  
The ITAM Review US Conference 2017
Prevent Leaks Before The Audit
Before	
  the	
  audit	
  begins	
  
•  Create	
  an	
  internal	
  audit	
  team	
  and	
  define	
  their	
  roles	
  
•  Establish	
  list	
  of	
  in	
  scope	
  informaFon	
  	
  
•  Understand	
  and	
  idenFfy	
  who	
  your	
  publisher/auditor	
  representaFves	
  are	
  
•  Restrict	
  and	
  centralize	
  all	
  communicaFons	
  
•  Train	
  your	
  internal	
  staff	
  to	
  redirect	
  all	
  communicaFons	
  related	
  to	
  the	
  audit.	
  
The ITAM Review US Conference 2017
Internal Audit Team
•  Legal	
  Council	
  –	
  Manage	
  the	
  legal	
  terms	
  and	
  condiFons	
  
•  Security	
  –	
  Help	
  define	
  and	
  enforce	
  data	
  elements	
  that	
  are	
  captured	
  and	
  communicated	
  
•  Procurement	
  –	
  Manage	
  the	
  pricing	
  and	
  seWlement	
  acFviFes	
  
•  ITAM/SAM	
  –	
  Manage	
  the	
  data	
  gathering	
  and	
  compliance	
  review	
  process	
  
	
  
The ITAM Review US Conference 2017
What is considered in scope information
Only	
  usage	
  data	
  based	
  on	
  contractually	
  agreed	
  upon	
  license	
  metrics	
  should	
  be	
  included	
  
•  Confirm	
  which	
  specific	
  agreements	
  are	
  under	
  review	
  
•  IdenFfy	
  what	
  products	
  and	
  use	
  rights	
  apply	
  
•  Outline	
  regions	
  or	
  locaFons	
  under	
  audit	
  
•  Agree	
  on	
  duraFon	
  of	
  product	
  usage	
  
•  Establish	
  license	
  usage	
  calculaFon	
  methods	
  
•  Compile	
  a	
  list	
  of	
  eligible	
  .exe	
  values	
  and	
  installaFon	
  paths	
  
•  Determine	
  what	
  environments	
  require	
  licenses	
  (i.e.	
  dev,	
  test,	
  prod,	
  etc)	
  
•  Establish	
  data	
  gathering	
  process	
  and	
  tools	
  
•  Establish	
  quesFon	
  and	
  answer	
  protocol	
  
	
  
The ITAM Review US Conference 2017
What should be considered out of scope
	
  Data	
  to	
  avoid	
  	
  
	
  
•  Trial,	
  evaluaFon	
  and	
  free	
  installaFons	
  
•  Customer	
  idenFfiable	
  informaFon	
  
•  Customer	
  installed	
  products	
  where	
  licenses	
  are	
  not	
  provided	
  by	
  your	
  company	
  
•  Orphaned	
  .dll	
  and	
  other	
  data	
  leI	
  behind	
  from	
  uninstalls	
  
•  Incomplete	
  installaFons	
  
•  Prior	
  expired	
  agreements	
  
•  Auditor	
  access	
  to	
  event	
  viewer	
  logs	
  
The ITAM Review US Conference 2017
Publisher/Audit Company Representatives
Who	
  should	
  be	
  considered	
  a	
  company	
  representaFve	
  we	
  would	
  want	
  to	
  avoid?	
  
	
  
•  Sales	
  and	
  Sales	
  Support	
  
•  Tech	
  Support	
  Engineers	
  
•  Billing	
  contacts	
  	
  
•  Compliance/audit	
  team	
  
•  Industry	
  event	
  or	
  conference	
  parFcipants	
  
•  SoIware	
  product	
  reseller	
  
The ITAM Review US Conference 2017
Communication Types To Avoid
Below	
  are	
  a	
  few	
  examples	
  of	
  communicaFon	
  methods	
  by	
  the	
  publisher/auditor	
  
company	
  that	
  non	
  audit	
  team	
  employees	
  may	
  be	
  exposed	
  to	
  and	
  should	
  avoid	
  
•  Emails	
  
•  Phone	
  and	
  text	
  conversaFons	
  
•  Social	
  Media	
  interacFons	
  (i.e.	
  LinkedIn,	
  Facebook,	
  etc.)	
  	
  
•  Industry	
  event	
  or	
  conference	
  parFcipants	
  
•  On	
  site	
  visits	
  
•  Business	
  Lunches	
  
•  Quarterly	
  Business	
  Reviews	
  
The ITAM Review US Conference 2017
Restrict Internal Staff Communications
Below	
  are	
  example	
  scenarios	
  of	
  who	
  might	
  unknowingly	
  communicate	
  risky	
  
informaFon	
  
•  OperaFons/Support	
  staff	
  calling	
  in	
  for	
  support	
  of	
  the	
  product	
  
•  Product	
  users	
  looking	
  for	
  product	
  roadmap	
  and	
  other	
  informaFon	
  
•  Accounts	
  Payable	
  working	
  to	
  pay	
  an	
  invoice	
  
•  Front	
  desk/lobby	
  staff	
  being	
  approached	
  for	
  onsite	
  visits	
  
•  Engineers	
  working	
  to	
  deploy	
  the	
  products	
  
•  Individuals	
  working	
  with	
  evaluaFon	
  and	
  new	
  product	
  tesFng	
  acFviFes	
  
•  MarkeFng	
  or	
  channel	
  sales	
  collaboraFons/partnerships	
  
•  Employees	
  requesFng	
  quotes	
  for	
  new	
  product	
  deployment	
  
The ITAM Review US Conference 2017
Prevent Leaks At Audit Commencement
•  Enforce	
  in	
  scope	
  agreed	
  upon	
  details	
  
•  Code	
  tools	
  to	
  only	
  capture	
  in	
  scope	
  data	
  elements	
  
•  Require	
  auditors	
  use	
  a	
  company	
  provided	
  laptop	
  with	
  no	
  internet	
  access	
  and	
  no	
  USB	
  
write	
  capabiliFes	
  to	
  review	
  the	
  data.	
  
•  Reclaim	
  the	
  laptop	
  from	
  the	
  auditor	
  at	
  the	
  end	
  of	
  each	
  day	
  
•  Do	
  not	
  allow	
  any	
  data	
  to	
  be	
  taken	
  off	
  site	
  unFl	
  analysis	
  is	
  completed	
  
•  Once	
  analysis	
  is	
  completed	
  only	
  allow	
  summary	
  ELP	
  level	
  data	
  to	
  be	
  taken	
  off	
  site	
  for	
  
compliance	
  posiFon	
  creaFon	
  
•  Require	
  auditor	
  quesFons	
  to	
  be	
  answered	
  offline	
  
•  If	
  auditor	
  quesFons	
  require	
  screen	
  share	
  acFviFes,	
  schedule	
  the	
  review	
  for	
  the	
  
following	
  day	
  and	
  train	
  the	
  impacted	
  staff	
  on	
  how	
  to	
  respond	
  
The ITAM Review US Conference 2017
Screen Share Best Practices
•  Hide	
  all	
  informaFon	
  on	
  desktop	
  
•  Close	
  all	
  programs	
  
•  Navigate	
  to	
  in	
  scope	
  locaFons	
  prior	
  to	
  starFng	
  the	
  screen	
  share	
  
•  Only	
  answer	
  quesFons	
  with	
  a	
  yes	
  or	
  a	
  no	
  
The ITAM Review US Conference 2017
Prevent Leaks Upon Audit Completion
•  Reclaim	
  and	
  reformate	
  company	
  provided	
  laptop	
  
•  Confirm	
  only	
  summary	
  ELP	
  level	
  data	
  has	
  been	
  provided	
  to	
  the	
  publisher	
  
•  Do	
  not	
  allow	
  auditor	
  to	
  retain	
  a	
  copy	
  of	
  the	
  data	
  used	
  for	
  ELP	
  creaFon	
  
The ITAM Review US Conference 2017
Summary
Remember that all compliance reviews should have
only one goal, determining current compliance
position. With that in mind always:
•  Proactively develop your compliance position prior to auditor
engagement
•  Establish and enforce the audit scope
•  Restrict non audit team communications
•  PROTECT YOUR DATA
The ITAM Review US Conference 2017
Questions?
The ITAM Review US Conference 2017
Thank You

More Related Content

What's hot

ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...
ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...
ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...Martin Thompson
 
ITAM AUS 2017 BMC SAM Journey
ITAM AUS 2017 BMC SAM JourneyITAM AUS 2017 BMC SAM Journey
ITAM AUS 2017 BMC SAM JourneyMartin Thompson
 
ITAM US 2017 The Maintenance Journey
ITAM US 2017 The Maintenance JourneyITAM US 2017 The Maintenance Journey
ITAM US 2017 The Maintenance JourneyMartin Thompson
 
ITAM AUS 2017 How to get SAM happily frolicking on the Cloud
ITAM AUS 2017 How to get SAM happily frolicking on the CloudITAM AUS 2017 How to get SAM happily frolicking on the Cloud
ITAM AUS 2017 How to get SAM happily frolicking on the CloudMartin Thompson
 
Australia Conference 2018_The $250BN annual software support and maintenance ...
Australia Conference 2018_The $250BN annual software support and maintenance ...Australia Conference 2018_The $250BN annual software support and maintenance ...
Australia Conference 2018_The $250BN annual software support and maintenance ...Martin Thompson
 
Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...
Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...
Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...Martin Thompson
 
Australia Conference 2018_Making ITAM Stick – a blue print for organizational...
Australia Conference 2018_Making ITAM Stick – a blue print for organizational...Australia Conference 2018_Making ITAM Stick – a blue print for organizational...
Australia Conference 2018_Making ITAM Stick – a blue print for organizational...Martin Thompson
 
Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...
Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...
Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...Martin Thompson
 
ITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantage
ITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantageITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantage
ITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantageMartin Thompson
 
AUS Conference 2018_All change - aligning sam with your data centre change pr...
AUS Conference 2018_All change - aligning sam with your data centre change pr...AUS Conference 2018_All change - aligning sam with your data centre change pr...
AUS Conference 2018_All change - aligning sam with your data centre change pr...Martin Thompson
 
Australia Conference 2018_Can itam be agile?
Australia Conference 2018_Can itam be agile?Australia Conference 2018_Can itam be agile?
Australia Conference 2018_Can itam be agile?Martin Thompson
 
The Software Asset Management Journey at BMC – The Financial Perspective: Bl...
The Software Asset Management Journey at BMC – The Financial Perspective:  Bl...The Software Asset Management Journey at BMC – The Financial Perspective:  Bl...
The Software Asset Management Journey at BMC – The Financial Perspective: Bl...Martin Thompson
 
Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...
Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...
Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...Martin Thompson
 
Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...
Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...
Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...Martin Thompson
 
Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...
Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...
Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...Martin Thompson
 
UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...
UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...
UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...Martin Thompson
 
Microsoft Negotiation in the cloud era: Kylie Fowler ITAM Intelligence ITAM ...
Microsoft Negotiation in the cloud era: Kylie Fowler  ITAM Intelligence ITAM ...Microsoft Negotiation in the cloud era: Kylie Fowler  ITAM Intelligence ITAM ...
Microsoft Negotiation in the cloud era: Kylie Fowler ITAM Intelligence ITAM ...Martin Thompson
 
Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...
Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...
Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...Martin Thompson
 
Australia Conference 2018_Building trust, reputation & budget within itam acc...
Australia Conference 2018_Building trust, reputation & budget within itam acc...Australia Conference 2018_Building trust, reputation & budget within itam acc...
Australia Conference 2018_Building trust, reputation & budget within itam acc...Martin Thompson
 
The business case for ITAM – how to win senior management approval: Martin Th...
The business case for ITAM – how to win senior management approval: Martin Th...The business case for ITAM – how to win senior management approval: Martin Th...
The business case for ITAM – how to win senior management approval: Martin Th...Martin Thompson
 

What's hot (20)

ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...
ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...
ITAM US 2017 How to Create a Successful SAM Program Across Multiple Territori...
 
ITAM AUS 2017 BMC SAM Journey
ITAM AUS 2017 BMC SAM JourneyITAM AUS 2017 BMC SAM Journey
ITAM AUS 2017 BMC SAM Journey
 
ITAM US 2017 The Maintenance Journey
ITAM US 2017 The Maintenance JourneyITAM US 2017 The Maintenance Journey
ITAM US 2017 The Maintenance Journey
 
ITAM AUS 2017 How to get SAM happily frolicking on the Cloud
ITAM AUS 2017 How to get SAM happily frolicking on the CloudITAM AUS 2017 How to get SAM happily frolicking on the Cloud
ITAM AUS 2017 How to get SAM happily frolicking on the Cloud
 
Australia Conference 2018_The $250BN annual software support and maintenance ...
Australia Conference 2018_The $250BN annual software support and maintenance ...Australia Conference 2018_The $250BN annual software support and maintenance ...
Australia Conference 2018_The $250BN annual software support and maintenance ...
 
Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...
Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...
Australia Conference 2018_Getting the best from ibm license metric tool (ilmt...
 
Australia Conference 2018_Making ITAM Stick – a blue print for organizational...
Australia Conference 2018_Making ITAM Stick – a blue print for organizational...Australia Conference 2018_Making ITAM Stick – a blue print for organizational...
Australia Conference 2018_Making ITAM Stick – a blue print for organizational...
 
Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...
Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...
Australia Conference 2018_Cloud won't manage itself - a strategic opportunity...
 
ITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantage
ITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantageITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantage
ITAM AUS 2017 Leveraging Microsoft's Cloud Focus to your advantage
 
AUS Conference 2018_All change - aligning sam with your data centre change pr...
AUS Conference 2018_All change - aligning sam with your data centre change pr...AUS Conference 2018_All change - aligning sam with your data centre change pr...
AUS Conference 2018_All change - aligning sam with your data centre change pr...
 
Australia Conference 2018_Can itam be agile?
Australia Conference 2018_Can itam be agile?Australia Conference 2018_Can itam be agile?
Australia Conference 2018_Can itam be agile?
 
The Software Asset Management Journey at BMC – The Financial Perspective: Bl...
The Software Asset Management Journey at BMC – The Financial Perspective:  Bl...The Software Asset Management Journey at BMC – The Financial Perspective:  Bl...
The Software Asset Management Journey at BMC – The Financial Perspective: Bl...
 
Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...
Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...
Taking back control of your Microsoft Negotiation: Mike Austin, Method 180 (I...
 
Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...
Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...
Australia Conference 2018_SAM Soufflé: 1 part Tool & 2 parts People = A recip...
 
Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...
Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...
Audit Defence from a Legal Perspective: Robert Scott – Scott & Scott LLP (ITA...
 
UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...
UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...
UK Conference 2018_Boost up your Oracle audit defence_Richard Spithoven & Cat...
 
Microsoft Negotiation in the cloud era: Kylie Fowler ITAM Intelligence ITAM ...
Microsoft Negotiation in the cloud era: Kylie Fowler  ITAM Intelligence ITAM ...Microsoft Negotiation in the cloud era: Kylie Fowler  ITAM Intelligence ITAM ...
Microsoft Negotiation in the cloud era: Kylie Fowler ITAM Intelligence ITAM ...
 
Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...
Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...
Advanced Software Negotiation – How to remove an Audit Clause Workshop: Kris ...
 
Australia Conference 2018_Building trust, reputation & budget within itam acc...
Australia Conference 2018_Building trust, reputation & budget within itam acc...Australia Conference 2018_Building trust, reputation & budget within itam acc...
Australia Conference 2018_Building trust, reputation & budget within itam acc...
 
The business case for ITAM – how to win senior management approval: Martin Th...
The business case for ITAM – how to win senior management approval: Martin Th...The business case for ITAM – how to win senior management approval: Martin Th...
The business case for ITAM – how to win senior management approval: Martin Th...
 

Similar to ITAM US 2017 Audit Defense Plugging the Leaks

eSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM Investment
eSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM InvestmenteSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM Investment
eSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM InvestmenteSavvy
 
Data analytics software selection and implementation
Data analytics software selection and implementationData analytics software selection and implementation
Data analytics software selection and implementationJim Kaplan CIA CFE
 
Document Management Options for Abila MIP
Document Management Options for Abila MIPDocument Management Options for Abila MIP
Document Management Options for Abila MIPNet at Work
 
Are You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATAre You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATJim Kaplan CIA CFE
 
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]Barun Kumar
 
Improve Regulatory Compliance & Risk Management Using Best Practices
Improve Regulatory Compliance & Risk Management Using Best PracticesImprove Regulatory Compliance & Risk Management Using Best Practices
Improve Regulatory Compliance & Risk Management Using Best PracticesLavante Inc.
 
Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!Jim Kaplan CIA CFE
 
2016 BestGRC Product Demo
2016 BestGRC Product Demo2016 BestGRC Product Demo
2016 BestGRC Product DemoGlenn Murphy
 
How to Write an RFP
How to Write an RFPHow to Write an RFP
How to Write an RFPEPAY Systems
 
Best Practices for the Service Cloud
Best Practices for the Service CloudBest Practices for the Service Cloud
Best Practices for the Service CloudRoss Bauer
 
SPI_Conference_Handling Breakups to Save Future Headaches_Final
SPI_Conference_Handling Breakups to Save Future Headaches_FinalSPI_Conference_Handling Breakups to Save Future Headaches_Final
SPI_Conference_Handling Breakups to Save Future Headaches_FinalCurtis Weldon
 
How to work with a vendor during an audit & what not to do – is there such a ...
How to work with a vendor during an audit & what not to do – is there such a ...How to work with a vendor during an audit & what not to do – is there such a ...
How to work with a vendor during an audit & what not to do – is there such a ...Martin Thompson
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubFLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubBlack Duck by Synopsys
 
Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...
Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...
Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...Perficient, Inc.
 
Our Journey to Marketing Cloud
Our Journey to Marketing CloudOur Journey to Marketing Cloud
Our Journey to Marketing CloudSalesforce.org
 
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...Paris Open Source Summit
 
Software License Optimization and ITSM - Drive Efficiency and Cost Savings
Software License Optimization and ITSM - Drive Efficiency and Cost Savings Software License Optimization and ITSM - Drive Efficiency and Cost Savings
Software License Optimization and ITSM - Drive Efficiency and Cost Savings Flexera
 
Software Audit Assist Introduction forLinkedIn
Software Audit Assist Introduction forLinkedInSoftware Audit Assist Introduction forLinkedIn
Software Audit Assist Introduction forLinkedInSean Gilbert
 

Similar to ITAM US 2017 Audit Defense Plugging the Leaks (20)

eSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM Investment
eSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM InvestmenteSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM Investment
eSavvy webinar: Top 5+1 Tips of How to Maximize the ROI of a CRM Investment
 
Data analytics software selection and implementation
Data analytics software selection and implementationData analytics software selection and implementation
Data analytics software selection and implementation
 
Document Management Options for Abila MIP
Document Management Options for Abila MIPDocument Management Options for Abila MIP
Document Management Options for Abila MIP
 
Are You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATAre You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAAT
 
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
GRCSG2014_Kumar_Lessons for ensuring_F2E [Compatibility Mode]
 
Benchmarking
BenchmarkingBenchmarking
Benchmarking
 
Improve Regulatory Compliance & Risk Management Using Best Practices
Improve Regulatory Compliance & Risk Management Using Best PracticesImprove Regulatory Compliance & Risk Management Using Best Practices
Improve Regulatory Compliance & Risk Management Using Best Practices
 
Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!
 
2016 BestGRC Product Demo
2016 BestGRC Product Demo2016 BestGRC Product Demo
2016 BestGRC Product Demo
 
How to Write an RFP
How to Write an RFPHow to Write an RFP
How to Write an RFP
 
Best Practices for the Service Cloud
Best Practices for the Service CloudBest Practices for the Service Cloud
Best Practices for the Service Cloud
 
SPI_Conference_Handling Breakups to Save Future Headaches_Final
SPI_Conference_Handling Breakups to Save Future Headaches_FinalSPI_Conference_Handling Breakups to Save Future Headaches_Final
SPI_Conference_Handling Breakups to Save Future Headaches_Final
 
How to work with a vendor during an audit & what not to do – is there such a ...
How to work with a vendor during an audit & what not to do – is there such a ...How to work with a vendor during an audit & what not to do – is there such a ...
How to work with a vendor during an audit & what not to do – is there such a ...
 
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck HubFLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
FLIGHT WEST 2018 Presentation - Open Source License Management in Black Duck Hub
 
Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...
Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...
Move from Business Intelligence to Advanced Analytics by Integrating IBM SPSS...
 
Our Journey to Marketing Cloud
Our Journey to Marketing CloudOur Journey to Marketing Cloud
Our Journey to Marketing Cloud
 
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
#OSSPARIS19 - Understanding Open Source Governance - Gilles Gravier, Wipro Li...
 
Software License Optimization and ITSM - Drive Efficiency and Cost Savings
Software License Optimization and ITSM - Drive Efficiency and Cost Savings Software License Optimization and ITSM - Drive Efficiency and Cost Savings
Software License Optimization and ITSM - Drive Efficiency and Cost Savings
 
Steps to select the right ERP Vendor
Steps to select the right ERP VendorSteps to select the right ERP Vendor
Steps to select the right ERP Vendor
 
Software Audit Assist Introduction forLinkedIn
Software Audit Assist Introduction forLinkedInSoftware Audit Assist Introduction forLinkedIn
Software Audit Assist Introduction forLinkedIn
 

More from Martin Thompson

Wisdom UK 2019: Building the ultimate HAM sandwich - David Foxen
Wisdom UK 2019: Building the ultimate HAM sandwich - David FoxenWisdom UK 2019: Building the ultimate HAM sandwich - David Foxen
Wisdom UK 2019: Building the ultimate HAM sandwich - David FoxenMartin Thompson
 
2019 Salary and Skills Survey by The ITAM Review
2019 Salary and Skills Survey by The ITAM Review 2019 Salary and Skills Survey by The ITAM Review
2019 Salary and Skills Survey by The ITAM Review Martin Thompson
 
2017 ITAM Review Salary Survey
2017 ITAM Review Salary Survey2017 ITAM Review Salary Survey
2017 ITAM Review Salary SurveyMartin Thompson
 
Australia Conference 2018_News that shook the itam world in 2018 with resources
Australia Conference 2018_News that shook the itam world in 2018 with resourcesAustralia Conference 2018_News that shook the itam world in 2018 with resources
Australia Conference 2018_News that shook the itam world in 2018 with resourcesMartin Thompson
 
Australia Conference 2018_What you need to think about when implementing micr...
Australia Conference 2018_What you need to think about when implementing micr...Australia Conference 2018_What you need to think about when implementing micr...
Australia Conference 2018_What you need to think about when implementing micr...Martin Thompson
 
Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...
Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...
Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...Martin Thompson
 
Australia Conference 2018_Process Meh
Australia Conference 2018_Process MehAustralia Conference 2018_Process Meh
Australia Conference 2018_Process MehMartin Thompson
 
Australia Conference 2018_ITAM in 2023 - where is your role heading
Australia Conference 2018_ITAM in 2023 - where is your role heading Australia Conference 2018_ITAM in 2023 - where is your role heading
Australia Conference 2018_ITAM in 2023 - where is your role heading Martin Thompson
 
Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...
Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...
Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...Martin Thompson
 
Australia Conference 2018_How to engage your it security team and fund your s...
Australia Conference 2018_How to engage your it security team and fund your s...Australia Conference 2018_How to engage your it security team and fund your s...
Australia Conference 2018_How to engage your it security team and fund your s...Martin Thompson
 
Australia Conference 2018_How to be a SaaS manager – tools, people and proces...
Australia Conference 2018_How to be a SaaS manager – tools, people and proces...Australia Conference 2018_How to be a SaaS manager – tools, people and proces...
Australia Conference 2018_How to be a SaaS manager – tools, people and proces...Martin Thompson
 
Australia Conference 2018_Boost up your oracle audit defence
Australia Conference 2018_Boost up your oracle audit defenceAustralia Conference 2018_Boost up your oracle audit defence
Australia Conference 2018_Boost up your oracle audit defenceMartin Thompson
 
UK Conference 2018_7 pillars of a HAM practice_Martin Thompson
UK Conference 2018_7 pillars of a HAM practice_Martin ThompsonUK Conference 2018_7 pillars of a HAM practice_Martin Thompson
UK Conference 2018_7 pillars of a HAM practice_Martin ThompsonMartin Thompson
 
UK Conference 2018_Software support and maintenance survey_Martin Thompson
UK Conference 2018_Software support and maintenance survey_Martin ThompsonUK Conference 2018_Software support and maintenance survey_Martin Thompson
UK Conference 2018_Software support and maintenance survey_Martin ThompsonMartin Thompson
 
UK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ WittUK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ WittMartin Thompson
 
UK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich Gibbons
UK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich GibbonsUK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich Gibbons
UK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich GibbonsMartin Thompson
 
UK Conference 2018_SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_SaaS Management - How to save your share of $30bn_AJ WittUK Conference 2018_SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_SaaS Management - How to save your share of $30bn_AJ WittMartin Thompson
 
UK Conference 2018_How to fortify your Audit Castle_Jochen Hagenlocher
UK Conference 2018_How to fortify your Audit Castle_Jochen HagenlocherUK Conference 2018_How to fortify your Audit Castle_Jochen Hagenlocher
UK Conference 2018_How to fortify your Audit Castle_Jochen HagenlocherMartin Thompson
 
UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...
UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...
UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...Martin Thompson
 
UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...
UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...
UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...Martin Thompson
 

More from Martin Thompson (20)

Wisdom UK 2019: Building the ultimate HAM sandwich - David Foxen
Wisdom UK 2019: Building the ultimate HAM sandwich - David FoxenWisdom UK 2019: Building the ultimate HAM sandwich - David Foxen
Wisdom UK 2019: Building the ultimate HAM sandwich - David Foxen
 
2019 Salary and Skills Survey by The ITAM Review
2019 Salary and Skills Survey by The ITAM Review 2019 Salary and Skills Survey by The ITAM Review
2019 Salary and Skills Survey by The ITAM Review
 
2017 ITAM Review Salary Survey
2017 ITAM Review Salary Survey2017 ITAM Review Salary Survey
2017 ITAM Review Salary Survey
 
Australia Conference 2018_News that shook the itam world in 2018 with resources
Australia Conference 2018_News that shook the itam world in 2018 with resourcesAustralia Conference 2018_News that shook the itam world in 2018 with resources
Australia Conference 2018_News that shook the itam world in 2018 with resources
 
Australia Conference 2018_What you need to think about when implementing micr...
Australia Conference 2018_What you need to think about when implementing micr...Australia Conference 2018_What you need to think about when implementing micr...
Australia Conference 2018_What you need to think about when implementing micr...
 
Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...
Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...
Australia Conference 2018_Taming the multi-cloud hydra – innovate with confid...
 
Australia Conference 2018_Process Meh
Australia Conference 2018_Process MehAustralia Conference 2018_Process Meh
Australia Conference 2018_Process Meh
 
Australia Conference 2018_ITAM in 2023 - where is your role heading
Australia Conference 2018_ITAM in 2023 - where is your role heading Australia Conference 2018_ITAM in 2023 - where is your role heading
Australia Conference 2018_ITAM in 2023 - where is your role heading
 
Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...
Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...
Australia Conference 2018_ISO 19770 – How it’s changed and how it can benefit...
 
Australia Conference 2018_How to engage your it security team and fund your s...
Australia Conference 2018_How to engage your it security team and fund your s...Australia Conference 2018_How to engage your it security team and fund your s...
Australia Conference 2018_How to engage your it security team and fund your s...
 
Australia Conference 2018_How to be a SaaS manager – tools, people and proces...
Australia Conference 2018_How to be a SaaS manager – tools, people and proces...Australia Conference 2018_How to be a SaaS manager – tools, people and proces...
Australia Conference 2018_How to be a SaaS manager – tools, people and proces...
 
Australia Conference 2018_Boost up your oracle audit defence
Australia Conference 2018_Boost up your oracle audit defenceAustralia Conference 2018_Boost up your oracle audit defence
Australia Conference 2018_Boost up your oracle audit defence
 
UK Conference 2018_7 pillars of a HAM practice_Martin Thompson
UK Conference 2018_7 pillars of a HAM practice_Martin ThompsonUK Conference 2018_7 pillars of a HAM practice_Martin Thompson
UK Conference 2018_7 pillars of a HAM practice_Martin Thompson
 
UK Conference 2018_Software support and maintenance survey_Martin Thompson
UK Conference 2018_Software support and maintenance survey_Martin ThompsonUK Conference 2018_Software support and maintenance survey_Martin Thompson
UK Conference 2018_Software support and maintenance survey_Martin Thompson
 
UK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ WittUK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_ SaaS Management - How to save your share of $30bn_AJ Witt
 
UK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich Gibbons
UK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich GibbonsUK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich Gibbons
UK Conference 2018. People. Processes. Tools. Three's a Cloud_Rich Gibbons
 
UK Conference 2018_SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_SaaS Management - How to save your share of $30bn_AJ WittUK Conference 2018_SaaS Management - How to save your share of $30bn_AJ Witt
UK Conference 2018_SaaS Management - How to save your share of $30bn_AJ Witt
 
UK Conference 2018_How to fortify your Audit Castle_Jochen Hagenlocher
UK Conference 2018_How to fortify your Audit Castle_Jochen HagenlocherUK Conference 2018_How to fortify your Audit Castle_Jochen Hagenlocher
UK Conference 2018_How to fortify your Audit Castle_Jochen Hagenlocher
 
UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...
UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...
UK Conference 2018_All change - Aligning SAM with your Data Centre change pro...
 
UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...
UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...
UK Conference 2018_How BT delivered 21% cost savings through Converged Transf...
 

Recently uploaded

AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Science&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfScience&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfjimielynbastida
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Scott Keck-Warren
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Commit University
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr LapshynFwdays
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksSoftradix Technologies
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Neo4j
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 

Recently uploaded (20)

Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort ServiceHot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
Hot Sexy call girls in Panjabi Bagh 🔝 9953056974 🔝 Delhi escort Service
 
DMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special EditionDMCC Future of Trade Web3 - Special Edition
DMCC Future of Trade Web3 - Special Edition
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Science&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdfScience&tech:THE INFORMATION AGE STS.pdf
Science&tech:THE INFORMATION AGE STS.pdf
 
Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024Advanced Test Driven-Development @ php[tek] 2024
Advanced Test Driven-Development @ php[tek] 2024
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!Nell’iperspazio con Rocket: il Framework Web di Rust!
Nell’iperspazio con Rocket: il Framework Web di Rust!
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
"Federated learning: out of reach no matter how close",Oleksandr Lapshyn
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other Frameworks
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 

ITAM US 2017 Audit Defense Plugging the Leaks

  • 1. The ITAM Review US Conference 2017 Audit Defense: Plugging The Leaks Chris Moffett, Global Software Asset Manager Lisa Hellberg, Sr. Director, Global Supplier Asset Management
  • 2. The ITAM Review US Conference 2017 Introduction TOPIC  OF  DISCUSSION:   Many  companies  struggle  with  tools,  "helpful"  employees  and  even  internal  audit  teams   leaking  what  appears  to  be  irrelevant  informaFon  to  outside  auditors.  Unfortunately  the   auditors  and  sales  teams  are  very  adept  at  asking  probing  quesFons  that  are  out  of  scope   and  oIen  lead  to  unintended  audit  complicaFons.     WHAT  YOU  WILL  LEARN:   In  this  session  you  will  discover  how  to  organize  your  company's  audit  response  acFviFes.   Who  can  discuss  what  informaFon,  what  tools  can  be  used  and  how  the  auditors  and   sales  teams  can  interact  with  your  company  while  under  audit.    
  • 3. The ITAM Review US Conference 2017 Agenda •  Software Audit Pre-conditions •  What are we trying to avoid •  Prevent leaks •  Before the audit •  At audit commencement •  Upon audit completion
  • 4. The ITAM Review US Conference 2017 Audit Preconditions: Non-Negotiable •  All  communicaFon  regarding  the  ongoing  audit  must  be  directed  to  “Your  Company’s”   audit  response  team     •  Publisher/auditor  representaFves  must  not  aWempt  to  discuss  environment,   installaFon  count,  forecast,  growth  expectaFons,  strategic  direcFon  or  any  other  audit   related  data  with  other  “Your  Company”  employees.  
  • 5. The ITAM Review US Conference 2017 What Are We Trying To Avoid •  Unauthorized  release  of  confidenFal  informaFon   •  Prohibit  gathering  and  communicaFon  that  is  out  of  scope   •  InteracFons  between  auditors  and  non  audit  team  members   •  Auditor/Company  representaFves  probing  for  addiFonal  informaFon  
  • 6. The ITAM Review US Conference 2017 Prevent Leaks Before The Audit Before  the  audit  begins   •  Create  an  internal  audit  team  and  define  their  roles   •  Establish  list  of  in  scope  informaFon     •  Understand  and  idenFfy  who  your  publisher/auditor  representaFves  are   •  Restrict  and  centralize  all  communicaFons   •  Train  your  internal  staff  to  redirect  all  communicaFons  related  to  the  audit.  
  • 7. The ITAM Review US Conference 2017 Internal Audit Team •  Legal  Council  –  Manage  the  legal  terms  and  condiFons   •  Security  –  Help  define  and  enforce  data  elements  that  are  captured  and  communicated   •  Procurement  –  Manage  the  pricing  and  seWlement  acFviFes   •  ITAM/SAM  –  Manage  the  data  gathering  and  compliance  review  process    
  • 8. The ITAM Review US Conference 2017 What is considered in scope information Only  usage  data  based  on  contractually  agreed  upon  license  metrics  should  be  included   •  Confirm  which  specific  agreements  are  under  review   •  IdenFfy  what  products  and  use  rights  apply   •  Outline  regions  or  locaFons  under  audit   •  Agree  on  duraFon  of  product  usage   •  Establish  license  usage  calculaFon  methods   •  Compile  a  list  of  eligible  .exe  values  and  installaFon  paths   •  Determine  what  environments  require  licenses  (i.e.  dev,  test,  prod,  etc)   •  Establish  data  gathering  process  and  tools   •  Establish  quesFon  and  answer  protocol    
  • 9. The ITAM Review US Conference 2017 What should be considered out of scope  Data  to  avoid       •  Trial,  evaluaFon  and  free  installaFons   •  Customer  idenFfiable  informaFon   •  Customer  installed  products  where  licenses  are  not  provided  by  your  company   •  Orphaned  .dll  and  other  data  leI  behind  from  uninstalls   •  Incomplete  installaFons   •  Prior  expired  agreements   •  Auditor  access  to  event  viewer  logs  
  • 10. The ITAM Review US Conference 2017 Publisher/Audit Company Representatives Who  should  be  considered  a  company  representaFve  we  would  want  to  avoid?     •  Sales  and  Sales  Support   •  Tech  Support  Engineers   •  Billing  contacts     •  Compliance/audit  team   •  Industry  event  or  conference  parFcipants   •  SoIware  product  reseller  
  • 11. The ITAM Review US Conference 2017 Communication Types To Avoid Below  are  a  few  examples  of  communicaFon  methods  by  the  publisher/auditor   company  that  non  audit  team  employees  may  be  exposed  to  and  should  avoid   •  Emails   •  Phone  and  text  conversaFons   •  Social  Media  interacFons  (i.e.  LinkedIn,  Facebook,  etc.)     •  Industry  event  or  conference  parFcipants   •  On  site  visits   •  Business  Lunches   •  Quarterly  Business  Reviews  
  • 12. The ITAM Review US Conference 2017 Restrict Internal Staff Communications Below  are  example  scenarios  of  who  might  unknowingly  communicate  risky   informaFon   •  OperaFons/Support  staff  calling  in  for  support  of  the  product   •  Product  users  looking  for  product  roadmap  and  other  informaFon   •  Accounts  Payable  working  to  pay  an  invoice   •  Front  desk/lobby  staff  being  approached  for  onsite  visits   •  Engineers  working  to  deploy  the  products   •  Individuals  working  with  evaluaFon  and  new  product  tesFng  acFviFes   •  MarkeFng  or  channel  sales  collaboraFons/partnerships   •  Employees  requesFng  quotes  for  new  product  deployment  
  • 13. The ITAM Review US Conference 2017 Prevent Leaks At Audit Commencement •  Enforce  in  scope  agreed  upon  details   •  Code  tools  to  only  capture  in  scope  data  elements   •  Require  auditors  use  a  company  provided  laptop  with  no  internet  access  and  no  USB   write  capabiliFes  to  review  the  data.   •  Reclaim  the  laptop  from  the  auditor  at  the  end  of  each  day   •  Do  not  allow  any  data  to  be  taken  off  site  unFl  analysis  is  completed   •  Once  analysis  is  completed  only  allow  summary  ELP  level  data  to  be  taken  off  site  for   compliance  posiFon  creaFon   •  Require  auditor  quesFons  to  be  answered  offline   •  If  auditor  quesFons  require  screen  share  acFviFes,  schedule  the  review  for  the   following  day  and  train  the  impacted  staff  on  how  to  respond  
  • 14. The ITAM Review US Conference 2017 Screen Share Best Practices •  Hide  all  informaFon  on  desktop   •  Close  all  programs   •  Navigate  to  in  scope  locaFons  prior  to  starFng  the  screen  share   •  Only  answer  quesFons  with  a  yes  or  a  no  
  • 15. The ITAM Review US Conference 2017 Prevent Leaks Upon Audit Completion •  Reclaim  and  reformate  company  provided  laptop   •  Confirm  only  summary  ELP  level  data  has  been  provided  to  the  publisher   •  Do  not  allow  auditor  to  retain  a  copy  of  the  data  used  for  ELP  creaFon  
  • 16. The ITAM Review US Conference 2017 Summary Remember that all compliance reviews should have only one goal, determining current compliance position. With that in mind always: •  Proactively develop your compliance position prior to auditor engagement •  Establish and enforce the audit scope •  Restrict non audit team communications •  PROTECT YOUR DATA
  • 17. The ITAM Review US Conference 2017 Questions?
  • 18. The ITAM Review US Conference 2017 Thank You