Shopping Cart

No products in the cart.

BS ISO/IEC 19770-2:2015:2018 Edition

$215.11

Information technology. Software asset management – Software identification tag

Published By Publication Date Number of Pages
BSI 2018 84
Guaranteed Safe Checkout
Category:

If you have any questions, feel free to reach out to our online customer service team by clicking on the bottom right corner. We’re here to assist you 24/7.
Email:[email protected]

This part of ISO/IEC 19770 establishes specifications for tagging software to optimize its identification and management.

This part of ISO/IEC 19770 applies to the following.

  1. Tag producers: these organizations and/or tools create software identification (SWID) tags for use by others in the market. A tag producer may be part of the software creator organization, the software licensor organization, or be a third-party organization. These organizations and/or tools can broadly be broken down into the following categories.

    1. Platform providers: entities responsible for the computer or hardware device and/or associated operating system, virtual environment, or application platform, on which software may be installed or run. Platform providers which support this part of ISO/IEC 19770 may additionally provide tag management capabilities at the level of the platform or operating system.

    2. Software providers: entities that create, license, or distribute software. For example, software creators, independent software developers, consultants, and repackagers of previously manufactured software. Software creators may also be in-house software developers.

    3. Tag tool providers: entities that provide tools to create software identification tags. For example, tools within development environments that generate software identification tags, or installation tools that may create tags on behalf of the installation process, and/or desktop management tools that may create tags for installed software that did not originally have a software identification tag.

  2. Tag consumers: these tools and/or organizations utilize information from SWID tags and are typically broken down into the following two major categories:

    1. software consumers: entities that purchase, install, and/or otherwise consume software;

    2. IT discovery and processing tool providers: entities that provide tools to collect, store, and process software identification tags. These tools may be targeted at a variety of different market segments, including software security, compliance, and logistics.

This part of ISO/IEC 19770 does not prescribe Information Technology Asset Management (ITAM) or other IT-related processes required for reconciliation of software entitlements with software identification tags or other IT requirements.

This part of ISO/IEC 19770 does not specify product activation or launch controls.

This part of ISO/IEC 19770 is not intended to conflict either with any organization’s policies, procedures or standards or with any national or international laws and regulations.

PDF Catalog

PDF Pages PDF Title
2 undefined
7 Foreword
8 Introduction
11 1 Scope
2 Normative references
12 3 Terms, definitions, and abbreviated terms
3.1 Terms and definitions
3.2 Abbreviated terms
13 4 Conformance
4.1 SWID tag conformance
4.2 Application conformance
4.3 Platform conformance
5 Interoperability guidance
5.1 Overview
5.2 SWID tag modification
14 5.3 SWID tag relationships
5.3.1 Overview
5.3.2 Pre-installation data attribute
5.3.3 SWID patch attribute
15 5.3.4 SWID supplemental attribute
16 6 Implementation of software identification tagging processes
6.1 General requirements and guidance
6.1.1 XML and XSD
6.1.2 SWID tags based on earlier revisions of this part of ISO/IEC 19770
6.1.3 SWID tag installation and removal
6.1.4 SWID data storage and transmission
17 6.1.5 Unique registration ID (regid)
18 6.1.6 Tag identifier
6.1.7 Unique software identification tag file name
6.1.8 Software identification tag discovery
6.1.9 Languages
19 6.1.10 Authenticity of software identification tags
6.1.11 File hash definitions
20 6.1.12 Use of standardized data types in XSD definition
6.1.13 Using Evidence or Payload
6.1.14 Redistributable software components
7 Platform requirements and guidance
21 8 Elements
8.1 General
22 8.2 Minimum SWID tag data values required
23 8.3 Recommended SWID tag data values
8.4 XML element and attribute names
8.4.1 Introduction
24 8.4.2 Additional attributes allowed
8.5 Data values
8.5.1 SoftwareIdentity
28 8.5.2 Entity
30 8.5.3 Evidence
8.5.4 Link
35 8.5.5 Meta
36 8.5.6 Payload
8.6 Type and attribute definitions
8.6.1 Directory
37 8.6.2 File
38 8.6.3 FileSystemItem
40 8.6.4 Ownership
8.6.5 NMTOKEN and NMTOKENS
8.6.6 Process
8.6.7 Rel
41 8.6.8 Resource
8.6.9 ResourceCollection
42 8.6.10 Role
8.6.11 SoftwareMeta
44 8.6.12 Use
45 8.6.13 VersionScheme
46 Annex A (informative) XSD changes between revisions
49 Annex B (normative) XML schema definition (XSD)
70 Annex C (informative) UML structure of SWID tag schema
72 Annex D (informative) Sample tags
83 Bibliography
BS ISO/IEC 19770-2:2015
$215.11