Software Auditing: A New Task for U.K. Universities

Mark Fletcher · ˜The œjournal · 1997

Universities in the United Kingdom have now become dependent upon for teaching, learning and administration. In this explosive growth, pressure has arisen from vendors to demonstrate that is still being used legally. Higher education is also seeking to better manage as an asset. This article discusses how these factors have led to one pilot project that aims to assist its peers in software management. U.K. universities have long benefited from the educational pricing of software, and vendors have applied appropriate licence conditions to those sales. Most recently, the issue of concurrency has been debated, that is, the running of more than one copy of a program over a network. But with (at best) static financial resources available to central computing services, better management practices are sought. Vendors are keen on this, arguing that the payback for cheap has arrived in the form of auditing to demonstrate legality and an absence of piracy. But there is a carrot as well as a stick to an audit. Software auditing creates a large volume of useful data that can be used to populate IT (information technology) asset-management systems. Thus better answers can be obtained for: * What level of support should our help desk provide for application A? * Which PCs need upgrading to run a new version of the OS? * What is the dollar value of the we possess? * What would be the implications of standardising on word processor B? * Who is using old versions of package C? Software Auditing Defined Software auditing is the process of determining how many copies of a program are installed, on both workstation and server hard disks, then comparing this total to the number of copies allowed by one's licensing agreement with the vendor. A two-month pilot project on auditing in academia was initiated and hosted by Exeter University. Evaluating possible audit tools and drawing together other pertinent information was done via the Web. Much new information was added, and U.K. higher education institutions expressed strong support in an e-mail survey. Exeter's Implementation Path There are essentially two approaches to implementing auditing. First, policy approval and procedural issues can be devised, followed by institution-wide rollout. Conversely a bottom-up approach can be taken: local procedures are constructed, funding is obtained for sample departments, then areas requiring clarification and management decision are identified. This latter approach was adopted at Exeter. The university's computing facilities and services are overseen by the Computer Users' Group (CUG). At a meeting, it was proposed that a sub-committee (Software Audit Group, SAG) be established. SAG would explore the issues and practicalities of auditing at Exeter, would hold a budget to audit sample departments, and thus best practice would be established. Policy documents and a Procedures manual would be produced as part of the deliverables from this national pilot project on auditing. The CUG allocated funding for auditing the central computing service, IT Services, and sample departments. Following the evaluations of suitable audit tools, two products (fPrint 4.02 and InControl Audit 2.51, now called Utopia Audit) were selected. fPrint was allocated for all departments that had only PC compatibles, while InControl Audit (Utopia Audit) went to departments with both PCs and Macs. Doing a Walk-Round Audit Each participating department was asked to complete a questionnaire on the number of staff workstations in use with hard disks. Diskless workstations could only be audited for their hardware and were not included. Also excluded were workstations in public clusters (e.g. classrooms), as these hard disks tended to be re-set on a regular basis. …

Read the paper · More papers on PaperTik