Browse Definitions :
Definition

software audit

Contributor(s): Matthew Haughn

A software audit is an internal or external review of a software program to check its quality, progress or adherence to plans, standards and regulations.

Software audits may be conducted for a number of reasons, including:

  • Verifying licensing compliance.
  • Monitoring for quality assurance (QA).
  • Compliance with industry standards.
  • Satisfying legal requirements.

For the organization, internal audits can be useful for improving efficiency, catching inactive licenses that can be dropped and finding problems before they can become licensing or regulatory issues in a third-party review. Third-party review typically focuses on software used beyond licensed rights, and external reviewers also won’t usually care if some licenses are unused. These different priorities mean it is advisable for an organization to conduct internal reviews prior to external audits.

An organization usually contracts with third-party reviewers and teams to provide independent verification of a software program’s compliance with development plans, industry standards, best practices and legal practices. Compliance audits may focus on adherence to IEEE standards or legal regulatory compliance. This kind of audit focus is especially important in the case of software used in critical infrastructure and key resources (CIKR).

Software audits are often important and sometimes required. However, audits can be disruptive to a company's development and may place a financial strain on a project because of unbudgeted costs. Teams and management may be required to consult with auditors to ensure the process is complete and accurate. This consultation can take away from time spent on work. Since time is important, organizations should refrain from overdoing audits and executives should understand how, why and when audits are conducted so they can best prepare for them.

This was last updated in July 2017

Continue Reading About software audit

Start the conversation

Send me notifications when other members comment.

Please create a username to comment.

-ADS BY GOOGLE

File Extensions and File Formats

Powered by:

SearchCompliance

  • compliance audit

    A compliance audit is a comprehensive review of an organization's adherence to regulatory guidelines.

  • regulatory compliance

    Regulatory compliance is an organization's adherence to laws, regulations, guidelines and specifications relevant to its business...

  • Whistleblower Protection Act

    The Whistleblower Protection Act of 1989 is a law that protects federal government employees in the United States from ...

SearchSecurity

  • Malwarebytes software

    Malwarebytes is a cross-platform anti-malware program that detects and removes malware and other rogue software.

  • Transport Layer Security (TLS)

    Transport Layer Security (TLS) is a protocol that provides authentication, privacy, and data integrity between two communicating ...

  • van Eck phreaking

    Van Eck phreaking is a form of electronic eavesdropping that reverse engineers the electromagnetic fields (EM fields) produced by...

SearchHealthIT

SearchDisasterRecovery

  • cloud insurance

    Cloud insurance is any type of financial or data protection obtained by a cloud service provider. 

  • business continuity software

    Business continuity software is an application or suite designed to make business continuity planning/business continuity ...

  • business continuity policy

    Business continuity policy is the set of standards and guidelines an organization enforces to ensure resilience and proper risk ...

SearchStorage

  • solid-state storage

    Solid-state storage (SSS) is a type of computer storage media made from silicon microchips. SSS stores data electronically ...

  • persistent storage

    Persistent storage is any data storage device that retains data after power to that device is shut off. It is also sometimes ...

  • computational storage

    Computational storage is an information technology (IT) architecture in which data is processed at the storage device level to ...

Close